Why cybersecurity must evolve for the age of AI agents
Date:
Fri, 07 Aug 2026 10:26:45 +0000
Description:
As AI agents gain autonomy, organizations must rethink cybersecurity, governance and trust to manage emerging risks.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter For years, cybersecurity was built on a simple assumption: systems follow defined rules.
Applications do what they are programmed to do, while people log in, are
given permissions and access the resources they need. Artificial intelligence (AI) is changing that. With nearly 50% of cybersecurity solutions buyers expecting AI to be embedded across the cyber stack within three years, organizations are no longer focused solely on protecting applications and access rights. Latest Videos From TechRadar Watch full video here:
They also need to secure intelligent systems that can make decisions,
interact with users and act autonomously. Vishal Salvi Social Links
Navigation
Global Head of Cybersecurity Services at Cognizant. AI can draw on models, prompts, context and external tools to understand a goal, make decisions and determine how best to achieve it. You may like Why self-running agents are creating the biggest security crisis of 2026 How AI agents are wrecking havoc in legacy security setups and enterprises are catching up AI agents are the new unmanaged endpoints
As organizations give these agentic systems greater autonomy across
enterprise workflows, the consequences of failure extend beyond generating a wrong answer.
A mistake can now disrupt business processes, influence decisions and trigger unintended actions across connected systems. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. An expanded attack surface Greater autonomy creates new points of vulnerability whenever AI is given access to data, systems and external tools.
Cyber threats, such as attackers manipulating the information AI receives or impersonating trusted users, can alter how it responds or the actions it takes. This could lead an AI agent to retrieve inaccurate information or approve unauthorized actions.
Traditional cybersecurity controls were designed for humans and applications, but autonomous agents dont fit neatly into either category. Security
therefore needs to extend further across the entire AI lifecycle: before go-live, during operations, and at every point where AI learns, decides, and acts. What to read next Phishing the agent: Why AI guardrails arent enough Agentic security doesn't need a whole new definition you just need to
reframe what you already know AI agents are creating a major security blind spot in financial services
Organizations need a unified security architecture that provides consistent visibility and controls across both AI and traditional systems, which makes
it easier to identify threats, enforce policies and respond quickly when incidents occur. Trusting AI safely However, a unified architecture is only part of the solution. Businesses also need to ensure the AI agents themselves can be trusted. Like any trusted user or system, AI agents should have a verifiable identity, tightly controlled access to data and systems, and auditable records of the actions they take.
Without these safeguards, organizations risk creating AI systems that can bypass security and compliance controls because of design flaws rather than malicious intent. Security also cannot stop once an AI system is deployed. Unlike traditional software, AI systems learn from new data, operate in changing contexts and can behave differently over time.
Organizations therefore need continuous monitoring to ensure agents stay within defined boundaries and policies continue to be enforced. That includes clear ownership, escalation paths and kill switches that can safely contain
or stop an agent behaving unexpectedly. Some organizations are also beginning to use "guardian agents" that monitor other AI agents and flag unusual behavior.
The level of oversight should reflect the level of risk. AI agents carrying out low-impact tasks can remain largely autonomous, while higher-risk activities - such as updating customer data, approving financial transactions or interacting with production systems - should have stronger guardrails.
Applying controls in proportion to risk allows organizations to capture the benefits of AI while maintaining security, compliance and trust. Context as a security boundary Securing AI also means securing the information it relies on. Context is what gives AI agents their power. This includes internal documents, customer information, business rules and previous interactions, helping agents understand a task and decide what to do next.
That also makes context a new security boundary. If the information an AI relies on is inaccurate or has been deliberately manipulated, the decisions
it makes can be wrong, even if the underlying model is working exactly as intended. This is known as context poisoning.
Protecting against this means controlling what AI can see as well as what it can do. Agents should only have access to the data and systems they need for
a specific task. For example, an AI assistant answering employee questions should not have the same level of access as one authorized to approve payments.
Guardrails must go beyond filtering outputs and extent to protecting the integrity of the information AI uses, ensuring it is accurate, up to date and appropriate for the task at hand. Governance at scale Technical controls are most effective when they are supported by effective governance. This requires a joined-up approach that brings together AI and traditional systems, with consistent controls across the business.
Organizations should also define where human intervention is required and who is responsible for the decisions models make. Oversight should focus on the activities that carry the greatest operational, financial or regulatory risk, supported by investment in the skills needed to govern AI effectively and maintain trust in autonomous systems. The path forward Ultimately, securing
AI is about more than protecting systems from attack. Organizations need the right technical solutions, clear ownership and continuous oversight
throughout the AI lifecycle. Trust depends on these elements working
together.
The organizations that succeed with AI will not necessarily be those that
move fastest, but those that scale it securely and responsibly. The question for leaders is no longer whether to trust AI, but whether they are building systems that deserve to be trusted. We've reviewed, rated, and ranked the
best endpoint protection software . This article was produced as part of TechRadar Pro Perspectives , our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here:
https://www.techradar.com/pro/perspectives-how-to-submit
======================================================================
Link to news story:
https://www.techradar.com/pro/why-cybersecurity-must-evolve-for-the-age-of-ai- agents
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)