When agents move at machine speed, security teams lose their lag time, as autonomous software now reads, writes, and moves corporate content faster than any human adversary could. The agentic AI attack surface is less a matter of new territory than of new velocity.
Security leaders are forced to rebuild detection, visibility, and governance around agents they cannot always see. Much of that activity is landing back where enterprise defense started, on the endpoint.
Endpoint Security
CrowdStrike Holdings Inc. has responded by extending the Falcon platform to police agents at the endpoint, treating each one as an asset with an identity and a data footprint attached, according to Cristian Rodriguez, field chief technology officer of the Americas at CrowdStrike.
“Every enterprise has a collection of assets, and those assets are made up of this anatomy of the type of system that they run on, the identity that that system is attached to, the type of data that that system can ultimately access, and then AI essentially automates and accelerates that entire experience from start to finish,” Rodriguez said.
Related: FTC and 22 States Sue Amazon Over Ads
Rodriguez and Heather Ceylan, chief information security officer of Box Inc., spoke about the challenges of securing the agentic AI attack surface. Box added controls to govern AI agents working with enterprise content in July.
Speed of Attack
“Attack surface is the same, but it’s not just humans who are the attackers anymore. It’s agents and they move at machine speed. So everything got faster. Our detections need to be faster, our visibility needs to be real time,” Ceylan said.
Early adopters are now discovering what they deployed. Enterprises that moved first are returning to CrowdStrike six months to a year later asking for visibility and data controls across the estate, Rodriguez noted.
They’re calling CrowdStrike saying, they have a problem, the AI sprawl is real, they know it’s in their SaaS apps, they know it’s on their endpoints, they know it’s in their cloud instances, help them get their arms around visibility and governance programs and control, because they’ve bitten off a little more than they can chew, Rodriguez said.
Related: Microsoft and Amazon credentials exposed in LiteLLM attack
Securing the agentic AI attack surface remains unsettled work, with no agreed architecture and no shared responsibility model. Security teams have to move at least as fast as engineering to stay in the process at all, Ceylan noted.
The next couple of years are going to be really uncomfortable for CISOs and security leaders around AI. They haven’t really figured out what does security for AI look like and what is a secure AI architecture, Ceylan said.
In comparison to past experiences with cloud security, the industry is still in the process of figuring out how to secure AI, and it’s likely that it will take some time to develop a standardized approach. As Ceylan mentioned, it’s changing by the day, and everybody’s kind of figuring out what works best for their organization.
