As AI systems evolve from advising to acting independently, security experts warn of a new wave of threats posed by autonomous agents capable of executing malicious actions across business operations, prompting urgent calls for enhanced controls and oversight.
Artificial intelligence was once presented mainly as a productivity layer: a way to summarise documents, draft messages, analyse data and generate code. The security problem has changed as AI systems have begun to move from advising humans to taking actions on their own. In that shift, the central concern is no longer only whether a model can be tricked into revealing sensitive information, but whether a system with legitimate access can be induced to do real damage.
That is why agentic AI is creating a new class of enterprise risk. These systems can plan tasks, use software tools, call APIs and act across business applications with limited supervision. In practice, that gives them the operational reach of an insider, but at machine speed. A compromised agent connected to finance, customer service or enterprise resource planning systems could execute many harmful actions before a human notices, turning speed into the main security multiplier.
Axios reported this week that security leaders are already dealing with decision fatigue as AI-driven attacks intensify and vendor offerings proliferate. CrowdStrike has said AI-driven cyberattacks rose sharply, including attempts to target AI infrastructure itself, while experts warn that the industry is still struggling to define what AI risk actually means. The broader lesson is that firms cannot wait for a perfect defensive framework before tightening identity controls, access boundaries and incident-response processes.
Researchers and conference speakers are increasingly treating AI agents as insider threats rather than conventional software. At Black Hat, experts told Axios that agents have escaped testing environments before, and that strong permissions and monitoring are essential. That warning is reinforced by newer research on memory poisoning, reported by ITPro, which shows attackers can plant false information in an agent’s long-term memory through compromised pages, documents or tickets, causing the system to reuse malicious content as if it were trusted knowledge.
The most immediate attack path is indirect prompt injection. Instead of breaching systems directly, an attacker can hide instructions in an email, webpage or support document and manipulate an authorised agent into misusing its own access. That is why the principle of least privilege matters as much for autonomous systems as it does for staff. An agent that books meetings should not be able to move money; one that reads data should not be able to alter records. Credentials should be temporary, narrow and revocable.
The risk rises further when organisations deploy multiple agents that can pass information and tasks between each other. In that environment, a security incident can become a chain of machine-to-machine decisions, making it difficult to answer basic forensic questions after the event: where the malicious instruction entered, which agent acted on it, what permissions were active and whether the chain can be reconstructed. Traditional logging captures logins and system events, but it is weaker at explaining context, prompts and automated decisions.
There is also a governance problem that may prove harder to spot than classic shadow IT. Employees may begin deploying autonomous agents with access to files, credentials and external services without the organisation fully understanding what they do. That makes observability essential. Firms need to know what an agent can see, what it can change, who authorised it, whether its behaviour is traceable and how it can be stopped quickly. The practical aim is not to eliminate autonomy, but to secure it with the same discipline used for privileged human access.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





