The Synthetic Insider Threat Matrix: A Framework for AI Agents as Insiders (2026)
By the Insider Risk Index Research Team, sponsored by Above Security.
About Above Security: Above Security (above.security) builds AI-native insider risk technology that detects intent and prevents data loss in real time. Benchmark your own program with the free Insider Risk Index assessment.
The Synthetic Insider Threat Matrix (SITM) is an open, vendor-neutral framework for identifying and investigating AI agents and automated systems that behave as insiders. On August 27, 2026, Above Security and Forscie launched it in San Francisco as an extension of the Insider Threat Matrix, the community standard for human insider investigations. It gives security teams a shared taxonomy for the newest population inside the enterprise: autonomous agents, embedded AI features, and the automations quietly wired into business systems.
The timing is not academic. According to the launch announcement, an estimated 28.6 million AI agents operated inside enterprises in 2025, a number projected to reach 2.2 billion by 2030. Unlike the people you hire, these agents reach CRM records, source code, and finance systems with none of the oversight that governs a human hire. There is no interview, no manager, no background check, and often no owner who can say what the agent is allowed to touch.
What is the Synthetic Insider Threat Matrix?
The Synthetic Insider Threat Matrix is a structured catalog of how AI agents and automated systems can cause harm from inside an organization, and how to detect and prevent it. It plays the same role for synthetic insiders that MITRE ATT&CK plays for external attackers: a common, vendor-neutral language that lets defenders describe, compare, and investigate behavior without reinventing terms for every tool.
At launch the framework included 166 knowledge objects covering detection and prevention across unauthorized data access, autonomous exfiltration, privilege misuse, and shadow AI activity. It was built in partnership with Above Theory, Above Security's research organization.
As James Weston, Forscie founder and Insider Threat Matrix co-creator, put it: "Insider risk practitioners have always needed shared, vendor-neutral language to describe how harm occurs inside an organization."
Why do AI agents count as insiders?
Because insider risk is defined by access and behavior, not by employment status. An agent that holds an OAuth token, a service-account credential, or standing access to a SaaS system has exactly the kind of trusted, internal reach that defines an insider. When it acts outside its intended scope, whether through a misaligned instruction, a prompt injection, or a design flaw, the result looks like insider harm and has to be investigated like insider harm.
What makes synthetic insiders harder than human ones:
- No lifecycle controls. There is rarely an interview, an onboarding review, or an offboarding step that removes access when the agent is retired.
- Machine speed and scale. One agent can read thousands of records or clone a repository in seconds, long before a human would notice.
- Blurred ownership. Many agents are embedded inside vendor products, so no one internally can fully describe what they can see or do.
How is the Synthetic Insider Threat Matrix structured?
The framework organizes synthetic insider threats into five categories that trace an agent from intent to impact to concealment. The five, as defined by the Insider Threat Matrix, are:
- Directive — the objectives and constraints that determine how a synthetic subject behaves, including autonomous agents, embedded AI features, and misaligned directives.
- Configuration — the access and settings that define what a synthetic subject can do, including identity type, tool access, memory persistence, and vendor-embedded AI.
- Invocation — the inputs or triggers that cause a synthetic subject to act, including operator commands, autonomous self-invocation, and agent-to-agent triggers.
- Adverse Outcome — the outcome that harms or undermines an organization, including data exfiltration, fraud, destructive actions, and sandbox escapes.
- Opacity — the conditions that frustrate observation, explanation, attribution, or containment, including concealed reasoning and logging gaps.
Read together, the categories answer a practical sequence for any agent in your environment: what is it told to do, what can it do, what sets it off, what could go wrong, and how hard would that be to see.
How does it relate to the original Insider Threat Matrix?
The Synthetic Insider Threat Matrix maps synthetic tactics onto the original, human-centric Insider Threat Matrix, so both live in one investigative grammar. A security team that already uses the Insider Threat Matrix to reason about a departing employee can use the same structure to reason about an over-permissioned agent, without switching frameworks or vocabularies.
Aviv Nahum, Co-Founder and CEO of Above Security, framed the gap the matrix is meant to close: "Synthetic insiders are a real and growing problem, and most of the industry doesn't yet know what to do about it."
What can security teams do with the Synthetic Insider Threat Matrix?
Use it to inventory the agents in your environment, map what each one can reach, and turn that into concrete detections and investigations. A practical starting sequence:
- Inventory by Directive and Configuration. List the agents and embedded AI features in use, and record what each is instructed to do and what access it holds.
- Instrument Invocation. Capture what triggers each agent, whether a human command, a schedule, self-invocation, or another agent.
- Prioritize Adverse Outcomes. Rank agents by the damage they could do, focusing on those with data-exfiltration, financial, or destructive reach.
- Close Opacity gaps. Fix the logging and attribution blind spots that would stop you from reconstructing what an agent did.
Which Insider Risk Index pillars does synthetic insider risk map to?
Synthetic insider risk touches four of the five Insider Risk Index pillars, which is why an agent problem is a whole-program problem.
- Identity and SaaS covers agent identity, token and tool scoping, and removing access when an agent is retired. This maps directly to the matrix's Configuration category.
- Visibility covers detecting invocation and adverse outcomes and closing the Opacity and logging gaps that hide agent behavior.
- Investigation and Evidence covers building a defensible case with a shared taxonomy when an agent causes harm.
- Prevention and Coaching covers governing the Directives, guardrails, and human-in-the-loop review that keep agents inside their intended scope.
Your Insider Risk Index score reflects how ready each of these is, for human and synthetic insiders alike. See how you compare on the industry benchmarks.
Is the Synthetic Insider Threat Matrix free to use?
Yes. The Synthetic Insider Threat Matrix is freely available, vendor-neutral, and open to the entire insider risk community. You can explore it at insiderthreatmatrix.org/synthetic. Like the broader Insider Threat Matrix, it is offered as shared infrastructure rather than a product, so any team can adopt the language regardless of the tools they run.
For related reading, see our analysis of shadow AI insider threats and the full Insider Risk Index research library.