As AI agents gain more autonomy, they can also take unexpected actions across systems, identities, and data. Organizations can prepare by applying familiar security controls to agent activity: least-privilege access, segmentation, vulnerability management, behavioral monitoring, and incident response planning.
Artificial intelligence (AI) agents are becoming more capable of working independently across systems, tools, and data as the industry leans toward autonomy and agentics. For enterprise security teams, that creates an important question: What happens when an agent does something no one expected?
Recent cybersecurity testing from OpenAI, Anthropic, and the UK AI Security Institute (AISI) is beginning to provide some answers. During controlled evaluations, AI agents took unexpected or unauthorized actions while attempting to complete assigned cybersecurity tasks. In some cases, agents reached real-world systems outside the intended scope of testing.
While these incidents were specialized cybersecurity evaluations, and some intentionally included permissive conditions or disabled safeguards to test the limits of advanced models, they do raise broader questions about how organizations control access, contain activity, monitor behavior, and set appropriate boundaries as AI agents are given more autonomy.
Let’s look at what these incidents mean for your organization’s cybersecurity plan and what it can mean for future incidents. The good news is that the defenses needed to prepare for security incidents with AI agents should look familiar.
The circumstances varied across each incident, but a common pattern emerged: agents pursued their assigned objectives in ways their operators had not anticipated.
The takeaway? Plan for agents acting outside their intended scope the same way you plan for a compromised service account: limit what it can reach, watch what it does, and keep a fast path to revoke it.
The AI agents used vulnerability exploitation, credential theft, remote code execution, lateral movement, and privileged access. Sound familiar? The only difference with AI agents is the speed at which they can combine and deploy tactics.
Let’s look at the specific steps you can take to combat AI-enhanced cyber attacks.
Security organizations need an inventory of where agents are operating and what those agents can reach. That includes understanding the identities and credentials they use, the systems and applications they can access, the data available to them, the APIs and tools they can invoke, and the actions they are authorized to take.
From there, basic identity principles apply. Agents should receive only the access required for their intended function, and that access should be reviewed as use cases change. Governance should also establish where agents can act autonomously, which actions require human approval, and where access should be prohibited altogether.
There’s substantial work to do here: 75% of more than 400 offensive AI security research efforts could ultimately be traced to some form of identity or privilege gap. Agents may be a new type of identity, but excessive permissions remain an old problem.
Non-human identities can be governed with the tooling your team already runs for human ones. Identity providers such as Okta and Microsoft Entra ID can issue scoped identities for agents and apply conditional access to those identities. Privileged access management from CyberArk or Delinea vaults the credentials agents use, brokers the sessions, and records what happens inside them. Silverfort and similar tools extend MFA and visibility to the service accounts that have historically sat outside both. Whatever the mix, agents should appear in the same access reviews, vault, and logs as every other identity in the environment.
Security teams should evaluate which internal and external connections agents actually require and restrict everything else. Existing network security principles still apply:
Data security controls can provide another layer of protection by limiting what sensitive information an agent can access, move, or expose if its behavior falls outside expectations.
Microsegmentation from Illumio or Akamai Guardicore can enforce those boundaries at the workload level, while SASE and ZTNA platforms like HPE Aruba Networking SSE, Zscaler, or Netskope control what agents can reach outbound and from where.
AI agents will increasingly automate reconnaissance, vulnerability discovery, exploitation, and lateral movement.
Despite the speed at which autonomous agents can find and attempt to exploit vulnerabilities, the steps to combat them remain the same. Security teams should focus on shortening the time between vulnerability discovery and remediation, prioritizing vulnerabilities based on business risk, exploitability, exposure, and access to critical systems or data.
Having effective vulnerability management plans and tools can help teams continuously identify weaknesses, prioritize what matters most, and track remediation before those gaps become part of a larger attack path.
Preventive controls won’t catch everything, so security teams also need visibility into what agents actually do. Authentication activity, unusual network connections, unexpected API calls, changes in privileges, large data transfers, and access to atypical systems can all signal behavior outside an agent’s intended role.
Current adoption of those safeguards appears uneven. More than 31% of security, compliance, and IT leaders had no AI containment control measures deployed in their org.
AISI’s experience shows why monitoring matters: anomalous outbound traffic helped trigger investigation and containment during testing. As agent activity expands, MDR, SIEM, and behavioral monitoring capabilities can help teams identify unusual activity quickly enough to respond before it spreads.
AI agents should be incorporated into existing incident response planning. Teams need to be able to revoke credentials, restrict connectivity, identify affected systems and data, and quickly isolate activity.
AI agents will continue to evolve, and no security team can predict every way they will behave as their capabilities expand. Fortunately, your team doesn’t need perfect predictions to prepare. Instead, it needs to make sure the security practices and tools it already relies on are ready for a faster, more autonomous source of activity.
For organizations unsure whether those foundations are ready for increasingly autonomous AI, VLCM can help evaluate your current environment. A cybersecurity assessment can help identify gaps across existing security controls, while our vCISO services can help organizations evaluate emerging risks and develop governance and security strategies around AI adoption.
AI agents may create new ways for cybersecurity incidents to unfold. The best place to start preparing is still with the fundamentals.