Table of Contents

Abstract 04
Infographics

Taxonomy of Agent Threats

TL;DR: AI agent threats follow a predictable pattern as agents move from reasoning to action. This taxonomy maps five domains of risk and shows how impact expands with capability. Across each stage, identity determines what an agent can access, what it can do, and how far a compromise can extend.

Aembit Team

Product & Research

Published Jun 2026

Updated Sep 2026

50:1

Non-human to human identities

18

Agent threat classes mapped

0

Long-lived secrets required

Taxonomy of Agent Threats
No form · instant

Download the Infographics

Free PDF · no email required

Table of Contents

When AI agents start taking real action inside enterprise systems – calling APIs, accessing data, chaining tools – the question of what they’re allowed to do becomes tantamount. This graphic maps the full risk surface so security teams and builders can see it clearly, all at once.

Every known agent threat – 18 of them across five domains – maps into a single tree, with tiers that escalate by blast radius and one root that connects them all: the agent’s identity.

Inside, you will find:

FAQs

You Have Questions? We Have Answers.

What is the Agent Identity Attack Surface?

It is a model that maps how AI agent risk expands as agents move from reasoning to execution. It shows how different threat domains connect and how identity determines the impact of each one.

Agents operate in stages. They interpret instructions, use tools, and execute actions. Each stage introduces distinct risks, which is why threats can be grouped into repeatable domains.

Blast radius refers to the scope of impact when an agent is compromised. As agents gain access to tools and infrastructure, their ability to affect systems, data, and workflows increases.

Identity determines what an agent can access, what actions it can perform, and how those actions are authorized. Strong identity controls limit the impact of misuse by enforcing scoped and time-bound access.

No. Any environment where agents access data, call APIs, or automate workflows introduces these risks. The model applies wherever agents act within systems.

Identity confusion, prompt and instruction manipulation, tool and skill supply chain, runtime execution, and persistence or privilege escalation.

Continue Exploring

Our learning center features all the latest resources to deepen your understanding of securing workload access, including how-to guides, videos, webinars, and more.

Aembit and CrowdStrike AIDR data sheet for AI agent identity, access control, and content inspection share image

Aembit + CrowdStrike AIDR for AI Agent Security

Aembit and CrowdStrike AIDR combine AI agent identity and MCP access controls with real-time content inspection and enforcement.
Auditing and Governance for Workload and AI Agent Identity

Auditing and Governance in Modern Identity

Aembit turns workload and AI agent access activity into detailed audit trails, policy insights, and operational visibility.
A $300B Investment Firm
Secures Claude Access with Aembit

How a $300B Investment Firm Secured Enterprise Claude Access With Aembit

See how a $300B investment firm secured Claude for 500+ users with governed MCP access, secretless credentials, and full auditability.