A Business Process Automation system that uses AI agents accesses enterprise data, processes it, makes decisions, and acts on downstream systems. This is exactly its value. It is also, for exactly the same reasons, the primary source of security risk. The same mechanisms that make the system useful make it an attractive target for anyone wanting to access data, manipulate decisions, or sabotage processes. Security in this context isn't an added layer: it's a design constraint.
The problem is already inside the organization
Gartner published the top cybersecurity trends for 2026 in February 2026, with a data point that deserves attention: in a survey conducted between May and November 2025 of 175 employees, over 57% reported using personal GenAI accounts for work purposes, and 33% admitted to entering sensitive information into tools not approved by the company. This happens regardless of formal BPA systems: it's the pressure to adopt AI tools that produces ungoverned behaviors, with direct consequences for corporate privacy and intellectual property.
Gartner describes the uncontrolled proliferation of AI agents through no-code and low-code platforms, and so-called "vibe coding," as one of the most significant cybersecurity trends of 2026: they create new attack surfaces, insecure code, and potential regulatory compliance violations before IT is even aware.
By 2027, 40% of AI breaches will come from cross-border use
In a February 2025 press release, Gartner predicts that by 2027, over 40% of AI-related data breaches will be caused by improper use of GenAI across geographic boundaries. The problem is structural: when employees use GenAI tools embedded in existing products without these being clearly documented, data is often transferred to processing systems in different jurisdictions without the organization's awareness. Data localization regulations, such as the European GDPR and equivalent laws in other jurisdictions, apply regardless of the user's unwitting involvement.
Gartner identifies AI data governance, prompt filtering and redaction, and synthetic generation of unstructured data as specific measures for this type of risk. Organizations that apply AI TRiSM (AI Trust, Risk and Security Management) controls will consume at least 50% less inaccurate or illegitimate information, reducing faulty decision-making, according to Gartner's prediction for 2026.
AI agents expand the attack surface non-linearly
Gartner identified machine identity management as one of the six main cybersecurity trends for 2025. The adoption of GenAI, cloud services, automation, and DevOps practices has led to a proliferation of machine accounts and credentials for physical devices and software workloads. If ungoverned, these identities significantly expand the organization's attack surface.
In a BPA system with AI agents, each agent has credentials, accesses specific systems, and has defined permissions. A compromised agent can access all the systems it's authorized for, extract their data, and initiate actions that appear legitimate because they come from an authorized entity. The September 2025 Gartner survey of 302 cybersecurity leaders found that 62% of organizations experienced a deepfake attack involving social engineering or exploitation of automated processes, and 29% experienced an attack on enterprise GenAI application infrastructure in the previous twelve months.
By 2028, Gartner predicts that 25% of enterprise breaches will be traceable to AI agent abuse, by both external actors and internal employees with malicious intent.
AI security platforms: a market being born right now
Among the strategic technology trends for 2026, Gartner identifies AI security platforms as one of the most relevant emerging trends. These platforms offer a unified way to protect both third-party and internally developed AI applications. They centralize visibility, enforce usage policies, and protect against AI-specific risks such as prompt injection, data leakage, and rogue agent actions. By 2028, Gartner predicts that over 50% of enterprises will use AI security platforms to protect their AI investments.
Prompt injection deserves specific attention: it's the technique where an attacker inserts malicious instructions into the text that an AI agent processes, inducing it to perform unauthorized actions. In a BPA system where agents process documents, emails, or service requests from external sources, any unfiltered content is a potential vector for this type of attack.
Zero-trust as the standard for AI data governance
In a January 2026 press release, Gartner predicts that by 2028, 50% of organizations will adopt a zero-trust posture for data governance, in response to the proliferation of unverified AI-generated data. The prediction is driven by a specific risk: as future generations of LLMs are trained on outputs from previous models, the risk of "model collapse" grows, where AI tool responses no longer accurately reflect reality.
For BPA systems using GenAI, a zero-trust approach to data means never assuming that incoming data is correct or authentic without explicit verification. Every data source must be authenticated, every output must be validated before being used as input in a subsequent process, and every access must be logged with sufficient granularity to allow auditing in the event of an incident.
Global cybersecurity spending will reach $240 billion in 2026, a 12.5% increase over 2025, according to Gartner's July 2025 projections. The main drivers are growing threats and the expanding use of AI and GenAI, both by internal users and attackers. Investing in AI system security isn't an additional cost: it's the prerequisite for operating in a context where AI is both the defense tool and the attack vector.