Urgent.News

What's breaking now, across thousands of outlets.

AI

Weak API controls are one of the biggest threats in the agentic AI era

Artificial intelligence agents are already running inside your enterprise workflows, whether you know it or not. International Data Corp. projects full agentic AI deployment across the enterprise by 2027. Gartner Inc. estimates 40% of enterprise applications will integrate task-specific agents by the end of this year, up from less than 5% in 2025. The application […] The post Weak API controls…

Weak API controls are one of the biggest threats in the agentic AI era

Weak API controls represent one of the most significant threats in the burgeoning era of agentic AI. As enterprise workflows increasingly incorporate AI agents, the exposed APIs that these agents depend on were never designed with them in mind. Enterprises now manage vast numbers of APIs across teams, vendors, and legacy systems, many of which remain undocumented and ungoverned.

This sprawling landscape is already a problem; however, the introduction of AI agents amplifies the risk manifold. Poorly defined APIs allow AI agents to commit unauthorized actions, modify records inaccurately, and expose sensitive data when they misinterpret requests. The consequences of such mishaps can be severe, as demonstrated by a 2024 incident where financial institution attackers used a hidden email instruction to cause an AI assistant to approve fraudulent wire transfers totaling $2.3 million.

The AI agent executed its programmed function flawlessly, without the API's oversight. The urgency of the situation is compounded by the speed and scale at which AI agents operate. Once activated, they can proceed at machine speed before any human intervention. This rapid execution becomes particularly problematic when guardrails are insufficient, as the damage can accumulate faster than it can be detected.

To mitigate these risks, enterprises need to focus on proven security practices. First, AI agents should be constrained by mapping out workflows and anticipating potential adverse consequences. This process requires time and input from cross-functional stakeholders who understand the business processes involved. Constraints are essential for ensuring that agents are reliable, effective, and secure.

Next, implement permission-aware data access and deterministic execution boundaries. AI agents should operate with clearly defined identities, roles, and least-privilege access controls. Execution boundaries define the specific actions an agent is permitted to take, not just the data it can access. This distinction separates controlling what an agent knows from controlling what it can do.

Using-intent logging is a critical practice that should be enforced. This involves collecting the user prompt, the agent's reasoning steps, the proposed action, the human approval or rejection, and the final outcome. This comprehensive audit trail creates a record of the entire execution chain, providing essential information for determining whether an incident is defensible in the face of regulatory scrutiny.

Effective data management is nonnegotiable when dealing with AI agents. Agents should only have access to the data necessary for their specific tasks, with no additional information. This principle includes enforcing ephemeral containers, encrypting data at rest, in transit, and in use, stripping personally identifiable information from the model, and holding sub-processors to zero data retention agreements where feasible.

If regulators inquire about the data touched by an agent, a precise answer should be readily available. Simplifying the AI supply chain is also crucial. Having too many tools, models, and integrations can create security blind spots and governance failures. A complex stack hinders observability and control, making it harder to maintain a secure environment.

Administrative controls play a vital role in the overall approach to AI agent security. These controls include kill switches, user and group-based access controls, and Model Context Protocol server allow lists. Governance should be calibrated according to the deployment stage, with experimental projects requiring more flexibility and production systems demanding stricter controls, auditing, and compliance frameworks.

The primary goal is not to impede the deployment of agentic AI but to establish a solid foundation that enables its safe and effective use. The rise of AI agents, with their deep reliance on APIs, necessitates a more disciplined approach to API management. The era of AI agents does not require new security principles; it demands the proper implementation of existing proven practices.

With the right guardrails in place, the blast radius of potential security breaches is significantly reduced. Conversely, mismanagement leads to an expanded risk landscape that any team struggles to contain.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in AI

More from Friday 14 August →