AEBA: Why Behavioral Analytics Has to Expand Beyond Humans

AEBA: Why Behavioral Analytics Has to Expand Beyond Humans

Why Security Teams Need Behavioral Visibility Into AI Agents

Simon Hunt, Chief Product Officer, Securonix

 

For years, security teams have built behavioral models around people. We learned that valid credentials only tell so much. A user can have legitimate access to a system and still behave in a way that deserves attention, which is why UEBA became such an important part of modern security operations today – intersecting data from multiple sources over extended periods of time to build a story indicating risk has become an essential tool to identify malicious actors, both insiders and outsiders.

AI agents are creating a similar challenge in a different form. They can retrieve data, call APIs, invoke tools, interact with users, and act inside business workflows using permissions the organization has deliberately given them. The line between AI agents and human operators is beginning to blur. As access expands, security teams need to understand whether an agent is behaving as expected and how its activity fits into the wider environment.

AI agents can work autonomously using their own access rights, or on behalf of users inheriting their rights – both scenarios are ones that many companies typically struggle to control, but now we have the challenge of agents exploring their “rights perimeter” much faster than any person could achieve, and without any concepts of appropriateness, company loyalties or wisdom.

AEBA, or Agent and Entity Behavior Analytics, applies the same behavioral thinking to this new class of identity. It extends the principles behind UEBA into environments where AI agents are beginning to perform meaningful work on behalf of people and systems.

 

Permission is Not Enough

Traditional access controls tell us whether an identity is allowed to perform an action. However, they say less about whether that action makes sense in context.

An AI agent may be authorized to access a document repository, call a business application, or interact with a mailbox. If the same agent suddenly begins retrieving much more data than usual, accessing unfamiliar repositories, invoking tools it rarely uses, or operating at unusual times, the permissions themselves offer very little insight into whether that behavior deserves attention.

Security teams have dealt with versions of this problem for years. Insider risk and compromised accounts both showed us that legitimate access can still produce risky behavior. UEBA helped teams move beyond isolated events and look at patterns over time, comparing current activity with what was normal for that user or entity.

AI agents require that same depth of context, especially as they become more embedded in day-to-day operations. An agent with permissions to retrieve files and update content – perhaps performing a helpful task of keeping a website updated, is one mistaken prompt and poor access control rules away from publishing any confidential information it might find.

 

Understanding Agent Behavior Over Time

Behavior becomes useful when there is enough history and context around it.

Consider an agent that normally reads a small number of internal documents and prepares summaries for a particular team. Over time, its activity settles into a pattern. It touches familiar repositories, interacts with a known group of users, and invokes a predictable set of tools. If that pattern changes, there may be a perfectly reasonable explanation, but security teams should still be able to see it.

The signals are rarely confined to one event. Changes in access volume, tool usage, application activity, user interaction, or operating times can become meaningful when they are viewed together. An agent that suddenly accesses unfamiliar systems and retrieves more sensitive data than usual may deserve investigation even if every individual action remains technically permitted.

The OpenAI and Hugging Face incident gives us a more extreme example of the same principle. In testing, an OpenAI model reportedly chained vulnerabilities, escalated privileges, gained broader access, and eventually reached Hugging Face infrastructure while pursuing the objective it had been given. The concern was not one action in isolation. It was the progression, the persistence, and the way the model adapted as it moved through the environment.

That is the same reason behavioral analytics became valuable for human identities.

 

What Changes When Agents Start Doing Real Work?

The security implications grow as agents move deeper into operational workflows. An agent that summarizes documents has a limited impact. An agent that can invoke APIs, change a business process, access sensitive information, or act on behalf of a user has a much stronger risk profile. The more authority these systems have, the more important it becomes to understand how that authority is being used.

We can no longer rely on “good users having no malicious intent” – AI agents have no wisdom or intent, they follow their instructions as their training and statistical models allow – they are relentless and also motivated to succeed in their tasks, and as we have seen, have become very successful at quickly expanding their access to data through ACL mistakes, overprovisioning, and even exploitation.

Securonix is applying behavioral analytics across human and non-human identities to help identify abnormal agent behavior, suspicious human-to-agent interactions, unusual tool invocation, unauthorized AI adoption, and potential misuse or compromise. The aim is to bring agent activity into the same security picture teams already use to investigate users, identities, cloud services, endpoints, and applications.

It’s important operationally because SOC teams already have established processes for investigating unusual behavior, correlating activity, escalating risk, and reviewing evidence. They are just applying it to one application, rather than getting ahead of increasingly expanding AI. Agent activity should fit into those workflows rather than creating another isolated discipline that analysts have to manage separately.

 

Behavior and Guardrails

Behavioral analytics can tell a security team that something deserves attention but cannot determine every outcome on its own.

A deviation may indicate misuse, compromise, configuration drift, or simply a legitimate change in the way an agent is being used. Security teams need enough context to understand the difference before consequential action is taken, especially when that action could affect a user, a business process, or a critical system.

That is where governance becomes part of the operating model. Findings should retain the context behind them, investigations should be explainable, and actions should be reviewable and auditable. Human approval should remain available when the potential impact warrants it. Those principles are already central to the way Securonix approaches governed AI across security operations.

As more agent activity becomes automated, the checks an experienced analyst would normally apply need to be reflected in the logic around those workflows. That gives teams room to move faster without giving up control over decisions that carry real consequences.

 

Bringing Agents Into the Security Picture

Security architecture has always had to adapt as new kinds of identities gained access to valuable systems. Cloud identities changed how teams thought about authentication and privilege. Service accounts and machine identities introduced similar challenges because they could perform significant actions without a person sitting behind every transaction.

AI agents are following the same path, with an added layer of complexity because their behavior can change according to context, instructions, and the systems they interact with. UEBA gave security teams a way to understand human and entity behavior beyond a simple access decision. AEBA extends that discipline to agents, helping teams establish expected patterns, identify meaningful deviations, and investigate those changes alongside the rest of the environment.

Security teams will still need people who understand the business, the data, and the consequences of a decision. As agents take on more operational work, those teams need enough behavioral context to know when an agent is acting outside the expected pattern and enough control to decide what happens next. We should be designing security around that operating model now.

 

Start Building Visibility Into Agent Behavior Now

Over the last year, we’ve expanded our UEBA capabilities into AEBA and are regularly publishing new detection policies covering the major AI systems. But this is only the beginning.

The first material AI security incidents are unlikely to start with sophisticated attackers deliberately exploiting autonomous agents. They are more likely to begin with agents doing exactly what they were asked to do, but with more access, more autonomy, or less context than anyone intended.

For CISOs, there is a relatively simple way to test whether the security architecture is keeping pace. Do you know which agents are operating across your environment and whose authority they are using? Can you establish what normal behavior looks like across the identities, data, applications and tools they touch? And would your SOC recognize when an authorized agent began behaving in a way that was technically permitted but operationally abnormal?

If those questions are difficult to answer, there is already a visibility gap.

This is where we’re focused at Securonix. We’re bringing AI agents into the behavioral security model alongside users and other identities, correlating their activity with the broader environment rather than treating AI as another security silo.

We’re creating machine-speed actors that can exercise legitimate permissions across multiple systems, potentially on behalf of humans, and our existing controls were largely designed around human-speed behavior.

If you’re starting to think through how agentic AI changes your security architecture, that’s a conversation we’d welcome. Every organization adopting agents needs an answer to a fundamental question: how will you know when a trusted agent stops behaving like one?