AI News Feed
Market watch
Cybersecurity

Agentic AI Requires a New Approach to Enterprise Security, Proofpoint Strategist Says

TechRadar: 76% of enterprises pilot autonomous AI agents; 42% report AI-related incidents, exposing security gaps.

Unlike traditional generative AI, which responds to a question and stops, agentic AI pursues an objective. It interprets a request, selects tools, accesses data and acts across connected business environments. A conventional assistant might summarize an email chain, while an autonomous agent could read it, pull details from a CRM, draft a response, update a Zendesk ticket and schedule a follow-up call. Each stage may look legitimate on its own, but the end result could still be wrong, excessive or manipulated. Blocking AI tools outright is not practical, the article says, because it pushes employees toward unapproved services where activity and data flows are harder to see. Leaders should treat AI agents as a new category of digital worker, with clear boundaries, oversight and accountability.

Securing autonomous AI agents means moving from access control to behavior-aware governance. Permission to act matters less than whether that action fits the original request, the data it touches and the consequences it could trigger. Traditional enterprise security assumes a person makes the decision and a system executes it. Agentic AI compresses that chain: a human writes the prompt, the AI interprets it, pulls in connected tools and triggers the action itself, often without a checkpoint between decision and execution. That works for low-risk, repetitive, reversible tasks. Once an agent can send external communications, modify sensitive records, approve transactions or change permissions, a misunderstood or malicious instruction turns into an immediate consequence.

Security teams must assess what an agent is doing, why it is doing it and whether its actions remain aligned with organizational policy and human intent, according to the article. Governance has to cover the full chain of activity, from the original request through to the outcome inside a business system.

One emerging concern is semantic privilege escalation, where an agent stays fully within its access rights but stretches them further than the user intended. An employee might ask an agent to organize customer communications. With access to a CRM, an email platform and a customer database, the agent could read that instruction broadly enough to email confidential pricing details to the wrong contact, message an entire distribution list instead of one recipient, or push through a change that should have needed a manager's sign-off. The agent stays within its authorization the entire time; the mismatch is between its behavior and human intent. Static permissions cannot catch that gap. Organizations need controls that weigh an action's purpose, context and likely impact before it completes, not just its permission level.

AI agents are directed by prompts, shaped by whatever information they receive and trusted by employees who assume the output is correct. That creates three failure points: what data goes in, how the agent interprets it and how much employees trust what it produces. Employees paste sensitive data into prompts or upload confidential files without thinking twice. An agent can misread a request or get steered by hidden instructions buried in an email, document, chat message or webpage. Employees often wave AI-generated recommendations through without the scrutiny they would give a colleague's advice.

Prompt injection is the clearest example. Attackers hide instructions inside content they know an AI agent will process. If the agent treats that content as trustworthy, it can ignore policy, leak data, alter a workflow or act on an instruction no human ever approved. Against a chatbot, that produces an embarrassing wrong answer. Against an agent with direct access to tools and systems, it produces an executed action. Data leakage compounds the problem. Agents typically need broad access to enterprise data, which means sensitive information can travel through prompts, uploads, generated responses, logs and retrieval workflows.