AI Agents Are Everywhere. Your Security Team Probably Isn’t Ready.

Abstract representation of artificial intelligence with neural network patterns

The conversation around AI Agents Are Everywhere. Your has reached a critical point. I’ve been thinking about AI agents a lot lately. Not the chatbots that answer customer service questions – those are old news. I’m talking about autonomous agents that can browse the web, write code, access databases, and make decisions without a human in the loop.

They’re being deployed everywhere. However, most organisations have no idea what they’ve just let through the front door.

The Problem Nobody’s Talking About

Here’s the thing about AI agents: they’re essentially interns with root access. They can do amazing things, but they can also do amazing damage if something goes wrong.

Think about it. You give an AI agent access to your codebase, your customer database, your internal tools. It’s productive, sure. But what happens when someone tricks it into sharing that data? Or when it accidentally deletes something important? Or when it gets manipulated through prompt injection into doing something you never intended?

This isn’t hypothetical. Research from NTT DATA this week highlighted that enterprises are deploying AI agents faster than they can secure them. The gap between capability and security is growing, not shrinking.

What I’m Worried About

Prompt injection. Someone puts malicious instructions in a document, email, or webpage that your AI agent processes. The agent follows those instructions instead of yours. It sounds like science fiction, but it’s happening right now.

Data exfiltration. Your AI agent has access to sensitive information. A well-crafted query can trick it into sharing that information in its responses. The agent isn’t being malicious – it’s just doing what it was asked.

Shadow AI. Your marketing team signed up for an AI tool without telling IT. That tool now has access to your customer data, and nobody’s monitoring what it’s doing with it.

What You Can Do

Start with least privilege. Give AI agents only the access they need for their specific task. Not general access to everything. Not “we’ll figure it out later.” Specific access for specific tasks.

Log everything. If you can’t see what your AI agents are doing, you can’t protect against what they’re doing. Every action, every query, every response – log it.

Test for prompt injection. Red-team your AI deployments. Try to trick them. If you can do it, someone else definitely can too.

Establish governance now. Don’t wait for a breach to figure out your AI policies. Who can deploy agents? What access can they have? What happens when something goes wrong? Answer these questions before you need to.

The Window Is Closing

AI agents are getting more capable every week. The security gaps we have today are going to be the attack vectors of tomorrow. We need to close them now, while we still can.

The organisations that establish strong AI governance today will be the ones still standing when the attacks come. However, they will come.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.