Oracle event puts focus on securing data at the source as agentic AI attacks escalate
Analysts at an Oracle event said agentic AI attacks are pushing security controls into databases and broadening what recovery means.
Krista Case of theCUBE Research and Dave Vellante discussed the event's main takeaways in a broadcast on theCUBE, SiliconANGLE Media's livestreaming studio, according to SiliconANGLE. Their conversation followed interviews with Oracle's security leaders and outside industry analysts.
The analysts described trust boundaries being relocated to the database itself, where access policies can be enforced regardless of the instructions an AI agent has been given. That approach gained urgency after recent high-profile breaches involving agents that escaped from model provider labs.
"What agentic has done is it really has solidified the fact that even very mature security programs, at some point, will likely fail," Case said. "Now, with agentic AI, we have these new agentic-fueled attacks that are making all of the headlines. So, when it comes to cyber resilience and business resilience, the impact that this has had is that it's really become a part of the security conversation. It really needs to be built in up front because there is a recognition that we cannot just build the fences high enough."
Attackers equipped with AI can operate at machine scale, compressing the time organizations have to respond and forcing them to reconsider where controls sit and how quickly they can recover once defenses fail. Case and Vellante said the traditional cloud-era shared responsibility model is giving way to a shared accountability model: vendors remain responsible for ensuring their products work securely and as promised, while customers must understand the criticality of their own assets, set policies and decide how much risk they will accept.
"The mainspring of innovation at Oracle has always been the core database," Vellante said. "Oracle's philosophy is you've got to secure at the source, at the data, take the burden off the application. You, the customer, are responsible for understanding the criticality of your assets. The vendor is responsible for making sure that the product is safe, that when it takes action it does so in a governed way, as advertised and as promised. Recovery is a big deal."
As AI agents begin making decisions and taking actions across business systems, recovery now extends past the data. Organizations also have to define what a trusted operational state looks like and how to return business processes and functions to it after an incident.
"Recovering data is still incredibly fundamental, but it has to go much beyond that," Case said. "We need to be able to have that understanding of a trusted good state of business ... having that understanding and also having an understanding of what it means to get the business back to that point. So, it goes again beyond data, even beyond applications and systems, to having that understanding of these business processes and functions and what it means to again roll them back or get them back online."
That wider definition raises questions conventional disaster recovery plans may not cover, including what an AI agent was trying to accomplish when an incident occurred, which systems or processes were affected, and who has the authority to decide when the business can safely resume operating. It also shifts weight toward building resilience into systems before an attack rather than depending solely on detection and response afterward.
theCUBE is a paid media partner for the Oracle event, and sponsors of theCUBE's event coverage do not have editorial control over content on theCUBE or SiliconANGLE.