Sep 22, 2026

Insider Threat Awareness Month 2026: The Expanding Definition of Insider Risk

5

A month dedicated to insider threats

September is Insider Threat Awareness Month, and DTEX has spent much of it in conversation with people responsible for building and running insider risk programs.

Those conversations have taken us from London to Washington, D.C., with Toronto next on the docket. The most substantial stop so far was DSI’s National Insider Risk Symposium, a closed event where DTEX participated as a top sponsor.

Because the symposium is closed to the public and media, I won’t recap individual remarks or sessions. Instead, we’ll look at a broader question that followed us throughout the month: what happens to insider risk when the actor behind a trusted identity isn’t always human?

Why Insider Threat Awareness Month feels different this year

Insider Threat Awareness Month gives organizations a reason to examine risks that are easy to overlook when attention is fixed on outside attackers. Traditionally, security budgets go toward keeping outsiders out. Insiders, people or systems with legitimate access, get comparatively little airtime until an incident forces the conversation.

That definition is no longer complete and became part of the conversation at DSI worth discussing. Organizations have spent decades building programs around a fairly stable assumption: insiders are people. Now, AI systems are beginning to use enterprise access to take actions on a user’s behalf. Insider risk programs must now consider what happens when trusted access is exercised by a person or an agent.

A discipline built on collaboration

DSI drew practitioners, researchers, investigators, and government leaders, several of whom helped write the policies and build the programs we see today. A common theme across these perspectives reflected something fundamental about insider risk: no single function sees enough of the picture to manage it alone.

An effective program depends on collaboration across organizational boundaries. Security may identify unusual activity, but understanding that activity often requires context from elsewhere in the business. As technology changes who or what can act inside enterprise systems, that shared context becomes even more important.

The symposium reinforced the value of creating space for those perspectives to meet. It also provided a timely backdrop for a question facing the wider insider risk community. Are programs built to understand behavior regardless of whether it comes from a person or a machine?

When trusted access isn’t exercised by a person

For most of insider risk’s history, programs could assume that a person was behind the activity they were investigating. Someone opened the file or moved the data.

AI agents now complicate that assumption. An agent doesn’t carry the hesitation or self-doubt that often shows up in human behavioral signals. Instead, its activity may appear legitimate, especially when viewed as a login or permission check, even when the resulting action creates risk. Agents don’t pause before exfiltrating data. They execute tasks as assigned.

This doesn’t make established insider risk practices obsolete. It makes context more important. Teams still need to understand what happened and whether the activity was consistent with its intended purpose, especially if it’s affecting sensitive data. They also need enough visibility to distinguish between the account owner or system acting and the instructions that shaped the action. DTEX’s platform captures that shift to treat human, AI, and data risk as one connected behavioral platform.

The practical question isn’t whether AI should be treated exactly like an employee. It’s whether insider risk programs can investigate consequential behavior when a human isn’t the only actor involved.

Governance has to catch up with access

Technology is changing faster than many of the policies built to govern trusted access. Insider risk programs often operate within structures designed around human users and relatively clear lines of accountability.

AI introduces harder questions. Who is responsible when an agent takes an action a user didn’t directly perform? How should an organization review activity that was technically authorized but inconsistent with the purpose of the access? And how can investigators reconstruct what happened when several systems contributed to the outcome?

These aren’t reasons to abandon existing insider risk frameworks. They’re reasons to examine where those frameworks rely on assumptions that no longer hold. Policies governing access and accountability need to reflect how work is actually being performed insider modern organizations.

Continuing the conversation

DTEX kicked off Insider Threat Awareness Month at the UK IRM CC event in London before heading to Washington, D.C., for DSI’s National Insider Risk Symposium and the U.S. IRM COE Bootcamp.

We’re closing out the month in Toronto with the Canadian Insider Risk Management Partnerships Summit on September 21-22 and the Canadian COE IRM Innovations Lab on September 23. These events give the insider risk community another opportunity to compare approaches and continue the conversations shaping programs across government and industry.

If you’ll be there, connect with the DTEX team.

What insider risk programs should reconsider

Insider Threat Awareness Month is a good excuse to dust off training and incident exercises. In 2026, it should also prompt a review of the assumptions behind the program itself.

Start with trusted access. Can your team determine when an action was taken directly by a user, performed by an agent on that person’s behalf, or shaped by instructions from another source? Can investigators see how the activity affected sensitive data? Do existing policies establish who is accountable when those lines overlap?

The organizations handling this well are treating AI behavior as an extension of their existing insider risk program rather than a separate initiative running in parallel. DTEX’s point of view is that human, data, and AI risk shouldn’t be investigated in isolation. The behavior has to be understood in context, regardless of which actor initiated it. That approach gives security teams a more complete basis for deciding whether trusted activity is appropriate or risky.

Looking ahead to Cybersecurity Awareness Month

The conversation won’t end in September. Cybersecurity Awareness Month begins in October, and we have more events and perspectives planned for the weeks ahead.

Stay tuned to see what DTEX has in store.

Learn about the DTEX approach to human, data, and AI risk, or contact our team to discuss where your programs may need broader context.

FAQ: Insider Threat Awareness Month

Insider Threat Awareness Month is observed every September to help organizations recognize, prevent, and respond to risks posed by insiders: employees, contractors or other trusted individuals with legitimate system access. Traditionally, these risks have centered on employees and other people who cause harm. Organizations are now also examining how AI systems and agents use trusted access inside enterprise environments.

Ai agents and generative AI tools now perform actions inside enterprise systems, like accessing data or making decisions, that used to require a human. Because those actions carry the same potential for harm as a human insider, insider risk programs are starting to treat AI-driven behavior as part of the same discipline rather than a separate AI security problem.

DTEX’s September schedule included five insider risk events in London, Washington, D.C., and Toronto. These included the UK IRM CC event, DSI’s National Insider Risk Symposium, the U.S. IRM COE Bootcamp, the Canadian Insider Risk Management Partnerships Summit, and the Canadian COE IRM Innovations Lab.

The DTEX Platform unifies human, data, and AI risk into one behavioral model, using continuous, privacy-by-design monitoring to detect risky patterns. This context carries across people, sensitive data movement, and AI agent or generative AI tool activity.

Subscribe today to stay informed and get regular updates from DTEX