AI & TechnologyAgentic

The Rise of AI Agents Demands a New Security Model

By Hasan Imam, CEO of Obsidian Security

AI agents have now arrived as full, robust integrations into critical business operations across industries. Organizations are giving them access to code repositories, CRM platforms, collaboration tools, and other applications where some of their most sensitive information lives. But as enterprises expand what agents can access, they are also creating a new attack surface that traditional security controls were not designed to govern. 

The challenge is not simply that agents can make mistakes. Unlike conventional software, agents can make decisions and take actions across multiple systems with limited human intervention. When an agent has excessive permissions, interacts with a compromised tool or is manipulated by an unexpected input, a seemingly simple prompt can quickly escalate to a critical security incident.  

Every enterprise is racing to put AI agents to work across all kinds of tasks, from strategy development to coding to even the mundane admin work.  Agents become truly valuable when they can access and operate inside third-party applications for these tasks, but that is also where legacy security models begin to fall short. With the right controls in place to block high-risk actions and monitor activity in real time, security can become the function that closes that gap, turning AI momentum into AI confidence for the business. 

The Threat Is Already Taking Shape 

Securing this new layer requires a deep understanding of identity and privilege activity inside third-party applications, combined with guardrails and runtime enforcement that allow agents to deliver productivity without introducing unacceptable risk.  

Non-human identities now outnumber human identities by 144 to 1, and agentic access to third-party applications is accelerating that shift. Third-party applications are no longer just SaaS tools; they are becoming data platforms that power AI-driven workflows. As enterprises rapidly adopt these applications, AI agents are emerging as some of their most active users.  

At the same time, the models behind these agents are not just getting more capable. Each generation can reason more effectively, and chain actions together faster than a human ever could. This represents a different category of capability, and it is moving into production faster than security teams can establish the necessary controls. Agents have autonomy, access and, increasingly, the permissions to update, modify and delete. 

Enterprise data stored in third-party applications may be particularly vulnerable as agents gain greater access to business systems. The opportunity for agentic AI is clear, but so is the need for stronger guardrails that limit what agents can access, monitor the actions they take and intervene when their behavior exceeds the defined parameters. Finding the right balance between capability and control will be critical to unlocking the productivity benefits of agents without introducing unnecessary risk. 

Recent incidents demonstrate why this matters. OpenAI recently disclosed that one of its frontier models escaped its testing environment after exploiting a misconfiguration and accessed AI platform Hugging Face to retrieve evaluation data. Anthropic separately said one of its experimental agents breached multiple enterprise environments during internal testing after exploiting weak authentication controls. 

These incidents occurred during testing but point to a broader concern that as agents become more capable, they can also interact with systems in ways that security teams may not anticipate. Once those capabilities are connected to production environments and sensitive third-party applications, the potential consequences due to compromise become much greater. 

Innovation Without Compromising Security 

Organizations are entering a new era of software autonomy, giving AI agents the ability to act with a level of independence few technologies have had before. That requires security teams to establish a level of control they can trust, one that can enforce runtime policies on AI agents operating inside third-party applications safely and precisely, without slowing the business down. 

The ability to understand what an agent is attempting to do as it operates and intervene when its behavior crosses an established boundary will be paramount as agentic AI is increasingly embedded into enterprise workflows. If an agent suddenly attempts to access sensitive data, escalate its privileges or perform a destructive action, detecting that behavior after the fact is not enough. Controls need to be capable of stopping the action before it creates impact. 

The goal should not be to slow AI adoption. It should be to make autonomy predictable and controllable. AI agents will continue to move deeper into the systems that run the enterprise. The organizations that successfully scale them will be those that can give agents the ability to act without giving them unchecked authority. That requires security teams to move beyond securing the model itself and toward securing the identities, applications, tools, and data that allow an agent to operate.  

As agentic AI adoption continues to grow, the central security question is no longer simply, “Can this AI system be trusted?”, but “What exactly can this agent access right now, and what happens when it attempts to do something it shouldn’t?”. Security leaders who can answer these questions aren’t managing AI risk reactively; they’re the strategic partner the business needs to move forward with confidence in this next phase of enterprise AI security.  

Related Articles

Back to top button