More than 70% of IT security and decision makers expect negative business impact from attacks targeting platforms like Slack, Teams, Zoom in 2026.
Increasingly, the exposure on those platforms comes not from hackers or rogue software, but from sanctioned AI agents duplicating credentials as they pass data between collaboration tools and SaaS platforms, says Mimecast.
“Forget the container escape. Worry about the agents that never needed one. AI agents are spreading credentials across departments through normal handoffs, creating a growing insider risk,” says Heino Gevers, vice-president of global customer value at Mimecast. “The main threat is from credentials being copied between departments by approved AI tools that are doing exactly what they were set up to do.”
“The risk sits where people, data and AI meet,” says Gevers. “An employee makes a judgement call, sensitive data moves, and an agent acts on it. Most organisations watch each of those with a different tool and a different team, so nobody sees the moment they connect.”
How the exposure happens
Gevers says the problem builds through a series of steps that, on their own, seem perfectly reasonable. An employee under time pressure pastes information into an AI assistant or a shared workspace. The paste contains an API key, a database connection string or password. That one credential can open customer records, source code, or the payroll system. Later, an AI assistant in another department that has been connected to the same Slack channel or Jira project indexes that content. The credential now sits in a second team’s tool history.
“Nobody passed the credential on deliberately, and nobody asked for it. It crossed a departmental boundary because the second team’s AI tool was allowed to read the place where it already sat,” he explains.
Gevers says the risk is built into how automated workflows now run. He says a good everyday example is a typical automated onboarding process, where HR data from a platform such as Workday is picked up by one AI agent and passed to another that handles account provisioning, and then on to further agents that set up access to individual tools.
“Every time an agent provisions an account it needs single sign-on access, so personal information and credentials get passed along at each step,” he says.
The same thing happens when employees connect AI assistants to company data sources. Each connector needs credentials, and AI agents increasingly exchange information directly with other agents rather than with the underlying platforms.
Gevers adds that the gap is not about authorisation. “It’s not about accessing privileged information without permission. It’s about what information gets shared between the agents, and there’s very little governance or control over that information and its context.”
Who owns the risk?
Gevers says that, as a rule, accountability sits with the person who approved the AI tool, because that person answers for the tool’s governance and compliance.
This becomes harder to apply when the person who set up the tool months earlier has since left the company. In those cases, he says, organisations need to show how a credential was shared and whether an employee’s instruction caused it.
“It’s about being able to prove the context and how the credential was shared. Did the prompt trigger the AI agent to share it, or did the agent do so on its own? That context determines the action that’s warranted,” he says.
“That evidence only exists if you captured the person, the data and the agent’s action at the same moment,” he adds. “Stitching it back together from separate logs after the fact rarely works.”
Why existing controls fall short
While many organisations try to monitor AI activity with separate tools for each platform, Gevers says each produces its own alerts, making it hard to tell which to deal with first. “It’s 50 separate investigations and 50 separate remediation events, as opposed to one. This obviously takes time, adding to the risk exposure quite significantly.”
That gap shows up in the data. The Mimecast State of Human Risk 2026 report found that 38% of SA organisations still rely solely on the security built into their collaboration tools, while 62% acknowledge that native security is insufficient.
It’s here that many organisations lose sight of the reality they face. “If you’re relying on people to manually join the dots across separate tools you will fail. You need one platform that sees the human, the data and the agent together, and uses AI to prioritise what matters,” he says.
Stop looking for the breach, start watching the drift
Gevers frames the response in three steps: identify, govern and intervene. Identifying means working out how exposed the organisation already is: which agents exist, what they connect to, who owns them, and where credentials already sit. Governing means defining which AI tools are approved, assigning a named human owner to every agent, and making sure employees understand the usage policy.
Intervening means applying controls at the moment of risk, ranging from outright blocks for high-risk groups and data types, to prompts that ask users to confirm before sharing sensitive information. Every confirmation should be logged so it can serve as evidence later. That same record answers the accountability question if something does go wrong.
Gevers says security leaders need one connected view of how people, data and AI agents interact across endpoints, browsers, SaaS platforms, email and Model Context Protocol (MCP) connections (links that plug AI agents into company systems).
With this visibility, teams can quickly separate normal behaviour for every agent and flag drift to identify unauthorised agents and unusual attempts by agents to access data. Instead of being buried in separate log files that someone must investigate later, these risks should appear as prioritised, actionable alerts.
“The industry must move on from judging agents in a vacuum to tying every agent back to a human owner, a data footprint, and a baseline of normal behaviour. As AI agents take on tasks that employees previously completed manually, security teams need the same level of visibility into what agents do as they have long had for human activity,” Gevers says.
“You can’t get there with a patchwork of point tools. It takes a single platform that governs the point where people, data and AI meet,” he concludes.