Not all insider risk is the same; the employee who clicks a phishing link isn’t the same problem as one deliberately selling IP to a competitor. And right now, organisations are deploying agentic AI systems with identities, access, persistent memory, and the ability to act inside business processes. And we are making the same mistake again: treating all agent risk as a single, adversarial problem.
This talk looks at the parallels between human insider risk management and agentic AI security. We map the human insider risk spectrum: unaware, incompetent, disobedient, and malicious, onto four AI agent archetypes, identify which controls actually reduce risk and relate this to the concept of a semantic layer: the agent equivalent of onboarding, culture, and supervision.
The takeaway: we don’t need a new playbook. We need to remember and act on the one we already wrote for people and apply it to machines.