EXCLUSIVE: 'It's Like Everybody's Become a Builder': AI Is Creating a New Security Problem, Vanta Says

Artificial intelligence is giving employees capabilities that were once largely limited to technical teams, creating a new set of security challenges for companies struggling to track what people — and increasingly, AI agents — can access.

"It’s like everybody’s become a builder," Jeremy Epling, chief product officer at Vanta, told Benzinga in an interview, describing how AI is allowing employees to build software, automate tasks and navigate systems with far less technical expertise.

The shift is changing how companies approach cybersecurity, governance and compliance as AI tools become embedded across the enterprise.

Vanta, which provides security and compliance software, has seen builder roles among its more than 16,000 customers increase by more than 300% year over year, according to Epling. Those roles include go-to-market engineers and governance, risk and compliance (GRC) engineers, as businesses use AI to automate work and accelerate software development.

But the same technology that expands employees’ capabilities can also create new security gaps.

"You can’t get away with security through obscurity because the agents will find a way to [access] the data or do something unexpected," Epling said.

That means security teams face a growing challenge not only in determining which AI tools employees are using, but also understanding what those tools can access and what they are doing inside corporate environments.

Vanta has identified "shadow AI" as an emerging concern, as employees sign up for AI services without necessarily going through established security processes. In some cases, employees may also be feeding company information into tools that have not been vetted by their organization.

That raises the prospect of companies having to monitor not just their employees, but potentially thousands of autonomous systems operating on their behalf. 

Epling said organizations could eventually have dramatically more agents than employees, creating a new visibility problem for security teams.

Vanta is also turning to AI agents to automate security and compliance work. Its Vanta agent can analyze security programs, assess vendors, answer questionnaires and help identify risks. The company has also introduced integrations, APIs, an MCP server and custom agents that allow customers to build workflows on top of its platform.

Daily users of Vanta’s agent have increased by more than 250% this year, while usage of its MCP server has grown 50-fold, according to Epling.

The broader trend, he said, will be toward companies giving AI systems greater authority to act on their behalf.

"I think the amount of automation is going to fundamentally change everything," Epling said. "And I think it’s going to create some form of chaos and overwhelm the people that are using it."

As AI takes on more of the work once handled by employees, security teams will have to rethink what it means to control access across the enterprise. The challenge may no longer be simply securing employees and their devices, but keeping track of an expanding network of AI systems that can make decisions, access data and act with increasing autonomy.

Photo: Shutterstock