{"id":9088,"date":"2026-08-11T08:25:00","date_gmt":"2026-08-11T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9088"},"modified":"2026-08-11T08:25:00","modified_gmt":"2026-08-11T08:25:00","slug":"security-leaders-rogue-ai-confidence-could-actually-be-disastrous","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9088","title":{"rendered":"Security leaders\u2019 rogue AI confidence could actually be disastrous"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A large majority of IT and security leaders are confident in their teams\u2019 ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope.<\/p>\n<p class=\"wp-block-paragraph\">Nine in 10 IT and security leaders surveyed by <a href=\"https:\/\/www.cio.com\/article\/4176067\/the-ai-governance-imperative-you-cant-afford-to-ignore.html?utm=hybrid_search\">IT observability<\/a> vendor WanAware believe in their capabilities to find malfunctioning agents, but only 26% acknowledge that they can trace the downstream impact within minutes. Over 45% say it would take hours to understand the full impact of an agent incident.<\/p>\n<p class=\"wp-block-paragraph\">That delay between detection and mitigation can be a huge problem, says <a href=\"https:\/\/www.linkedin.com\/in\/jmcollins\/\">Jeffrey Collins<\/a>, WanAware\u2019s CEO. The survey suggests IT leaders are overconfident about their ability to control agents, he adds.<\/p>\n<p class=\"wp-block-paragraph\">And here, timing is critical, Collins says, given that malfunctioning agents can lead to major outages and data breaches \u2014 damage that can start within seconds, he notes.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat\u2019s truly the gap here. It\u2019s not if you understand it; it\u2019s when you understand it,\u201d Collins says. \u201cIf your average time to just knowing about an event is measured in days, weeks, or months, you have a serious problem right now.\u201d<\/p>\n<p class=\"wp-block-paragraph\">While it\u2019s not always easy to tell whether an agent has gone beyond its scope, it\u2019s even harder to tell the downstream impacts, he adds.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat\u2019s been affected if one machine was compromised, either from our own AI usage as a customer or from someone else\u2019s, what else could happen, and how can we understand that quickly?\u201d Collins asks.<\/p>\n<h2 class=\"wp-block-heading\">Machine speed<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/kevin-paige-578547a\/\">Kevin Paige<\/a>, field CISO at IT solutions provider C1, agrees that time is of the essence when an AI agent malfunctions.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe problem is that agents move at machine speed, so the gap between an agent malfunctioning and you catching it isn\u2019t measured in minutes, it\u2019s measured in actions,\u201d he says. \u201cEvery minute it\u2019s wrong it\u2019s still working, and because it\u2019s usually running on borrowed standing credentials, the damage spreads across everything those credentials can reach before anyone can pin it on the agent.\u201d<\/p>\n<p class=\"wp-block-paragraph\">In many cases, organizations with rogue agents don\u2019t find out from their <a href=\"https:\/\/www.cio.com\/article\/4195251\/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs.html\">own detection tools<\/a>, but from customers, auditors, or broken downstream systems, he says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat\u2019s the worst way to learn,\u201d Paige adds. \u201cThe longer-term cost is trust, because one incident like that and the business pulls back on agents entirely, so failing to contain a malfunction fast is also what stalls adoption.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The problem with detecting <a href=\"https:\/\/www.cio.com\/article\/4127774\/1-5-million-ai-agents-are-at-risk-of-going-rogue-2.html?utm=hybrid_search\">rogue agents<\/a> is that many organizations have built in visibility but not control, he says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen an agent goes out of scope it\u2019s rarely dramatic,\u201d Paige adds. \u201cUsually, it\u2019s using access it legitimately has, for a purpose nobody signed off on, which means your access model doesn\u2019t even flag it. So you find out after the fact, and you fix it by hand.\u201d<\/p>\n<p class=\"wp-block-paragraph\">IT teams can stop agents that exceed their scope, but only if controls were built in before the agent was deployed, adds <a href=\"https:\/\/www.linkedin.com\/in\/chrisdcamacho\/\">Chris Camacho<\/a>, COO of Abstract Security.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEvery agent should have its own identity, narrowly scoped permissions, and a complete audit trail,\u201d he says. \u201cJust as important, organizations need the ability to immediately revoke that identity or suspend the agent without manually hunting through multiple consoles during an incident.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Part of the challenge is that an agent\u2019s activity is spread across identities, cloud platforms, SaaS applications, APIs, and security tools that were not designed to tell a complete story, Camacho says. Security teams often have to piece together events from multiple basic questions such as, what did the agent access, and what changed?<\/p>\n<p class=\"wp-block-paragraph\">\u201cMost organizations know where they\u2019ve deployed AI agents,\u201d he adds. \u201cThat\u2019s very different from knowing exactly what an agent did after something unexpected happens.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The organizations that most successfully manage agents won\u2019t be the ones that deploy the most, he says. \u201cThey\u2019ll be the ones that can explain every action an agent took, prove it operated within policy, and stop it immediately when it doesn\u2019t,\u201d he adds.<\/p>\n<h2 class=\"wp-block-heading\">Confidence isn\u2019t reality<\/h2>\n<p class=\"wp-block-paragraph\">The survey\u2019s results make sense to <a href=\"https:\/\/www.linkedin.com\/in\/brinkleyjoseph\/\">Joe Brinkley<\/a>, director of offensive security research and community at pentest firm Cobalt. The high confidence in detecting malfunctions is compliance paperwork, whereas the minority of respondents who can detect problems quickly is the reality on the ground, he says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cTracing agent impact fast is brutal,\u201d Brinkley says. \u201cThese systems do not run on fixed code paths. They use nondeterministic reasoning across a web of different APIs. Traditional logs only catch isolated events. They completely miss the full execution chain.\u201d<\/p>\n<p class=\"wp-block-paragraph\">By the time an anomaly alert hits, an agent has already executed multiple downstream actions, he adds.<\/p>\n<p class=\"wp-block-paragraph\">In some cases, agent malfunctions are related to data flow vulnerabilities, such as when a prompt injection from an untrusted input such as a malicious email overwrites the system instructions, he says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe need to be clear about the actual technology; the AI is not waking up angry,\u201d Brinkley says. \u201cThe agent suddenly thinks its official job is to dump your database. It spends tokens as fast as possible to do that.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Agents are also vulnerable to loop failures, when they hit API errors and try to self-correct, he adds.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt hits that same broken endpoint 10,000 times in two minutes,\u201d he says. \u201cIt drains your budget and causes a self-inflicted denial of service. It is an automated wrecking ball moving faster than your monitoring can log it.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Brinkley recommends that IT leaders put \u201chard kill\u201d switches at the API layer to stop agents going out of scope.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou can stop it, but soft guardrails are useless,\u201d he says. \u201cDo not try to patch the prompt or filter the text. You have to treat the agent like a compromised user account. Pull the OAuth tokens and kill the access immediately.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A large majority of IT and security leaders are confident in their teams\u2019 ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope. Nine in 10 IT and security leaders surveyed by IT observability vendor WanAware [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9089,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9088","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9088"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9088"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9088\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9089"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}