How Security Teams Can Manage Agentic AI Risks
How Security Teams Can Manage Agentic AI Risks
https://www.infosecurity-magazine.com/opinions/security-teams-agentic-ai-risks/
Publish Date: 2026-04-02 02:51:25
Source Domain: www.infosecurity-magazine.com
Summary
Security teams are deeply concerned with insider threats from trusted individuals, and recent data indicates that these threats have been a major factor in UK businesses experiencing cyber breaches. A significant problem is emerging with AI agents, which can exploit authorized access in a manner human-centric authorization (AuthZ) systems were not designed to manage. Unlike human employees, AI agents lack social constraints or common sense, which means they might optimize for efficiency in ways that could lead to serious data breaches or errors. To mitigate these issues, responsible governance must implement measures such as composite identities to track and manage AI actions, comprehensive monitoring frameworks to oversee AI behavior consistently, and establish transparency and accountability structures. The disruption caused by AI agents echoes past technological shifts, underscoring the necessity of adapting current security measures to harness innovation while minimizing risks.
Key Points:
- Insider Threat and Current Statistics: Insider threats have been responsible for 50% of cyber breaches in UK businesses in the past 12 months according to recent surveys.
- AI Agent Risks: AI agents, due to their lack of context and constraints, pose unique risks to existing authorization systems designed primarily for human users.
- Three Mitigation Strategies:
- Implementing Composite Identities to distinguish and track AI agents’ actions through their human overseers.
- Comprehensive Monitoring Frameworks to oversee AI activity across different environments and systems.
- Transparency and Accountability to create clear oversight, escalation procedures, and regular human reviews of AI actions.
- Responsible Agent Deployment: The integration of AI agents necessitates adapting current authorization systems and security measures to maintain balance between innovation and security.