Recent security evaluations by OpenAI and Anthropic should get the attention of every security leader considering AI.
In OpenAI’s evaluation, models operating in a highly controlled environment found and exploited a zero-day vulnerability, escalated privileges, moved laterally, and eventually reached infrastructure with internet access. Anthropic later disclosed three incidents in which Claude models crossed similar evaluation boundaries and gained unauthorized access to real-world systems.
These were controlled environments designed specifically to evaluate model behavior. Even there, the boundaries did not hold as expected.
AI systems do not necessarily remain confined to the access they were given at the start. They can find new paths, exploit connections, and acquire additional privileges that expand what they can reach and do.
For enterprise leaders, understanding what access an AI system starts with is only part of the picture. They also need to know how privileged it can become.
Every AI security conversation eventually becomes a conversation about privilege.
AI changes how privilege can be used
Security teams already understand privilege escalation, excessive access, weak segmentation, and lateral movement. AI increases the speed, scale, and flexibility with which those problems can unfold.
An AI agent can operate continuously, move across systems in seconds, call tools, use delegated identities, and adjust when one path fails. It does not need to stop and ask whether the next action is appropriate. If one route is blocked, it may find another through inherited permissions, connected services, vulnerable infrastructure, or another agent.
That makes privilege much harder to judge at a single point in time because an identity that looks narrowly scoped at the start of a task may not stay that way.
Its effective reach can expand as it discovers new connections, invokes additional tools, or accumulates access along the way.
The OpenAI evaluation is a useful example. Looking only at the models’ original permissions would have missed the larger risk. What mattered was what they could reach from there, how they could move, and what additional privileges they could gain.
Security teams now have to evaluate privilege as something dynamic, including both the access an AI identity has today and what that access could enable next.
The binary definition of privilege no longer holds
For years, privileged access was relatively easy to recognize. Administrators, root accounts, and a small set of high-access users sat on one side of the line. Everyone else sat on the other side.
That model is getting harder to defend as access becomes more contextual. A customer service agent may not have administrative rights, but they could still retrieve thousands of sensitive customer records. A development agent may start with limited access, then interact with repositories, credentials, build pipelines, and cloud services, creating a path to more sensitive systems. A non-human identity may hold only one narrow permission, but that permission becomes far more consequential when it is persistent, exercised at scale, or combined with other access.
Privilege increasingly operates on a spectrum rather than fitting neatly into a binary category.
Every identity can become privileged under the right conditions, and the level of risk will vary widely depending on what that identity can reach and do. Context matters: what the identity can reach, what actions it can take, how quickly it can act, and what other systems or identities it can influence.
Organizations need to move beyond asking, “Is this identity privileged?” and start asking, “How privileged is this identity, and what level of control does that privilege require?”
Controls should follow the level of privilege
Once privilege is understood as a spectrum, controls can be matched more closely to the level of risk.
An identity with limited reach and a narrow purpose should not be governed the same way as one that can access sensitive systems, invoke powerful tools, or act across multiple environments at machine speed. As privilege increases, so should the strength and immediacy of the controls around it.
That may mean tighter least-privilege policies, temporary or just-in-time access, Zero Standing Privilege, stronger review requirements, or runtime authorization for higher-risk actions. The specific mechanism will vary, but access decisions should reflect what an identity can actually do and should change as its privilege and risk change.
For AI agents, this becomes especially important. Controls should create boundaries that match the agent’s purpose, reach, and potential impact without unnecessarily constraining autonomy.
Done well, that gives security teams more precise control without forcing developers and business users through the same heavy process for every action. It also gives organizations a more practical way to scale AI without having to choose between speed and control.
The market is converging on identity and privilege
Recent activity across AI security, data security, and non-human identity management suggests the market is starting to connect problems that were once treated separately.
Organizations increasingly need to understand which data and systems are sensitive, which identities can access them, what privileges those identities hold, and how that access changes over time.
AI agents make those relationships more dynamic because their identities, access, and actions can change as they operate.
AI systems need identities. Those identities need owners, defined purposes, and access that changes as their roles and risk change. Visibility provides the starting point. Organizations still need to govern what an identity is permitted to do once it begins acting across the enterprise.
Model security and data protection remain essential parts of the picture. Governing the actions an AI identity takes across applications, infrastructure, data, and other identities requires identity-level control as well.
That is why identity remains such a durable control point. Every action eventually depends on an actor receiving permission to access something. Governing that privilege is becoming central to how organizations secure AI at scale.
Govern how privileged every identity can become
The OpenAI evaluation is worth returning to because it shows how quickly the meaning of privilege can change. Even in a controlled environment, the models found paths through software vulnerabilities, connected infrastructure, and available privileges, expanding what they could reach and do.
Enterprise environments will be far more complex. AI agents will interact with human accounts, non-human and cloud identities, APIs, applications, models, data, and other agents. Each connection can change what the agent is effectively able to reach and do.
Organizations therefore cannot assume an identity will remain at the privilege level it was originally assigned. As identities act, connect, delegate, and evolve, their effective privilege can change with them.
For executives, the priority is to make sure governance and controls keep pace.
Effective AI security depends on how precisely organizations understand and govern privilege across every identity, including how that privilege changes as identities act, connect, and evolve.
Ready to rethink privilege beyond the binary? Watch The Privilege Spectrum webinar on demand to learn how to secure human, non-human, cloud, and AI identities.