Six months ago, a developer on your team built an AI agent to automate invoice matching. The project wrapped up. The developer moved to a different team. But nobody ever turned the agent off.
It’s still running. Still holding valid credentials. Still able to touch your systems. And nobody on your team even remembers it exists.
That’s a zombie agent. And if you’re running AI agents anywhere in your environment, there’s a good chance you already have a few wandering around unsupervised.
This post breaks down what zombie agents actually are, how they get created, and why they’re becoming one of the more pressing risks in agentic AI security.
What Makes an Agent a “Zombie”
A zombie agent is an AI agent that still has access, power, or the ability to act on its own, long after it should have lost that access. It’s lost its purpose, owner, or oversight, but it hasn’t lost its keys.
It’s like an employee badge that still opens the building three years after someone quit. The person is gone, but the access never got revoked. Now apply that same idea to a piece of software that can log into your CRM or move money between accounts, and you can see why this matters.
How Does an Agent Turn Into a Zombie
Most zombie agents are the result of ordinary, everyday IT habits that just weren’t built with AI agents in mind.
Here’s how it goes: a team builds an agent to handle a repetitive task, like updating CRM records or orchestrating cloud infrastructure. To get it working fast, they attach it to a static service account or a raw API key that never expires. The project finishes. The developer changes teams. The employee leaves the company. But the agent keeps running, because nothing was ever built to stop it. Or offboard it.
Traditional identity systems weren’t designed with agents in mind, so agent access often becomes an afterthought. The credentials stay valid and sessions stay active. And the agent becomes a permanent, unmonitored backdoor into your core systems.
There’s a second, more aggressive way agents go rogue. Security researchers have documented an attack pattern where a hijacked AI assistant gets tricked through hidden instructions buried in an email or document, rewriting its own memory so it keeps following an attacker’s commands even after the original file is deleted. This is a growing external threat, which is different from the internal one commercial teams are dealing with today.
How Big Is This Problem?
AI agents are just one part of a much larger explosion in non-human identities (NHIs). According to our Q3 2026 IT Trends Report, NHIs now outnumber human employees in 53% of organizations, and nearly a quarter of those companies manage six NHIs for every single human worker.
That kind of volume makes manual tracking basically impossible. We found that 92% of organizations struggle to scale agents safely because their tools remain siloed and disconnected from each other. When agents and employees live in separate systems, IT can’t confirm whether an agent’s actions actually match what the person who triggered it intended.
Only 17% of organizations have a designated security leader responsible for AI agent actions, and 47% default that job to IT without ever making a real decision about it. That’s a lot of agents running around with nobody clearly on the hook for what they do.
How Many Zombie Agents Do You Already Have?
To find out how many zombie agents are hiding in your network, you have to look at how you manage NHIs. NHIs now outnumber human workers by 144 to 1, and 97% are overpermissioned. Since developers often set up these AI agents without telling IT, many companies simply lose track of them.
You can evaluate your actual exposure by examining your lifecycle governance, access constraints, and credential hygiene.
Take the quiz below to estimate the severity of your zombie agent footprint.
Midnight Blizzard: A Case Study
You don’t have to imagine what happens when an abandoned identity gets exploited. It already happened to Microsoft.
Between November 2023 and January 2024, the threat group known as Midnight Blizzard (APT29) broke into Microsoft’s corporate systems by targeting a legacy, non-production test account that had been left behind without multi-factor authentication. That account led them to a forgotten OAuth application still holding powerful, standing permissions inside Microsoft’s production tenant. From there, attackers created a new admin-level user, spun up more malicious apps, and quietly exfiltrated sensitive emails from senior leadership and security teams.
Nobody hacked in through some sophisticated zero-day exploit. They walked in through a door that should have been locked years earlier. That’s exactly the fault line zombie agents sit on: forgotten access, standing privileges, and no one watching.
Ready to Find Your Zombie Agents?
Zombie agents are a natural byproduct of how quickly teams are deploying AI agents without updating the identity and access habits meant to govern them. Every agent that’s missing a clear owner, a defined lifecycle, and an expiration date is a zombie agent waiting to go rogue.
You don’t need to rebuild your entire security stack to fix this. You need to extend the identity, device, and access discipline you already run for your human workforce to cover your agents too.
Want the full playbook for finding, governing, and permanently retiring zombie agents before they become your next headline? Download our eBook, AI Agents Are New. Your Security Foundation Doesn’t Have to Be, and get the complete guide to securing every identity running in your environment. Human or not.