Your CoPilot May Be Plotting Against You (Maybe)
- By Winston Thomas
- February 16, 2025

2025 is shaping up to be the year when AI is a savior and a nemesis. As companies rush to embrace AI agents and copilots, they’re unwittingly creating an unprecedented security nightmare: for every human user, there will soon be 100 AI bots operating within enterprise systems.
“We saw about 45 machine identities per human user on average in 2024. With the new AI bots and agents, it will exponentially grow,” warns Omer Grossman, global chief information officer at CyberArk. “You need to govern them.”
This explosive growth in machine identities represents a seismic shift in enterprise security, one that most CISOs and AI engineers are still struggling to grasp. While companies experimented with AI throughout 2024, 2025 marks the transition from cautious trials to full-scale deployment — and with it, an entirely new attack surface that makes traditional cloud security concerns look quaint by comparison.
AI’s triple acts of threat
The AI security landscape is evolving along three distinct vectors. First, there’s the weaponization of AI by attackers. Think beyond simple phishing emails — we’re entering an era where social engineering attacks leverage perfect voice clones of CEOs, making even the most security-conscious support teams vulnerable to manipulation.
Second, there’s the emergence of AI systems themselves as prime targets. From prompt injection to data poisoning, attackers are probing AI models for weaknesses with the same fervor they once reserved for network vulnerabilities. As Grossman puts it, “It’s cloud adoption all over again, but with higher stakes.”
The third vector? The desperate race to deploy AI as a defense mechanism. “2025 will be the year security vendors must leverage AI capabilities at scale,” says Grossman. But here’s the catch: most security teams are still operating with AI features bolted onto legacy architectures, rather than fundamental AI-driven redesigns.
The shadow (AI) wars
Underneath these vectors, another problem is emerging. Remember shadow IT? That is child’s play compared to what security teams are facing now. “You have now two to three dozen new copilots from startups that you didn’t know about yesterday,” Grossman reveals. Companies are frantically trying to monitor not just unauthorized software, but entire AI ecosystems sprouting up within their companies in record time.
This proliferation of AI tools creates a perfect storm: each copilot potentially has access to sensitive company information, creating what Grossman calls a “spaghetti-like system architecture” where everything is interweaved. The challenge isn’t just about controlling access — it’s about understanding the complex web of AI interactions happening beneath the surface. It also means that data and AI governance will become a security matter, not just a compliance headache.
Insider threat upgrade
But here’s where it gets really scary: the transformation of insider threats. We’re no longer just worried about disgruntled employees, careless clicks, or the occasional infiltration by those with malicious intent.

Today, you only need to inject AI agents into the AI ecosystem. Such agents are already showing signs of autonomous behavior, with documented cases of AI systems attempting to evade controls and persist on servers, says Grossman. “Attackers might use the AI new attack surface to get agents in your organization to do things on their behalf.”
In some cases, you don’t need malicious AI agents. “They will just need to hijack the already-existing agents you have on your endpoint.” As companies embrace Agentic AI, this problem is further compounded as machines may be compromising other machines at the speed of light.
The developer dilemma
At the heart of this AI security crisis lies a fundamental tension: developers, the new holders of the “keys to the kingdom,” need flexibility to innovate, but their access to production environments creates unprecedented security havoc. Traditional IT controls don’t work here — you can’t lock down development teams the way you once restricted system administrators.
The solution? A new paradigm called “zero standing privilege” where access is granted just in time and automatically revoked when not needed. “An attacker will try to connect after the developer connected, but won’t have anything,” Grossman explains, describing how this approach neutralizes post-authentication attacks.
Decoding AI Trust
So what should companies aim for in terms of AI security? Grossman points to trust. He sees it as the new currency that’s emerging in the cybersecurity world.
“Trust is the most important currency in cyberspace,” he emphasizes. This isn’t just about vendor relationships — it’s about building a new security architecture where trust is continuously verified and strictly governed.
The industry is also witnessing a consolidation around trust, with companies preferring fewer, more trusted vendors offering comprehensive solutions, observes Grossman. It's also a knee-jerk reaction to the complexity of securing AI systems, where the old model of piecing together point solutions is becoming unsustainable.
Get ready for the AI security transition
As we move deeper into 2025, the distinction between AI security and traditional cybersecurity will blur further. Grossman urges companies to evolve from thinking about securing AI tools to understanding that AI is fundamentally reshaping the security landscape itself.
The companies that survive this transition in thinking will be those that recognize AI security isn’t just about protecting AI systems — it’s about building a new security paradigm for a world where machine identities outnumber human users.
In this new reality, the question isn’t whether AI will transform security, but whether our security frameworks can keep up with AI’s split personality.
Image credit: iStockphoto/Andreus
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.