Why cybersecurity must evolve for the age of AI agents
As AI agents gain autonomy, organizations must rethink cybersecurity, governance and trust to manage emerging risks.
For years, cybersecurity was built on the assumption that systems operate based on predefined rules, with users logging in, receiving permissions, and accessing necessary resources. However, artificial intelligence (AI) is changing this landscape. With nearly half of cybersecurity solution buyers anticipating AI integration across the cyber stack within the next three years, businesses are now tasked with securing intelligent systems capable of making decisions, interacting with users, and functioning autonomously.
AI agents utilize models, prompts, context, and external tools to comprehend goals, decide on actions, and execute them. When organizations grant these agentic systems increased autonomy within enterprise workflows, the potential ramifications of failure extend beyond providing incorrect answers. A mistake can now disrupt business processes, influence decision-making, and trigger unintended actions across interconnected systems.
Greater autonomy introduces new vulnerabilities as AI gains access to data, systems, and external tools. Threat actors may manipulate the information AI receives or impersonate trusted users, leading AI agents to retrieve incorrect information or approve unauthorized actions. Traditional cybersecurity measures, designed for humans and applications, fail to address autonomous agents effectively.
As a result, security measures must extend throughout the entire AI lifecycle, from development to operation and every stage where AI learns, makes decisions, and performs actions.
A unified security architecture providing consistent visibility and control across AI and traditional systems is crucial. This enables organizations to identify threats, enforce policies, and respond swiftly to incidents. However, ensuring the trustworthiness of AI agents is equally important. Like any trusted user or system, AI agents should possess verifiable identities, controlled data and system access, and auditable records of actions taken.
Without these safeguards, organizations risk creating AI solutions that bypass security and compliance controls due to design flaws rather than malicious intent.
Continuous monitoring is essential for AI systems, as they learn from new data, adapt to changing contexts, and may behave differently over time. Organizations must implement clear ownership, escalation pathways, and kill switches to contain or stop AI agents that behave unexpectedly. Some businesses are even adopting "guardian agents" to monitor other AI agents for unusual behavior. The level of oversight should correspond to the risk level, with higher-risk activities requiring stronger guardrails.
Protecting AI agents also involves securing the context they rely on. Context provides AI agents with the information needed to understand tasks and make decisions, making it a new security boundary. If the context is inaccurate or manipulated, AI decisions can be erroneous, regardless of the model's integrity. Organizations must control what AI can see and do, granting access only to necessary data and systems for specific tasks.
For instance, an AI assistant answering employee queries should not have the same access as one authorized to approve payments. Guardrails should extend beyond filtering outputs to encompass the integrity of the information used, ensuring accuracy, timeliness, and relevance.
Effective governance is vital for scaling AI securely. This requires a collaborative approach that integrates AI and traditional systems, establishes consistent controls, and defines human intervention requirements and accountability for AI-driven decisions. Oversight should prioritize activities with high operational, financial, or regulatory risks, backed by investments in AI governance skills and trust-building initiatives.
In conclusion, securing AI extends beyond protecting systems from attacks. Organizations must develop robust technical solutions, establish clear ownership, and maintain continuous oversight throughout the AI lifecycle. Trust in AI hinges on these elements working cohesively. The organizations that succeed in AI adoption will not be those that move the fastest but those that securely and responsibly scale AI adoption.
The real question for leaders is not whether to trust AI but whether they are building systems worthy of trust.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.