Skip to content

GenAI in the Enterprise: How Excessive Permissions Escalate Ransomware Risks

In brief: Excessive permissions for GenAI systems in the enterprise can accelerate ransomware attacks; identity controls and least-privilege access are fundamental requirements for secure AI adoption.

Enterprise GenAI systems can accelerate ransomware attacks when AI assistants and agents are granted excessive permissions or leverage compromised identities. Identity controls and least-privilege access significantly reduce these risks.

Generative AI models in enterprise environments introduce new attack vectors. When AI assistants and autonomous agents are granted overly broad permissions — such as access to file systems, cloud storage, or backup infrastructure — attackers can exploit these as leverage points to deploy ransomware faster and circumvent defense mechanisms.

Acronis points out that the key to risk mitigation lies in three pillars: first, strict identity controls that ensure only authenticated and authorized identities gain access; second, well-designed governance structures that monitor and constrain AI systems; third, the principle of least-privilege access, whereby every system — including AI agents — receives only the minimum necessary rights. These measures reduce the risk that compromised or misused identities can be amplified through AI systems.

For CISOs, this means: secure AI adoption requires upstream architectural decisions. AI systems should not operate with administrative or uncontrolled access, but should be deployed in isolated, tightly controlled perimeters, similar to how Zero-Trust principles are applied to traditional IT resources.


Source: www.bleepingcomputer.com · Published July 22, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: