The one key thing that could aid enterprise success in the agentic AI cybersecurity space today is its ability to understand agents' intent. It’s easy to state but hard to convert into an actionable security strategy.
This is why in the recent episode of The Security Strategist podcast, host John Tolbert, Director of Research and Principal Analyst at KuppingerCole Analysis, is joined by Dror Zelber, VP Product Marketing at Radware and Dhanesh Ramachandran, Product Marketing Manager at Radware. They got together to discuss the emerging challenges of agentic AI security and how to tackle it realistically.
More specifically, they break down what it actually means to secure AI agents, whether they are interacting with internet-facing applications on behalf of users or operating within enterprise environments, emphasising the importance of behavioural monitoring and visibility in managing AI agent interactions.
The conversation further spotlighted the need for enterprises to establish trust and governance frameworks for AI agents while prioritising security budgets and strategies.
Also Watch: Unmasking the Invisible Threat: Defend Your APIs Before Attackers Do
What Happens when Agentic AI moves to Production?
One question on everyone’s mind is what actually happens when agentic AI moves from experimentation into production, particularly in the context of cybersecurity.
“When it comes to agentic AI, attackers' behaviour is reliant on natural language prompting and psychology,” Zelber tells Tolbert.
Zelber explains that while one can attack a business by writing a requirement in free-text language such as English, one can also suddenly change agents’ goals; they can be hijacked using prompt injection or other ways. The entry barrier to becoming an attacker is lowered as a result.
“Enterprises are now jumping exponentially to deploy AI-oriented businesses, applications, agents and more,” the VP Product Marketing added. As a consequence, enterprises are “expanding the attack surface.”
Boundaries are lowered at stakes as low as where a regular person with little knowledge of hacking can become a skilled attacker too; meanwhile, the attack surface is expanding.
The key difference between older AI models - Large Language Models (LLMs) and modern autonomous agents is that LLMs tend to manipulate the model’s output, like tricking it into leaking private information (PII) or forcing it to generate offensive content. However, autonomous AI agents are more dangerous as they can act on their own accord.
“Autonomous AI agents could take an entire task and basically run it from start to stop without an intervention, without being given any directives,” says Zelber. “This is the major difference, and this makes agentic AI attacks far more vicious than what the cybersecurity industry is accustomed to in traditional applications.”
Also Watch: How Do You Stop an Encrypted DDoS Attack? How to Overcome HTTPS Challenges
When APIs Become the Business
Why boards must treat APIs as core product surfaces and fund intent-aware controls that track drift, identity sprawl and business logic abuse.
How to Distinguish Beneficial vs Risky AI Agent Activity
The next natural question, Tolbert asked, was how enterprises should distinguish between beneficial AI agent activity and risky agentic behaviour when deploying autonomous AI agents for operational security and enterprise risk management.
Especially given that AI agents are emerging as the new class of actors on the internet alongside traditional human or even bot traffic, the main thing to look out for is automated activity.
Ramachandran tells Tolbert that AI agents challenge traditional security strategies. That means, in the past, security teams’ focus was “distinguishing human traffic from bot traffic or separating good bots from bad bots.”
Now the focus has shifted as AI agents have entered the cybersecurity space. An AI agent may be acting on behalf of a legitimate user while continuing to perform a valid task. However, this could still generate operational business or security concerns depending on its behaviour. On the other side, malicious actors are also deploying agents for malicious activities.
“Security teams need to look beyond simply determining whether an interaction is automated,” emphasises Ramachandram. “They need to move on from just human versus bots.”
Enterprises need to consider that a new category of internet traffic is slowly growing and increasingly taking over the internet. The Radware speaker added that the agent’s actions need to be aligned with enterprise expectations.
“Ultimately, distinguishing beneficial activity from risky activity requires more than identifying the presence of an AI agent,” Ramachram notes. “It requires understanding the agent's intent, observing its behaviour, and evaluating whether the outcomes align with expectations. That's really the key when dealing with agentic traffic on the internet.”
Inside the Internet of Agents
Exposes how interconnected AI agents weaponize CVEs, automate tooling and reshape security architecture decisions.
Tolbert asked about how CISOs should address the agentic AI security issues in the enterprise space. Zelber said that enterprises must allocate budget for Agentic AI security solutions as part of their agentic AI deployment model and not as an afterthought. “Don't repeat the same mistakes as we've made with networking, web, and API."
Meanwhile, Ramachram says that the goal shouldn't be to choose between innovation and security. “The goal should be to choose to enable beneficial agentic activity while maintaining the safeguards and controls that are expected of them.”
Takeaways
- Agentic AI introduces new security challenges compared to traditional applications.
- The attack surface for AI agents is significantly broader and easier to exploit.
- Behavioural monitoring is crucial for understanding AI agent actions and intent.
- Enterprises must prioritise visibility into AI agent activity.
- Trust and identity verification are key challenges in the agentic era.
- CISOs should allocate budgets for AI security solutions early in the deployment process.
- Strict policies and governance are necessary for deploying AI agents.
- Monitoring and auditing are essential to prevent unauthorised actions by agents.
- Enterprises need to distinguish between beneficial and risky AI agent behaviour.
- The future of security lies in enabling beneficial AI interactions while maintaining safeguards.
Chapters
- 00:00 Introduction to Agentic AI Security
- 01:25 Emerging Security Challenges with Agentic AI
- 05:37 Traditional Security Measures vs. Agentic AI
- 10:44 Current Activity of AI Agents in Enterprises
- 14:29 Distinguishing Beneficial vs. Risky AI Agent Activity
- 17:13 Establishing Agent Identity and Authority
- 23:18 Priorities for CISOs in the Agentic Era
Watch the full episode for complete insights on autonomous AI agents, the future of AI cybersecurity and how enterprises can effectively manage risky AI agent behaviour while still taking advantage of the agentic technology. For further information, visit radware.com.
Comments ( 0 )