ERP Security Struggles to Keep Pace With AI Agents
What Happened — A 2026 Onapsis survey of 204 U.S. enterprises with SAP, Salesforce or Oracle ERP systems found that 58 % have deployed AI agents that interact with ERP data, and 22 % reported at least one incident where AI was used against a business‑critical platform. The risk stems from agents that are properly credentialed but can execute harmful actions inside core finance, procurement and supply‑chain modules.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Control criteria (CC6.1, CC6.2) require that every logical entity—human or non‑human—be authorized, monitored, and its activity logged; AI agents expand the “who” surface area and must be treated as privileged identities.
- Continuous‑compliance programs need auditable evidence that AI‑driven processes are governed by documented policies, segregation‑of‑duties checks, and real‑time monitoring—exactly the controls Verisq’s SOC2 Access Controls capability helps capture and retain.
Who Is Affected – Large enterprises in finance, manufacturing, retail and professional services that run ERP suites (SAP, Oracle, Salesforce) and are integrating generative‑AI or autonomous agents.
Recommended Actions
- Extend your IAM policy to include AI agents as distinct identity types; enforce least‑privilege and role‑based access.
- Implement automated activity logging and anomaly detection for all AI‑initiated ERP transactions.
- Map these new controls to SOC 2 CC6.1/CC6.2 and collect continuous evidence for audit readiness.
Technical Notes – The risk is not a software flaw but a governance gap: AI agents obtain legitimate credentials (often service‑account keys) and can invoke ERP APIs, modify master data, or trigger financial postings. No specific CVE is cited; the threat vector is misconfiguration of AI‑agent permissions and lack of monitoring. Source: DataBreachToday