What Can Your AI Agent Reach Beyond Its Assigned Task?

An AI tool assigned to help your sales team could have a path to data it was never meant to use, according to Token Security’s Itamar Apelblat. In his contributed article in The Hacker News, Apelblat describes AI agents as systems that pursue a task by trying actions, using tools, and changing direction when an approach fails.

For business owners, Apelblat’s warning is about both access and independence: the risk depends on what an agent can reach and how much it can do without a person’s approval. Apelblat argues that reviewing only the tools assigned directly to an agent misses the routes those tools can open.

What is lateral movement in an AI attack?

In Apelblat’s account, lateral movement means moving from one system or account into others through available connections and access. According to Apelblat, AI agents can test thousands of actions, abandon failed routes, find sign-in details, and keep exploring.

Apelblat cites roughly 17,600 attacker actions reconstructed in Hugging Face’s technical review of a July 2026 incident during a cybersecurity evaluation. Most attempts failed, according to his account, but enough connected to create a route through several independent systems. Apelblat’s point is persistence as well as speed: agents can keep testing routes long after a person might stop.

How can a sales tool reach unrelated data?

Apelblat describes an environment reviewed by Token Security where a sales agent could reach powerful data access through a stored sign-in detail exposed by another tool. According to Apelblat, the agent had Salesforce access appropriate to its sales task, but also had broader-than-needed permissions in Vercel.

In Token Security’s example, Apelblat says the Vercel access exposed a stored credential—a sign-in detail—belonging to a separate software identity, meaning an account used by software rather than a person. That account had administrator-level access in Snowflake, according to Apelblat. The sales agent had no Snowflake account of its own, Apelblat notes, yet a route to the data still existed.

What should an owner ask IT to check?

Apelblat recommends reviewing each agent’s purpose, accountable owner, and complete access path rather than checking its initial permissions alone. Turn that recommendation into a practical review:

  • Purpose: Write down the job the agent is supposed to complete.
  • Ownership: Name the person responsible for its access and retirement.
  • Reach: Ask which other accounts and data its connected tools make available.
  • Cleanup: Remove unnecessary permissions and revoke unused sign-in details.

Apelblat also warns that filters on what an agent receives or says do not determine which systems its accounts can reach. According to Apelblat, access needs continued review as agents gain tools, change purpose, or stop being used.

Start with one AI agent your team already uses. Ask your IT provider or internal IT lead to document its owner, assigned task, and full access path, then identify any access that does not serve that task.


How this post was made. Brian M. McCarthy shared a link in one of our Teams channels. From there the article, its headline and its header image were generated by AI, and then read and approved by a person at Open Tier Systems before any of it was published — nothing reaches this blog unread. We work this way on purpose: it is the same kind of automation we build for our Clients, and showing you what it can do beats describing it.

About The Author

Brian McCarthy

Share This Post

Post Meta

Table Of Contents

Recent Posts

Featured Review

testimonial

Tortoise and Hare has been a key partner in our MSP's growth. Over the year's we've worked together they've helped our MSP dramatically increase our website traffic, and build a steady stream of leads sourced from our website and advertising efforts. Over that time, we've been able to raise our base customer size, build economies of scale to more efficiently service customers, and expand into new markets.

R.D.
President Regional MSP

Open Tier Systems

We Get IT Done
IT For Eastern Pennsylvania Businesses
Home » Blog » What Can Your AI Agent Reach Beyond Its Assigned Task?

Visit Us On Social Media

More About Our Open Tier Systems

Managed IT, Voice, AI and Compliance

Locations We Serve

Policies and Terms

Proudly Serving The State Of Pennsylvania

© 2018-2026 Open Tier Systems. All Rights Reserved.
This site content may not be copied, reproduced, or redistributed without the prior written permission of Open Tier Systems or its affiliates.