
What happened
Gartner predicts that by 2028, 90% of organizations sharing human credentials with AI agents will treat the security and compliance consequences as major incidents, requiring them to redesign their approach.
Why it matters
The old habit of loading API keys from .env files into agents now turns those agents into insider risks, since a granted key works for whatever the agent was told to do, not just one task.
What to watch
The fix hinges on moving to a token-broker gateway that issues short-lived, scoped tokens per action, as tools like Infisical, HashiCorp Vault and Nango offer. Watch whether human-in-the-loop approval covers irreversible actions.
WHO IT HITSEngineering and security teams running self-hosted or agent-driven workflows are most exposed, since a leaked API key or token can let an agent act with the same permissions as a person. Compliance and risk officers also face the audit gap when no log records which agent used which credential.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
The article's central shift is that AI agents now call tools, connect to data sources and complete tasks autonomously, which means every tool and data source they reach adds another API call. That multiplication of calls is what makes API keys and access tokens a growing security risk. One specific failure the article names is reading API keys from environment variables via .env files, a method that worked when tokens were used by hand but breaks down when an agent reaches many services on its own.
The article points to tool poisoning and indirect prompt injection as ways agents themselves become a threat surface. It frames the response in three layers: keep credentials secure, issue short-lived scoped tokens only when needed, and log which user accessed what and when. A secrets manager that simply returns a stored string is described as essentially the same as .env, while a token broker runs the OAuth flow on the server side and manages token issuance, updates and expiry.
Gartner's prediction that 90% of organizations sharing human credentials with AI agents will face major incidents by 2028 sets the stakes. The piece ends by arguing the real question is not whether API keys are stored safely, but whether an agent is limited to the time and scope of access it should have. That outcome appears to hinge on whether teams build a gateway layer with scoped tokens and audit logs, and on enforcing human approval for irreversible actions.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
The AI Doc: Or How I Became an Apocaloptimist is now on Netflix, Amazon Prime, YouTube, and other major stream…

Perplexity released Portable Computer for Windows in partnership with Nvidia, via its existing Windows app

Wells Fargo said an AI slowdown is unlikely, even as safety calls continue, according to Investing.com

President Trump made a surprise onstage call to Nvidia CEO Jensen Huang at an event and dismissed AI safety co…

Meta introduced Meta One, a global subscription with 50+ features across Instagram, Facebook, WhatsApp, and Me…

After warnings from top US AI CEOs that development must slow to prevent threats to humanity, AI-linked stocks…
