AI Agents Follow Rules, but Data Still Leaks Through Identity Gaps
A recent IBM Consulting engagement revealed that even when every AI agent follows the rules, data can still leak due to a lack of visibility and control. The client, a pharmaceutical company, faced a potential GDPR fine of up to EUR 50 million for unauthorized access to personal data.
The issue arose from the way AI agents interact with different systems, creating an identity boundary that's easy to overlook. Even when each team has sensible access within its own system, no single system can see the whole picture. This leads to a situation where the user asks an innocent question, and the agent selects a tool that queries a system, returning data that the user shouldn't have unlocked.
The IBM Cost of a Data Breach Report found that 21% of organizations reported AI-related breaches in 2026, averaging USD 5.33 million each. The causes of these breaches mirrored those seen in non-AI related breaches, highlighting identity, integration, and classification failures. The report exposed three gaps in data security: identity, encryption, and visibility into shadow AI.