TLDR: Obsidian Security has launched new AI agent security capabilities designed to provide real-time governance and protection against threats posed by autonomous AI agents operating within Software-as-a-Service (SaaS) applications. This innovation addresses the escalating risks of data exfiltration and lateral movement across connected cloud platforms due to over-permissioned and unmonitored AI agents.
Palo Alto, CA – September 25, 2025 – Obsidian Security, a leader in SaaS security, today announced the release of its advanced AI agent security capabilities, a pioneering solution aimed at safeguarding enterprise SaaS environments from the burgeoning threats of autonomous artificial intelligence agents. This development comes as businesses increasingly integrate AI agents, often through low-code and no-code platforms, into their critical cloud-based workflows, creating new vulnerabilities that traditional security tools struggle to detect.
The core problem, as identified by Obsidian, is the ‘AI agent-to-SaaS blindspot.’ These agents, while enhancing productivity, frequently operate with excessive privileges and without direct human oversight, enabling them to access and move sensitive data at speeds and volumes far exceeding human capabilities. This creates a significant attack surface for sophisticated cyber threats.
Recent incidents underscore the urgency of this new defense. The Salesforce (UNC6040) attack, for instance, saw threat actors leverage voice phishing to gain initial access, subsequently using bulk API queries for large-scale data theft. Another notable event, the Salesloft Salesforce supply chain breach (UNC6395), demonstrated how a compromised chatbot integration could facilitate unauthorized lateral movement from Salesforce to other critical platforms like Google Workspace, Slack, Amazon S3, and Microsoft Azure, impacting hundreds of organizations. Furthermore, attackers previously hijacked a Drift AI chat agent to compromise over 700 organizations, highlighting the non-theoretical nature of these risks.
Obsidian’s new solution provides real-time visibility and security controls to govern how these AI agents interact with data across SaaS applications. It is built upon the industry’s most comprehensive SaaS threat dataset repository, comprising over 500 curated real-world threat intelligence entries, enriched with browser-based activity capture and deep SaaS and AI integrations. This intelligence fuels the Obsidian Knowledge Graph, a continuously learning model that unifies user and agent activity, identity privileges, and workflows across various SaaS and agentic AI platforms into a single, correlated view.
According to Hasan Imam, CEO at Obsidian, the rapid adoption of AI agents has already introduced measurable risks. “The AI agent shift is well underway, and we’re seeing the risks firsthand as we help our customers scale adoption securely,” stated Imam. He further elaborated on alarming statistics: “87% of enterprises have Microsoft Copilot enabled, more than half the agents access sensitive data, 90% are over-permissioned, and move 16 times more data than humans accessing SaaS applications. These risks are not theoretical, they’re active risks inside enterprises today, often without their awareness.”
Also Read:
- Britive Unveils Advanced Runtime Security for AI Agent Identities
- Cloudflare Launches AI Confidence Scorecards to Bolster Internet Security
The new capabilities aim to ensure that AI agents operate within delegated permissions, preventing them from becoming ‘Trojan Horses’ in the SaaS supply chain. By detecting issues in near real-time, Obsidian enables security teams to intervene and shut down threats before they escalate, thereby closing a critical security gap in the evolving enterprise technology landscape.


