AI Bots Still Masquerading as Humans in Online Logins

www.news4hackers.com-ai-bots-still-masquerading-as-humans-in-online-logins-ai-bots-still-masquerading-as-humans-in-online-logins

AI agents increasingly rely on human credentials, creating security challenges as enterprises adopt hybrid AI ecosystems.

Okta’s Analysis of Anonymized Sign-On Data

Okta’s research analyzed anonymized sign-on data from over 20,000 organizations between June 2022 and June 2026, tracking AI tool proliferation through corporate single sign-on systems. The study cataloged over 100 distinct AI products, consolidating them into 74 vendor suites categorized by functions such as foundational models, developer tools, and enterprise search.

The Dual Growth Trajectory of AI Vendors

Okta’s Enterprise AI Index divided vendors into two groups based on enterprise customer growth rates. AI-focused startups like Anthropic, OpenAI, and Cursor achieved over fourfold expansion in corporate user bases, while established providers such as Microsoft, Google Workspace, and Adobe showed more measured growth. Both segments expanded their market presence, with startups capturing new use cases and legacy vendors integrating AI into existing customer bases.

Fei Liu, Okta’s Principal Emerging Tech Researcher, emphasized the need for a paradigm shift in security strategies, advocating for treating AI integration as an expansion of identity infrastructure rather than simple software addition.

The Evolution of AI Implementation

The shift from basic assistance to autonomous execution marked AI development. Early systems handled code completion and query responses, but the development cycle advanced through three phases: autocomplete, chat-based interaction, and agent-driven workflows. By spring 2025, coding tools began executing extended task chains with minimal human intervention, allowing modern systems to navigate codebases and complete multi-step processes independently.

Credential Proliferation and Security Risks

Each new AI system introduces unique authentication requirements, with chat and agent functionalities relying on secrets and tokens. This practice increases platform diversity and security risks. Okta’s research highlights growing concerns about over-permissioned applications and orphaned tokens as AI platforms proliferate.

Liu noted that traditional authentication methods remain prevalent for AI agents, with many organizations relying on service accounts, static API keys, and shared human credentials to authorize automated workflows. This creates audit challenges, as agent activities under human accounts obscure the distinction between human and automated actions.

Unregulated AI Usage Beyond Sanctioned Systems

A significant portion of AI activity occurs outside officially approved tools, as employees deploy personal cloud instances or use unapproved models through individual accounts. Liu observed that this shadow AI infrastructure often exceeds the scale of sanctioned implementations. The primary risk involves unmonitored data handling, as employees using personal accounts to access unsanctioned large language models may expose sensitive information through prompts containing proprietary code or customer data.

Okta recommends evaluating three critical factors for every AI agent: deployment environment, connectivity capabilities, and operational permissions. The demand for dedicated non-human identities with managed lifecycles and access reviews is increasing.

Conclusion

Enterprise security teams must adapt to the evolving landscape of AI-driven workflows while maintaining strict control over credential usage and data access. Centralized identity management remains critical to addressing challenges posed by the growing complexity of AI authentication requirements.



About Author

en_USEnglish