What happened
On September 9, 2026, CISA released its first refresh since 2020 of the Insider Threat Mitigation Guide. Beyond updated case studies, statistics, and a more streamlined format, the new edition adds a dedicated section, 'Artificial Intelligence and Insider Threat Mitigation Considerations,' addressing AI-enabled manipulation/deception of insiders, machine identities, and the security implications of increasing organizational AI adoption for insider-threat programs. The guide also expands coverage of hybrid/remote work and critical-infrastructure impacts.
Why it matters
This is CISA's flagship insider-threat guidance document, widely used by security and HR professionals across critical infrastructure and the private sector to build or benchmark insider threat programs. Formal incorporation of AI-specific risks (AI-driven manipulation of insiders, machine/agent identities as insider-threat vectors) signals that AI risk is now baseline expected content in insider-threat program design, not a specialized add-on — organizations building or auditing insider-threat programs against this guide will need to add AI-specific control considerations.
Action needed
Insider-threat program owners should map existing programs against the updated guide's new AI section, incorporate machine-identity/agent-identity considerations into monitoring scope, and update training materials to address AI-enabled manipulation vectors.