All articles
Enterprise AI Is The Biggest Insider Threat in IT History And It Only Wants To Help
Jesse Adams III, Senior Principal Enterprise Security Architect, warns that AI's eagerness to please makes it the biggest insider threat IT has ever onboarded

Make The Security Digest one of your go-to sources on Google
AI innocently represents the single biggest insider threat in the history of IT. It just wants to be helpful. If a user asks AI to do something it shouldn't, perhaps through a prompt injection attack, AI might not realize the error. It's going to try its best to fulfill the user's wishes.
Every enterprise AI plan promises faster delivery, and nearly every one assumes the helpful new workforce can be trusted. One security architect looks at those agents, with their own identities, entitlements, and bottomless desire to please, and sees a historic insider threat.
Jesse Adams III is a Senior Principal Enterprise Security Architect. A Zero Trust strategist who started out operating naval nuclear reactors and later served as chief architect of the Navy Marine Corps Intranet, Adams now guards some of the country's most regulated healthcare data.
"AI innocently represents the single biggest insider threat in the history of IT. It just wants to be helpful. If a user asks AI to do something it shouldn't, perhaps through a prompt injection attack, AI might not realize the error. It's going to try its best to fulfill the user's wishes," says Adams.
The naive child at the command line
The eagerness is the exploit. Prompt injection works because a model processes a malicious instruction like any other request, a pattern already moving sensitive data out of enterprises as the agentic threat map widens. Adams frames it with an employee comparison. "Think of the average customer service representative. They're operating a portal with a GUI, and the GUI limits what they can and cannot do.
The AI operates without the GUI. It's at the command line with dynamic, versatile entitlements. It can elevate its privileges and renegotiate its role with the other agents making those decisions." Agents trust too much by default, so a naive child is his working model. "Somebody clever enough can plant the seed of malice, get it to mistakenly divulge information it shouldn't have, and use it as an exploit."
The camel's nose under the tent
The procedural erosion worries him as much. Checkpoints align business requirements, technical solutions, and outcomes, and the hurry up mentality reads them as friction. "There should be review boards, checkpoints where you stop and ensure proper alignment. More and more, that's going to become a spectacular inconvenience." The replacement is easy to build, each evaluator arriving with an identity of its own. "Act as the chief technology officer, act as the chief architect, be my strongest supporter, be my worst adversary. You can synthetically create the same adversarial review board construct you would have with humans."
What follows depends on how much risk leaders can see. "The camel's nose under the tent will happen when they create some threshold," Adams says. "If the risk is low enough, if the cost of a mistake is within the risk appetite, let the AI team evaluate it. Once you reach a certain threshold, then we'll get humans involved. There'll be some successes and some stubbing of toes."
Show me the receipts
His countermeasure treats security as load-bearing in AI adoption, reference architecture first. He built one against the AI risk management framework, the OWASP Top 10 for large language models, and emerging ISO guidance, using AI to speed the research. "You might call it fox watching the henhouse. I just think of it as accelerating my research. But you've got to tell it, do not make this up. Show me the receipts. Cite all of your references. And it does, as long as you establish those guardrails."
The skepticism has to hold up at runtime, inside a layered agentic defense. "You start with your AI gateways. Make sure you're blocking any transfer of sensitive information outside your boundaries," he says. "Have the restrictions built in, and understand that least privilege RBAC-based access controls are not going to work anymore. You're going to have to figure something else out."
Sticker shock and the scoreboard
Measurement keeps the enthusiasm honest. "You've got this team going gung ho, charging downhill into AI, and then the first bill comes in. A quarter-million-dollar bill is an eye-opener, and it's even bigger when it's 10 or 20 times that. Enthusiasm gets curbed when the expense of AI starts to outweigh the perceived savings."
Past token costs, he tracks delivery time, customer satisfaction, and whether consolidation trims licensing spend, and calls mass layoffs in favor of agents shortsighted. For the most sensitive workloads, fully homomorphic encryption keeps a prompt encrypted even while the model computes on it, at heavy cost in speed and tokens. "All but the most sensitive should probably not use that solution."
With attacks breaking out in under a minute, matching the offense machine for machine is a losing bet. "The bad actors are using AI as well. You're not going to win an AI arms race if you're the defender. You simply cannot. The best bet you have is to revise your security posture and perfect it."






