AI News Feed
Market watch
Cybersecurity

Delegated authority turns trusted AI agents into security problem

At Fal.Con, Dash Security executives say agentic AI with delegated authority challenges traditional defenses, requiring runtime visibility and governance.

Mathur, co-founder and chief product officer, explained that AI agents are fundamentally different from other technologies. “They are non-deterministic, number one. They mix data, instructions and the input that they get,” he said. “Unlike other technologies, you are giving the AI agents a lot of delegated authority, which means that they are supposed to have access to a lot of systems and critical data.” The inversion has opened a market for startups built around the runtime behavior of autonomous software.

Hod, co-founder and chief executive officer, said fragmented tooling is the first obstacle. Sanctioned tools sit alongside shadow deployments on workstations, in browsers and across cloud environments, leaving teams without a clear view of how data crosses trust boundaries. Dash Security starts with visibility, mapping the AI estate before applying policy. “First we start with visibility, providing the right visibility to understand what people are doing with AI, with what AI tools they have within their organization,” Hod said. “Then to give the right size guardrails in order not just to help customers to block stuff, also to make sure that they can adopt AI in confidence, but at the same time not slow the organization.”

That context turns blunt controls into precise ones. Mathur cited a customer with 140,000 employees that was blocking users whose reports contained nine-digit numbers unrelated to Social Security records. “We understand the agent’s role and their past history,” he said. “We can say that this is a guy in operations who’s running a report on something which has a nine-digit number, which has nothing to do with Social Security. We were able to reduce false positives by 95%, and they rolled it out with action automatically being taken for their entire user base.”

Dash integrates with CrowdStrike Holdings Inc., pulling endpoint telemetry into the agent session and feeding the stitched signal to Falcon Next-Gen SIEM, CrowdStrike’s security data and detection platform. For a company founded in October 2025, agentic AI security means tracking the frontier labs as closely as the attackers. “Security follows the curve of the technology that you’re protecting,” Mathur said. “One of the core focuses we always have is to deeply understand on one hand how generative AI and agentic AI [are] changing and evolving, what the frontier labs are doing. The second thing is [to] deeply try to understand how our customers are adopting and using this technology.”