{"id":105091,"date":"2026-07-14T08:59:08","date_gmt":"2026-07-14T08:59:08","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/105091\/"},"modified":"2026-07-14T08:59:08","modified_gmt":"2026-07-14T08:59:08","slug":"your-law-firms-biggest-breach-risk-is-an-unsupervised-ai-agent","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/105091\/","title":{"rendered":"Your Law Firm\u2019s Biggest Breach Risk Is an Unsupervised AI Agent"},"content":{"rendered":"<p>In most organizations, the majority of the identities logging into systems aren\u2019t people. They\u2019re software: the automated accounts, access keys, and artificial intelligence agents that let applications talk to each other and move work along. These machine identities outnumber humans and roughly half hold privileged access. <a href=\"https:\/\/www.businesswire.com\/news\/home\/20250423817886\/en\/Machine-Identities-Outnumber-Humans-by-More-Than-80-to-1-New-Report-Exposes-the-Exponential-Threats-of-Fragmented-Identity-Security\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>The number climbs fast as firms put AI agents to work. Almost no one governs them. The accounts most likely to hand an attacker the keys to a firm\u2019s data are the ones nobody owns, reviews, or watches.<\/p>\n<p>Security programs have hardened how people log in: multifactor authentication, passkeys, security keys, access reviews, and training. A person can be phished or tricked into approving a sign-in, so defenders hardened the human \u2014 however, you can\u2019t phish an AI agent or an automated account.<\/p>\n<p>Machine identities haven\u2019t been ignored, and progress has been made, but it lags well behind the human side. A machine identity usually logs in with a fixed secret, a password or access key it presents every time. There\u2019s no human present to approve a prompt or provide a fingerprint to read, so the stepped up controls that hardened human login don\u2019t apply. What it has instead is a credential that can remain valid for years and be stolen or leaked.<\/p>\n<p>How Breaches Occur<\/p>\n<p>The pattern isn\u2019t hypothetical. In December 2024, a state-linked group stole <a data-terminal-id=\"SPDHSZDWRGG0\" href=\"https:\/\/news.bloomberglaw.com\/banking-law\/us-treasury-says-it-was-hacked-by-chinese-state-sponsored-actor\" rel=\"nofollow noopener\" target=\"_blank\">one access key<\/a> from a remote-support vendor and used it to reach into the Treasury Department, opening workstations and unclassified documents, including in its sanctions arm. One machine credential did the work. These aren\u2019t edge cases: By one estimate, half of organizations had a breach tied to a compromised machine identity last year. <a href=\"https:\/\/www.cyberark.com\/resources\/blog\/the-urgent-reality-of-machine-identity-security-in-2025\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>The legal world isn\u2019t exempt. A 2026 <a data-terminal-id=\"SX1RAZT1UM0W\" href=\"https:\/\/news.bloomberglaw.com\/litigation\/lexisnexis-sued-over-april-data-breach-affecting-364-000-people\" rel=\"nofollow noopener\" target=\"_blank\">breach at a major legal research provider<\/a> reportedly traced to one automated account that could read nearly every secret in that account, exposing data tied to 21,000 enterprise customers, including law firms. The credential that exposes your clients may not even live inside your walls. <a href=\"https:\/\/www.salesforceben.com\/lexisnexis-data-breach-salesforce-credentials-exposed-in-3-9m-record-hack\/\" rel=\"nofollow noopener\" target=\"_blank\"><a href=\"https:\/\/www.theregister.com\/security\/2026\/03\/04\/lexisnexis-legal-professional-confirms-data-breach\/4305422\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>Moving Data<\/p>\n<p>Attackers prize these identities because they are the conduits most data moves through. Picture the automated connection that copies every email into the records system, or syncs the document store to backup nightly. A paralegal can open files for her own matters. That connection touches all of them, because moving the data is its only job. A human login opens one mailbox. A compromised machine account opens the pipeline, and seizing it is seizing the plumbing, not a single room.<\/p>\n<p>AI Agents<\/p>\n<p>Many firms are racing to deploy AI agents. An agent is software you hand a goal and let act on it: Read the inbox, find the documents, draft the reply, update the matter. It logs in to each system the way a person would, through stored credentials rather than a typed password. If your firm uses Microsoft 365 Copilot, Salesforce Agentforce, or legal tools such as Harvey, you\u2019re already being asked to deploy these agents. The danger is aggregation. <\/p>\n<p>To be useful, a single agent is wired to several tools at once \u2014 email, the document system, billing, research \u2014 under one identity. Unless someone restricts what it can do in each, that identity inherits broad access across all of them, so one over-permissioned agent, or one talked into misbehaving, becomes a direct line to a large share of the firm\u2019s records, with no one in the loop.