Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
AI Agent Runs Amok in Your ERP: What 58% of Teams Learned Too LateTechnical Controls
5 min readFor Risk Managers

AI Agent Runs Amok in Your ERP: What 58% of Teams Learned Too Late

The Growing Threat

Between mid-2025 and mid-2026, nearly 22% of organizations using SAP, Salesforce, or Oracle ERP systems experienced security incidents where attackers used AI against their critical platforms. Another 15.2% suspected such incidents but couldn't confirm them.

This wasn't a typical breach. The incidents involved authorized AI agents with legitimate credentials taking harmful actions within ERP systems. No stolen passwords or unpatched vulnerabilities were involved, just agents doing what they were told or manipulated into doing.

The scale is alarming. A June 2026 survey of 204 senior cybersecurity leaders at U.S. organizations with over 1,000 employees found that 58% had deployed AI applications or agents interacting with their ERP systems in the past six months. Over 62% already use AI-generated code in ERP applications. Yet, more than 70% of these leaders expressed limited or no trust in AI protecting their critical data.

Rapid Integration and Consequences

The timeline of AI integration into ERP systems shows a rapid acceleration:

H2 2025: Organizations quickly integrate AI agents into ERP platforms, driven by vendor feature releases and competitive pressure to automate finance, procurement, and supply-chain processes.

Q1 2026: The first wave of incidents emerges. Teams report AI-assisted social engineering attacks bypassing traditional phishing detection. Attackers use AI to analyze ERP code libraries and create specialized payloads targeting application-layer vulnerabilities.

Q2 2026: A new incident category appears. Authorized agents with valid credentials cause harm, not through breaches, but because they were manipulated or acted within their approved permissions.

June 2026: Survey data highlights a trust gap. Nearly 69% of cybersecurity leaders lack confidence in detecting AI-based attacks. Security teams are the most resistant to further AI integration, with 41.4% of respondents objecting to AI in ERP environments.

Control Failures

The incidents reveal gaps in three control areas:

Identity and Access Management: AI agents were given broad permissions without distinct identities, often using shared service accounts or inheriting user-level access rights. When compromised, the impact spread across everything the identity could access.

Change Management and Code Review: Organizations deployed AI-generated code into business workflows without security testing, code analysis, or threat modeling. No validation was done to check if the code introduced vulnerabilities or faulty access checks.

Monitoring and Accountability: Agents acted without adequate logging. When harmful outcomes occurred, teams couldn't trace what the agent did, why it did it, or who was responsible for deploying it. Nearly 15% of suspected incidents couldn't be confirmed due to lack of evidence.

The core issue: treating AI agents as productivity tools rather than privileged identities requiring the same rigor as human users.

Standards and Requirements

ISO/IEC 27001 Annex A.9.2 (User Access Management) requires formal user access provisioning processes, including granting and revoking access rights. AI agents need distinct identities, documented access requests, and approval workflows.

NIST Cybersecurity Framework (CSF) 2.0 PR.AC-4 mandates managing access permissions and authorizations, incorporating the Principle of Least Privilege and separation of duties. An agent that can read, write, and approve transactions in your ERP violates this control.

ISO/IEC 27002 Control 8.2 (Privileged Access Rights) requires restricting and controlling the allocation and use of privileged access rights. If your agent can modify financial records or procurement approvals, it holds privileged access and must be managed accordingly.

NIST AI Risk Management Framework emphasizes accountability and transparency throughout the AI lifecycle. You can't meet this if you don't know which agent took which action or who approved its deployment.

SOC 2 Type II auditors evaluate logical access controls over time. Granting agents access without tracking their actions or reviewing their permissions will result in failing CC6.1 (logical and physical access controls) during your next audit.

Actionable Steps for Your Team

Treat every agent like a new hire. Create a distinct identity for each agent. Grant only the minimum permissions needed for its specific function. Expand access only when the agent proves reliable. This approach mirrors how you'd onboard a human with the same level of system access.

Gate the feature, not the vendor. Before deploying any AI capability in your ERP, ask these questions: Can it be turned off? What identity does it act as? What does it log when it acts? Can its access be scoped separately from the user's? If the vendor can't answer these, defer deployment.

Implement segregation of duties for agents. Your ERP already enforces separation between who can create and who can approve a purchase order. Apply the same logic to agents. An agent that reads data shouldn't write data. An agent that writes shouldn't approve.

Test permissions before granting write access. Run the agent in a sandbox environment. Map its downstream effects. If it can change an ERP record, ensure it can't cascade into unintended modifications across related transactions. Don't activate it until you've seen what it does.

Require human accountability for agent actions. Assign a named individual responsible for each agent's deployment, configuration, and oversight. When something goes wrong, you need to know who approved the agent's production deployment.

Apply your change management process to AI-generated code. Security testing, code analysis, and threat modeling are essential, even for AI-written code. Treat AI-generated code like any other third-party contribution -- review it before it enters your business workflows.

Log everything agents do. You can't investigate what you can't see. Ensure your ERP logging captures agent actions with the same detail as human user actions: who (which agent identity), what (which operation), when, and on which records.

Nearly 57% of organizations reported at least one business unit objecting to AI in their ERP environment. Security was the most resistant function, citing lack of confidence in AI security (75%) and compliance risk (71.6%).

This resistance isn't obstruction. It's pattern recognition. Your security team knows what happens when you grant broad access without controls, deploy code without testing, and operate systems without accountability. The technology changed. The fundamentals didn't.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like