CRITICALOWASP Agentic Top 10 ASI03
Identity and Privilege Abuse
Identity and privilege abuse in AI systems occurs when agents impersonate users, escalate their own privileges, or exploit shared service accounts to access resources beyond their authorization level. Enterprises face significant risk because AI agents often operate under service identities with broad permissions, making it difficult to attribute actions, enforce least privilege, or detect unauthorized access patterns. Look for vendors that support per-agent identity management, fine-grained permission scoping, session-level credential isolation, and real-time monitoring of privilege escalation attempts. Solutions should integrate with existing IAM infrastructure and provide clear audit trails that distinguish between human and agent actions.