<\/p>\n<p>Every machine identity is delegated authority, often with more reach than any single employee, and the duty of confidentiality attaches to whatever can touch a client\u2019s data.<\/p>\n<p>Insurers are starting to condition coverage on a governance framework for these identities, and outside counsel guidelines are beginning to ask how machine identities and AI agents are managed. <a href=\"https:\/\/thehackernews.com\/2026\/02\/identity-cyber-scores-new-metric.html\" rel=\"nofollow noopener\" target=\"_blank\"><a href=\"https:\/\/delinea.com\/news\/identity-security-controls-central-to-cyber-insurance-decisions\" rel=\"nofollow noopener\" target=\"_blank\"> A firm that can\u2019t answer can pay more for coverage or have to make lengthy justifications to clients. When a breach traces to an account no one owned, the hard part isn\u2019t the forensics, it\u2019s explaining to a client, a regulator, or a court why no one was accountable.<\/p>\n<p>The real question isn\u2019t whether these identities can be managed, but whether leadership and the board can authorize, supervise, and keep validating what they delegate to software. Identity governance is becoming corporate governance.<\/p>\n<p>What to DoInventory first. You can\u2019t govern what you can\u2019t see, so build a real inventory of machine identities and AI agents and the access each holds.Give every machine identity an owner. An account with no person accountable for it should be disabled, not legacied in.Apply least privilege and mean it. Scope each identity, especially each AI agent, to the minimum access it needs, and strip the standing access it doesn\u2019t.Manage the credential lifecycle. Keep credentials in a vault, rotate and expire them, stop burying them in applications, and retire an identity when its job ends.Treat AI agents as privileged users. Require human approval before they take sensitive actions on client matters.Monitor them in real time. Baseline how each machine identity and AI agent normally behaves, and alert when one deviates, so a stolen credential shows up in minutes, not months.Bring machines under the same governance as people. Put machine identities and AI agents into your access reviews, monitoring, and board-level risk reporting, not a separate track everyone ignores.<\/p>\n<p>The identities that matter most in the next breach are the ones a firm has never looked at. They run quietly in the background, carry real access to privileged material, and answer to no one. AI is about to multiply them.<\/p>\n<p>The firms that get ahead of this will decide \u2014 before an incident forces it \u2014 that every identity with access to a client\u2019s secrets has a name attached, human or not.<\/p>\n<p>This article does not necessarily reflect the opinion of Bloomberg Industry Group Inc., the publisher of Bloomberg Law, Bloomberg Tax, and Bloomberg Government, or its owners.<\/p>\n<p>Author Information<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/kyle-salous\/\" rel=\"nofollow noopener\" target=\"_blank\">Kyle Salous<\/a> is a chief information security officer at a large law firm and founder of OC2 Cyber.<\/p>\n<p>Interested in writing? Review our <a href=\"https:\/\/news.bloombergtax.com\/tax-insights-and-commentary\/author-submission-guidelines-for-bloomberg-tax-law-insights\" rel=\"nofollow noopener\" target=\"_blank\">author guidelines,<\/a> and submit pitches to <a href=\"https:\/\/news.bloomberglaw.com\/legal-exchange-insights-and-commentary\/mailto:Insights@bloombergindustry.com\" rel=\"nofollow noopener\" target=\"_blank\">Insights@bloombergindustry.com.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"In most organizations, the majority of the identities logging into systems aren\u2019t people. They\u2019re software: the automated accounts,&hellip;\n","protected":false},"author":2,"featured_media":105092,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,25,7537,34462,17667,5990],"class_list":["post-105091","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-artificial-intelligence","tag-artificial-intelligence-agents","tag-data-breaches","tag-insurance-coverage","tag-phishing"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/105091","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=105091"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/105091\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/105092"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=105091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=105091"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=105091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}