AI benefits/risks

Are our AI agents turning rogue?

AI Artificial Intelligence technology for data analysis, research, planning, and work generate. Man uses a laptop and AI assistant dashboard. Technology smart robot AI agents and agentic workflows.

COMMENTARY: Agentic AI has been sold to the enterprise on a simple and compelling promise: software can now do more than assist employees. It can perform work on their behalf. In many cases, they can complete in seconds what previously required several employees and multiple approval steps.

The efficiency gains are real, but so are the risks.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

The same autonomy that makes an agent valuable also means that a single rogue, compromised or badly instructed agent can cause enormous damage before a human being even realizes that something has gone wrong. Hugging Face-like attacks demonstrate the broader problem: once an autonomous system has access to tools, credentials and infrastructure, malicious or manipulated behavior can propagate at machine speed.

This changes the security equation fundamentally.

Consider something as mundane as pricing. A commerce agent may legitimately have permission to update product information, generate promotional offers and synchronize prices across a website. If that agent gets compromised, manipulated through malicious instructions, or simply makes an incorrect autonomous decision, it can change hundreds of prices almost instantly. A $1,499 product could suddenly be offered for $14.99. Contractually binding orders could begin arriving seconds later.

By the time an employee notices, the damage has already occurred.

The same scenario applies to corporate communications. Imagine a publicly-traded company preparing an acquisition announcement. A compromised agent modifies one sentence on the website several hours before the official release, suggesting that negotiations have failed. Automated trading systems and financial media crawlers pick up the change. The company's stock begins moving before anyone inside corporate communications understands why.

The attacker did not need to break into a web server. The agent already had permission to publish.

Even when a human approval step exists, automation creates its own psychology. Employees become accustomed to agents producing acceptable work and gradually begin reviewing outputs less carefully. The more reliable automation becomes, the easier it is for one dangerous change to slip through.

Email presents the simplest illustration of the problem. An executive assistant agent may prepare meeting summaries, distribute financial information or send internal documents. Give it access to email and corporate directories, and a single incorrect recipient can transform a productivity tool into a major data-loss event.

A confidential acquisition analysis intended for the CFO can be sent to an outside contact with a similar name. A customer list then gets attached to the wrong message. Source code, pricing strategy or unpublished earnings information can leave the company without malware ever touching the employee's laptop.

These are not traditional attacks in the familiar sense. The credentials are often legitimate. The API calls are authorized. And the agent may operate from an approved corporate system. Endpoint security might see absolutely nothing unusual.

The problem is the behavior. That raises a question enterprises need to begin asking much more aggressively: Who's watching the agents?

Organizations have spent decades building security controls around humans. Privileged users are monitored. Network traffic gets inspected. Applications generate alerts. Financial transactions have approval limits. Yet companies now introduce autonomous systems capable of acting across those same environments without establishing an equivalent layer of oversight.

That gap becomes especially dangerous as agentic networks emerge. One agent may collect information, another may generate content, another may execute an action and a fourth may verify the result. This architecture can produce extraordinary efficiency, but it also makes responsibility harder to trace. A harmful action may result from a sequence of seemingly reasonable decisions distributed across multiple autonomous systems.

Organizations should understand which agents are active, the privileges they hold, what systems they are interacting with, and whether their behavior remains consistent with their assigned objectives. Agentic network monitoring therefore needs to become part of the architecture rather than an afterthought and security systems need the ability to intervene when behavior crosses clearly-defined boundaries.

Teams should stop any agent that suddenly attempts to send confidential financial material outside the company. A marketing agent attempting an unusually large website modification should require additional authorization.

I'm not making an argument against agentic AI. The productivity advantages are too significant, and competitive pressure will make adoption unavoidable for most enterprises.

But autonomy without observation is not automation: it's delegation without supervision.

Companies embracing the remarkable efficiency of agentic networks must therefore make an equally serious investment in monitoring those networks and stopping dangerous behavior in real time. We don't want slow the agents down. We want to ensure that when an agent can change a price, publish a statement, send a contract, or distribute a company secret in seconds, someone – or something – will watch those seconds very carefully.

Dennis Zimmer, co-founder and CTO, Codenotary

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Dennis Zimmer, Codenotary

Dennis Zimmer is a co-founder and the chief technology officer of Codenotary, provider of tools for notarization and verification of the software development lifecycle attesting to the provenance and safety of the code. He has more than 25 years of experience in the IT industry.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds