Oracle CISO and former RSA CTO say AI agents require human oversight as breach window shrinks
Oracle and former RSA executives said AI agents need human accountability and faster remediation as the breach window shrinks.
Baybeck said AI security governance must control autonomous systems that can reach data, connect applications and act on users’ behalf, making human accountability a core security requirement. Traditional controls remain necessary, he added, but security teams also need to understand the data flows and processes agents create. People therefore need a new role in supervising consequential actions.
“Humans have never been more critical to help control these robots, as we call them,” Baybeck said. “We used to say humans are the weakest link. But now what I’m saying is that robots are the most powerful and potentially dangerous link, and humans are now an essential link.”
Baybeck identified three gaps as organizations put AI into production: a lack of a solid foundational governance program for AI; missing security basics, especially in Oracle ecosystems; and misunderstanding the shared security responsibility model for AI services with service providers. Under that model, security duties are assigned to both providers and customers.
AI can also help security teams create governance programs faster, Baybeck said. “Security professionals can leverage AI and actually create a governance program, associated policies, standards, processes and best practices in a matter of hours,” he said. “There is no excuse anymore of why we don’t have a governance program in place at any company because you can literally use AI services to create that and have a very well-thought-out and deployable governance program.”
Ramzan focused on agentic security, saying agents can use credentials, call tools and choose their own routes toward a goal, expanding the paths security teams need to watch. The risk arises even when no one instructs an agent to cause harm. Traditional controls such as least privilege and defense in depth become more consequential as agents gain authority.
“[Agents] can even choose among many different paths towards accomplishing a task,” Ramzan said. “And that … is what’s gotten really interesting in the last few weeks even, where a legitimate objective can still lead an agent down a path that’s unintended, making … the types of controls we’ve talked about for decades in this industry all the more important.”
Before setting limits, organizations need to know which agents exist, whose identities they use and which systems they can reach, he said. Broad access to tools complicates applying longstanding security principles to tasks that unfold across several steps. “Least privilege does become harder when agents need broad access to different tools and capabilities,” Ramzan said. “If you give an action to an agent around a multi-step task, we’ve got to now think about things like strong authorization and monitoring in that context.”
Ramzan argued that organizations need protection throughout an attack, including where sensitive data resides. He described protecting data at its source as a final line of defense if an attacker gets past earlier controls. “Intrusion is that first step in the attack. It’s that first foothold, so to speak,” Ramzan said. “But it’s not the goal of the attacker. That breach, which is the actual material compromise of an asset, that is what ultimately the attacker is after.”
The time available to intervene after an intrusion is narrowing as attackers use AI to find and exploit weaknesses, Ramzan said. Defenders need to speed up verification and remediation while still checking the effects of patches before deployment. “AI can create an asymmetry between that machine-speed discovery and the exploitation of what you find and human-speed triage,” he said. “That’s testing, approvals, patching and recovery. The reality is that we’re not going to be able to keep up with system-level speed.”
Security teams already know which assets and operations matter most to their business, Ramzan said, giving them a way to prioritize defenses. That knowledge should shape where they invest. “Continuously learn from every incident that occurs,” he said. “Look at those near misses where you got away with it, but maybe you shouldn’t have. Take that input, take that insight [and] feed it back into your security program on a regular basis.”
TheCUBE is a paid media partner for Oracle’s event, and neither Oracle nor other sponsors have editorial control over content on theCUBE or SiliconANGLE, according to a disclosure accompanying the interviews.
Editor's Summary At Oracle’s AI security event, Oracle CISO Brennan Baybeck called for human accountability and foundational governance as AI agents gain access to data and applications. Former RSA CTO Zulfikar Ramzan said agent identity, least privilege and source-data protection are critical as the breach window narrows. Both executives said security teams must speed verification, remediation and learning from incidents.