AI agents are being trusted with inboxes, payments, codebases, and corporate systems. Security teams are only beginning to understand what that means.
Over the course of AI’s development, most cybersecurity concerns focused on the technology’s offensive use cases. Much of the discussion centered on how large language models (LLMs) could accelerate malware development, improve phishing campaigns, automate reconnaissance, and eventually assist with cyberattacks carried out with limited human involvement.
And they can. Those concerns are entirely valid and must be taken seriously.
But the recent rapid rise of agentic AI systems has introduced a different, arguably more immediate, security challenge: Organizations are beginning to grant AI systems genuine authority within real operational environments.
Unlike chatbots that simply generate text, agentic systems are designed to make autonomous decisions, chain actions together, interact with external tools, and complete tasks with limited human involvement.
The risk profile starts to look very different once AI systems are allowed to act rather than simply respond.
A traditional application generally behaves predictably because its functionality is tightly defined. Agentic AI systems, on the other hand, operate as probabilistic workers. They interpret instructions for themselves, decide which tools to use, incorporate external information, and adapt their behavior in response to changing circumstances. In many cases, they are also connected to critical systems, cloud platforms, internal documentation, customer data, payment systems, and APIs carrying significant privileges.
Companies are starting to give AI systems deliberate and direct access to sensitive internal tools, business data, and operational workflows, despite sitting in the learning period and not yet knowing how reliably those systems behave outside carefully controlled demos.
The risk is not limited to agents behaving maliciously on their own. These systems also create new opportunities for attackers to manipulate trusted software that already has legitimate access inside corporate environments.
When agentic AI is given too much access and power
Some of the more experimental agentic AI projects already hint at how strange this landscape may become.
Researchers at the Alan Turing Institute’s Centre for Emerging Technology and Security recently examined a growing ecosystem of autonomous agents designed to complete open-ended tasks with mini mal supervision.
Meanwhile, developers behind projects like OpenClaw have demonstrated agents capable of browsing the web, purchasing products, managing workflows, and interacting with live online services using real credentials and payment methods.
The same ideas are already appearing in commercial products and enterprise platforms, just packaged in a more controlled form. Visa recently announced its Intelligent Commerce initiative, which aims to enable AI agents to browse products, make purchases, and complete transactions on behalf of users.
Early retail experiments are already exploring AI-managed operational workflows. One example, Andon Labs’ Luna convenience store in San Francisco uses AI agents to help manage tasks, including inventory decisions, ordering, pricing, and day-to-day operational coordination with limited human involvement.
Companies are drawn to agentic systems for the same reason they are drawn to any new technology: They promise to offload the routine operational work that quietly consumes huge amounts of time and money across modern businesses. Scheduling meetings, updating records, responding to customer queries, handling procurement requests, summarizing documents, and coordinating internal workflows are all tasks that companies would rather automate if the technology proves reliable enough.
The problem is that many see the benefits and overlook the potential pitfalls.
Every permission granted to an AI agent becomes another potential security liability. As it stands, agentic AI introduces a number of novel vulnerabilities.
The prompt injection issue
One of the biggest risks surrounding agentic AI systems is prompt injection, which has quickly become the AI equivalent of input validation failures in traditional software security.
LLMs rely heavily on instructions contained within prompts, along with surrounding context. Attackers can exploit that by embedding malicious instructions inside emails, documents, websites, Slack messages, PDFs, or other content that agents tend to encounter while performing tasks.
Prompt injection becomes much more serious once agents are connected to real tools and live business systems. Researchers have already demonstrated scenarios in which hidden instructions embedded in emails, websites, or documents can alter how an agent behaves after processing the content.
An email assistant, for example, might encounter hidden instructions embedded in a message that tell it to share information elsewhere. A customer support agent scraping external websites could inadvertently expose internal prompts or credentials. Coding agents connected to repositories and development tools may also introduce insecure packages or accidentally leak secrets while carrying out routine tasks.
Part of the problem is that nothing necessarily looks broken when this happens. The software is still reading information, interpreting instructions, and responding to what it encounters.
This is not a zero-day exploit or even an attack in the classic sense. The attacker is manipulating how the system behaves through an interface that is fundamentally designed to do just that.
That is just how AI agents work. Security researchers have repeatedly demonstrated that even sophisticated frontier models remain highly vulnerable to these techniques. The challenge becomes significantly worse once agents gain access to tools capable of taking actions automatically.
A chatbot hallucinating information is embarrassing, but an autonomous agent hallucinating while connected to payment systems, internal infrastructure, or customer data is a serious operational problem.
When agentic systems do not have proper boundaries
Breaches involving shadow AI cost an average of $4.36 million, and 97% of the organizations that suffered an AI-related breach lacked proper AI access controls.
Much of the risk stems from the level of access these systems require to be useful. In many cases, agents are expected to move between mission-critical tools independently while carrying out broader tasks on a user’s behalf.
That is a very different model from traditional software integration. These usually operate inside far narrower, more rigid boundaries. Agentic systems are designed to improvise, interpret, choose which tools to use, and decide how to sequence actions along the way. Their flexibility is highly appealing, but it also creates more opportunities for things to go wrong.
Agents can deviate from the plan. They are capable of inadvertently exposing sensitive data, connecting to untrusted external services, or carrying out actions their operators never expected after processing manipulated content or prompts. In some cases, an attacker may not need direct access to a company’s systems at all if they can influence an agent that already has permission to interact with them.
Access management becomes another obvious headache once agents start accumulating credentials across multiple platforms.
Many rely on API keys, authentication tokens, browser sessions, and integrations with email, cloud services, internal documents, messaging tools, and business applications, all at once.
