
A newly identified AI attack technique can let unauthenticated users trigger privileged workflows and access enterprise systems, highlighting a gap in how identity and access controls apply to AI agents, according to research from Noma Labs.
The report, authored by Noma Labs lead researcher Sasi Levi, describes the issue as “workflow identity hijacking,” where attackers bypass standard controls by sending normal, benign requests through an unauthenticated entry point such as a support inbox, GitHub issue, web form, or shared document.
“The enterprise AI pipeline reads the input, interprets the request, and executes the action exactly as designed,” Levi wrote in the report. “The core failure is that the requester had no authority to make that request.”
