AI Principals: The Monster Hiding in Your Agent Count
Your enterprise runs 79 AI agents per human employee — and roughly 60 of them are shadow agents no one inventoried.
But the real monster is that nobody is counting the AI Principals issuing their commands.
Every stat you've read this year measures identities. Agent counts, machine identities, credential sprawl, token hygiene. Useful. Also the wrong unit of analysis.
AI Principal is not an identity. AI Principal is code with creation authority — a program that spins up a thousand agents from a loop, orchestrates them, fine-tunes their models, and rewrites the instructions they act on. It doesn't show up as one more entry in your inventory. It's the thing generating the entries.
That's the distinction the entire industry is missing. And here's what the identity data proves about the blast radius:
- →75% of CISOs have already found unsanctioned AI running in production. The other 25% haven't checked. (Saviynt CISO AI Risk Report 2026)
- →70% grant AI systems more access than they'd give a human doing the identical job. Only 44% have any policy governing agents. (2026 Infrastructure Identity Survey)
- →Active agents in Microsoft 365 alone grew 15x year over year. (Microsoft, 2026)
Read those as output metrics and the attack path is obvious.
You don't compromise 500 agents. You compromise one AI Principal — and it manufactures them for you. Authenticated, over-privileged, unowned, behaving exactly as specified.
Worse: an injected AI Principal doesn't just clone. It trains. Poison the fine-tune and the backdoor isn't in the prompt or the payload — it's in the weights. The agent isn't misbehaving. It's doing precisely what it was taught, and it will keep doing it after you rotate every credential in the environment.
EDR and XDR treat agents as generic applications. Agentic AI security watches agent runtime — prompts, outputs, tool calls. Both are looking downstream at the product.
Neither has any concept of the program that issued the instruction, or of the pipeline that shaped the model behind it. There's no signature to match, no process to kill, no prompt to filter. A malicious AI Principal isn't an anomaly — it's a legitimate creator doing legitimate creation.
And this compounds. Every infected AI Principal seeds agents. Those agents inherit tooling and spawn more. The population grows at machine speed while governance moves at audit-cycle speed. That isn't a detection gap. It's a breeding program running inside your environment with valid credentials.
Andeavour #AgentGuard is built for that layer — not just the agents, but the thing that makes the agent.
Everyone else is guarding the exit.
If your AI security roadmap has no line item for the creation layer, you don't have an AI security roadmap. You have a prompt filter.
For the full reference — formal definition, Principal types, attack scenarios, Principal vs AI agent vs non-human identity, controls and sources — read our cornerstone guide.
What Is an AI Principal? Definition, Examples, Risks & Controls