New capabilities in the BeyondTrust Pathfinder Platform secure AI agent coworkers on endpoints and AI agent workloads across cloud infrastructure and SaaS platforms
BeyondTrust, the global leader in privilege-centric identity security, has announced expanded capabilities across its Pathfinder Platform. This update delivers the industry’s first unified approach to securing AI agent coworkers and autonomous AI workloads across cloud and SaaS environments. The launch is supported by new research from BeyondTrust Phantom Labs™, which revealed that most enterprises are running “shadow AI agents” with privileged access that bypasses traditional security oversight.
AI agents have transitioned from experimental tools to production workloads that initiate API calls, deploy code, and access sensitive data. In many environments, these machine identities now outnumber human identities, significantly expanding the attack surface. BeyondTrust’s unified approach aims to close the visibility gap between AI, human, and machine identities.
Unified Security for AI Coworkers and Workloads
The Pathfinder Platform is designed to defend both “AI coworkers” (local agents on endpoints) and autonomous “AI workloads” running in the cloud. Key features include:
- Endpoint Privilege Enforcement: BeyondTrust Endpoint Privilege Management (EPM) enforces least privilege for AI clients like ChatGPT and Claude, ensuring they only perform authorized actions.
- AI Agent Discovery and Risk Analysis: Identity Security Insights® provides automated discovery and risk scoring across platforms like OpenAI, Google Vertex AI, Salesforce Agentforce, and AWS Bedrock.
- Secrets Management: BeyondTrust Password Safe® manages the API keys and credentials used by autonomous agents, eliminating static credential exposure.
Managing the Surge of Non-Human Identities
Telemetry from the Pathfinder Platform shows a 466.7% increase in enterprise AI agents over the past year. Many of these are deployed via low-code platforms, often inheriting administrative privileges without the knowledge of security teams. Marc Maiffret, CTO at BeyondTrust, emphasized that a single compromised AI agent can escalate access across identity providers, cloud infrastructure, and SaaS platforms simultaneously.
Complimentary AI Security Posture Assessment
To help organizations identify these hidden risks, BeyondTrust now includes AI agent risk analysis in its Identity Security Risk Assessment (ISRA). This complimentary service provides a full inventory of AI agents, shadow AI detection, and privilege path analysis mapped to the MITRE ATT&CK framework within 24 hours.