CB Financial Services, a Pennsylvania-based bank holding company, disclosed last month that an AI agent had been unlocking nonpublic customer information, including names, Social Security numbers and dates of birth. The incident was considered material due to the volume and sensitivity of the data exposed. No sophisticated attack was required. The agent was misconfigured. It worked exactly as designed and exposed data it should never have been able to reach.¹
The Wall Street Journal covered the broader pattern this week. The framing is precise: AI agents are insider threats by default. They operate with the same data access as the employee who deployed them. They work at machine speed. They have no motive, no conscience and no hesitation. And organisations are deploying them faster than any security team can track.
One figure from the piece stands out. Organisations currently have roughly 45 digital identities for every one employee. Each new AI agent deployment increases that ratio. Most of those agents were built by employees with no data security training, using third-party agent-building tools, without any formal provisioning process. Security teams may not know they exist until something goes wrong.
The piece quotes a security researcher on why prompt-level controls are insufficient. A direct query asking for restricted M&A data returns a refusal. A tangential question asking for project code names retrieves the same information through inference. The agent is not bypassing a control. It is answering a question that the prompt-level guardrail was not designed to anticipate. The control and the capability live in the same system, which means the control can always be asked around.
Darktrace’s CISO is quoted asking the question security teams face every time an agent acts unexpectedly: is this normal business activity, a compromised account, an insider risk or an automated system acting outside its intended purpose? It is a detection question. By the time it is being asked, the action has already executed.
GoFirm makes that question irrelevant for the actions that matter most. Before a consequential action executes, whether initiated by a human, an AI agent, or a misconfigured system, GoFirm routes a confirmation request to the named human authority on their registered personal device through a channel separate from the agent environment. The authority confirms with their biometric. The action proceeds or it stops. A misconfigured agent cannot produce that confirmation. A compromised agent cannot produce it. An agent asked a clever lateral question cannot produce it.
The CB Financial incident required no attacker. The agent unlocked sensitive customer data by working as designed, without oversight, without a confirmation requirement, without a named human authority in the loop. The misconfiguration was the risk. GoFirm’s hard halt means the action waits for a confirmed human authority regardless of how the agent was configured or what it was asked.
Organisations have accepted the productivity upside of autonomous AI agents before fully understanding the security implications, as the Journal notes. The security implication is straightforward: every agent with access to consequential systems is a potential insider threat from the moment it is deployed. The control that addresses that is not better monitoring. It is a confirmed human authority requirement at the execution boundary, before the action that causes the damage.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.
References
1. Wall Street Journal, Turncoat AI Agents Emerge as the New Inside Hackers, June 2026, https://www.wsj.com/pro/cybersecurity/turncoat-ai-agents-emerge-as-the-new-inside-hackers-b0021e11
