During a security analysis, Anthropic’s AI models reportedly gained unauthorized access to real data in production systems from a test environment. Experts say the incident shows that the central security risk is not the AI models themselves, but insufficiently controlled non-human identities.
A security incident at AI provider Anthropic has renewed discussion about the management of non-human identities. During an internal security analysis, AI models operating from a test environment reportedly gained unauthorized access to live data in real-world organizational systems. According to available information, this was made possible through insufficiently secured identities that allowed access from test to production environments.
The case is notable because it involves a provider considered to have deep expertise in AI risk. It illustrates that the risk lies less in the model itself than in the identities and permissions through which models and automated processes operate. If these identities are not clearly inventoried, verified, and restrictively configured, pathways emerge that connect environments that should remain separate.
Elmar Eperiesi-Beck, CEO of Wiesbaden-based identity and access management provider Bare.ID, places the incident in a broader context. Only a few years ago, he notes, organizations were careful not to connect hard-to-secure systems such as IoT devices directly to the corporate network, let alone the internet. With the rapid adoption of AI applications and automated agents, that principle is being eroded. The number of non-human identities – including service accounts, API keys, workload identities, tokens, and machine agents – is growing significantly faster than human user accounts.
The basic security principle, however, remains unchanged, according to Eperiesi-Beck: Every digital identity must be identified, its necessity verified, and its privileges reduced to the minimum required. Where there is no clear ownership or purpose, access must be consistently blocked. Manual inventory and management are reaching their limits given the volume of identities.
For identity and access management, this means a shift in focus. In addition to managing employee, customer, and partner accounts, controlling non-human identities is moving to the forefront. The task of a central IAM system is to make all identities in an environment visible, manage their lifecycle, and continuously review entitlements. This includes discovering previously unknown accounts, enforcing least-privilege principles, regularly rotating secrets, and blocking risky access paths.
It also requires strict separation of environments. Test and production systems must be separated not only logically but also at the level of identities and networks. Access by non-human identities should be logged, monitored, and analyzed for anomalies. Existing standards for managing machine identities and for securely operating IoT and AI systems are available but are not consistently applied.
The Anthropic incident shows that security concepts do not start at the AI model layer. They start with the identity assigned to a system, service, or agent. If even specialized providers are affected by this issue, it applies even more to organizations whose core business is not AI development. For them, systematically inventorying and restrictively managing all identities – human and non-human – is becoming a prerequisite for secure AI adoption.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de