Gartner forecasts that 40% of enterprise applications will embed task-specific AI agents by 2026, up from less than 5% in 2025.
As more systems are connected over time, the amount of access tied to a single agent can quietly spread beyond most individual employee accounts.
Security teams are overwhelmed
Businesses have spent years pushing toward centralized workflows, heavy automation, and tightly integrated software ecosystems. Agentic AI fits naturally into that direction, except the software is now making far more decisions dynamically.
Part of the difficulty is that most organizations are not structurally prepared for software that behaves this way. Security teams already struggle with cloud complexity, software-as-a-service (SaaS) sprawl, identity management problems, and increasingly fragmented infrastructure.
Agentic AI systems introduce additional layers of dynamic behavior that are difficult to monitor using conventional security tools. Most enterprise security tooling clings to the idea that software behaves in broadly predictable ways. Analysts can usually define what normal traffic looks like, which systems should communicate with each other, and how approved applications are expected to behave.
Agentic systems make that much harder because their behavior is not always consistent from one task to the next. An agent connected to cloud platforms, messaging tools, databases, and external APIs may carry out thousands of perfectly normal actions before suddenly doing something unexpected.
When that happens, security teams are left trying to determine whether they are looking at malicious manipulation, a model error, or simply an unusual interpretation of instructions.
And when multiple agents are in play, the complexity tends to grow. Many organizations are already experimenting with multi-agent workflows in which specialized AI systems coordinate tasks collaboratively across departments and platforms. That creates the possibility of cascading failures, permission abuse, or unintended behavior spreading across interconnected systems in ways security teams may find difficult to trace in real time.
The technology is only part of the problem. The big question is how organizations are supposed to govern systems that behave this way inside real business environments.
Most organizations still lack clear governance models around what agents should be allowed to access, what decisions they should be permitted to make independently, and how organizations should audit or constrain their behavior. In many environments, agents are being deployed faster than security policies can adapt.
AI agents are reminiscent of the identity and access management problem
Veteran operators will see a familiar pattern in all this accelerated adoption and C-suite enthusiasm. The security industry has been through this, learned valuable lessons from it, yet in some ways agentic AI risks repeating many of the same mistakes organizations made during the early cloud and SaaS era.
Companies embraced convenience, automation, and rapid deployment long before fully understanding the resulting identity and access management problems. Years later, many organizations are still untangling sprawling permission structures, overprivileged accounts, and poorly monitored integrations scattered across hundreds of cloud services.
There is also a record-keeping problem. When a human employee takes an action, investigators can usually reconstruct the chain of events from their log ins, tickets, or approval trails. AI agents can make that trail harder to read.
A single action might be shaped by all manner of prompts or data encountered along the way. When an agent makes a change, a timestamp is of little use: The organization needs to piece together enough context to understand what the agent was trying to do, what influenced the decision, and whether the action stayed inside the boundaries originally intended.
Zero Trust is attracting renewed attention in AI security discussions because it solves many of the problems that come with the benefits of agentic AI.
Organizations are already looking more closely at how agents authenticate, which systems they can access, how permissions are segmented, and how to detect unusual behavior before an agent can move too far within internal environments. A Zero Trust approach tackles each of these issues head-on.
The difficulty comes in balancing those restrictions against a desire for autonomy, which is the very reason businesses want agents in the first place. The more useful an agent becomes, the more permissions it typically requires.
Organizations may eventually discover they are caught in a familiar security tradeoff between convenience and control.
Agentic AI is not impossible to secure
Many of the risks associated with agentic systems can be reduced through tighter access controls, stronger monitoring, and keeping humans in the loop for higher-risk decisions.
The real challenge for many organizations is ensuring this happens at a pace that exceeds that of AI adoption.
Businesses are racing to integrate agents into workflows because the productivity gains are potentially enormous, vendors are aggressively positioning agentic systems as the next major evolution in enterprise software, and investors see an opportunity to reshape everything from customer support to software development to financial operations.
Security teams, meanwhile, are still trying to work out how to monitor systems that can reason, improvise, and take actions dynamically. Those that have adopted Zero Trust find themselves in a stronger overall position because the deny-by-default model prevents AI agents from taking actions beyond those explicitly vetted and approved.
Zero Trust presents its own hurdles, such as limiting the flexibility of AI agents. The search for an optimal balance will define the next stage of enterprise AI adoption.
The immediate danger may not come from rogue superintelligent systems conducting autonomous cyberwarfare.
Instead, it may come from ordinary organizations deploying highly connected AI agents into sensitive environments without fully understanding how easily those systems can be manipulated, abused, or otherwise compromised.
The internet spent years learning painful lessons about web applications, cloud infrastructure, and identity systems after businesses rushed to adopt them faster than they could secure them. Agentic AI may be about to repeat the process all over again, except this time the software is making decisions on its own—and out of our control.
ThreatLocker tips for containing AI agents
AI agents may be new, but they essentially live in user space. The actions they take are familiar: launching applications, running scripts, calling services, connecting to networks, accessing cloud platforms, and moving data.
ThreatLocker supports organizations in creating control over such behavior.
- Allowlisting stops unapproved executables, scripts, and libraries from running even if an agent is tricked into calling them.
- Ringfencing™ restricts the resources approved applications are allowed to interact with, helping prevent an agent from being used to access sensitive files, registry keys, network locations, or other applications outside its intended role.
- Zero Trust Network Access helps keep AI agent access tightly restricted through consistent, device-level policies, reducing the chance of agent-driven activity spreading across the environment.
Book a demo today and find out how to take control of what runs in your environment.


