AI agents are evolving quickly, turning from experimental tools into autonomous enterprise actors. For organizations that want to deploy them, that’s creating new challenges around cybersecurity, governance and trust, observes Nishant Doshi, CEO at AI and data security solution provider Cyberhaven.
“Agents are moving at machine scale. They’re assuming identity. They may have access to more data than we realize, and this is leading to serious trust issues,” Doshi told The Forecast in an interview.
Given the emerging security risks surrounding agentic AI, organizations must ensure that they can safely adopt AI agents while also bridging the agentic AI trust gap that exists among enterprise leaders and users.
The solution, according to Doshi and other agentic AI thought leaders, is strong governance of agentic AI.
With AI agents performing increasingly complex tasks with a high degree of autonomy, people should think differently about the systems they use, Doshi suggested. Unlike generative AI, he noted, agents can have elevated permissions, autonomy and decision-making authority. That can expand not only productivity opportunities but also the attack surface.
“If one human was executing 10 queries a minute, agentic workflows are executing 10,000 queries a minute,” explained Doshi, who said agents’ incredible velocity and volume raise security concerns: Things can break fast and at an unprecedented scale.
Unlike generative AI, which merely responds, “agents can create, replicate and share data,” Doshi continued.
Agents also are more prone to indiscriminate data retrieval, and may have extensive access — a potentially toxic mix.
“For example, an agent might exploit an over-permissioned SharePoint and expose confidential data,” Doshi said.
The very nature of agentic activity puts organizations in a novel position regarding security, added Daniel Saks, CEO of the agentic AI company Landbase.
“The big problem businesses have to face today is to determine who is going to be accountable for something going wrong,” he told The Forecast in an interview.
“Trusting an agent is a very foreign concept.”
To build trust in AI agents, organizations must mitigate the possible security risks associated with them. That means being proactive about permissions — what agents are and aren’t allowed to access.
For humans, the principle of least privilege guides permissions: Don’t give people access to more than they need.
“For agents, it’s the principle of least agency,” Chris Cochran, field CISO and vice president of AI security at the SANS Institute, told The Forecast in an interview.
“You have to determine exactly what you want an agent to do inside of an organization — inside of a process — and then you set those permissions accordingly … Don’t over-provision an agent just for the sake of agency.”
Organizations can also take a fresh look at how permissions are assigned. “Every agent must be treated as a distinct principle, with its own cryptographically attested identity,” Doshi said, adding that IT can also utilize lifecycle controls, applying processes to automatically remove an agent’s permissions the moment a task concludes.
To ensure these controls work as planned, “you may want to do some controlled pilots,” Saks noted. “Assess your AI maturity curve and build trust in a controlled environment.”
The ability to monitor network activity is key to effective cybersecurity. That becomes a challenge as AI agents come to the fore, Doshi suggested, noting that today’s tools are not especially effective at distinguishing human from agentic behavior on the network. IT can’t always know for sure who’s acting.
In theory, “machine speed and the fragmented data movement are distinctive enough to recognize agentic workflows versus human workflows,” Doshi said. But in practice, “that’s something traditional models haven’t been able to solve very well.”
IT leaders must keep a close eye on the emerging toolsets that may support greater visibility into agentic-versus-human network behaviors.
“Like any type of tooling that is needed to secure or prevent malicious actions of humans, the same thing will need to exist for agents on the network,” Saks said.
“There’s going to be a new set of network behavior security vendors [with] a new set of tools that are going to safeguard against new things.”
Meanwhile, Cochran believes organizations should be shoring up their identity-management practices.
“Being able to first tie an identity to an agent is the most important part,” he stressed. With that visibility comes the ability to apply controls: “Is this agent allowed to do this?”
Ideally, organizations will be working toward a three-pillar framework based on visibility, observability and runtime control, Doshi said.
“You must discover every local and cloud agent, reconstruct the entire workflow, and understand where and how data’s flowing through these systems end to end,” he explained.
“Then you can have a centralized orchestration tower that can apply data protection across a very heterogeneous environment.”
If the security issues around agentic AI feel familiar, that’s because they are: Users of technology have always asked, “Can we actually trust it?”
“This is the same issue that’s been around forever. It’s just way magnified with agents, because the risk is way higher,” Saks said.
Because the risks are so consequential, IT departments alone can’t mitigate them from agentic AI. Doshi believes that leaders across the business must drive culture change to ensure AI agents are deployed at scale safely and responsibly. Doing so starts with establishing clarity for end users.
“What potential tasks can these agents perform?” Doshi asked. “Giving them guidelines and frameworks will allow users to have more trust in using agents so they can be sure that they are not going to cause damage.”
That means IT leaders must also ensure that they have a solid handle on the agentic solutions they’re implementing: In order to trust that an agent isn’t going to put security at risk, you need to know what it’s doing and how it works, Cochran noted.
“Trust is really about understanding what we’re getting when we use AI technologies,” he said.
At this pivotal moment, with agentic AI coming fast and hard, it’s vital that leaders get ahead of trust issues and other challenges. If they do, they can replace risks with returns, Saks said.
“If you’re too conservative, you’re missing out on being on the cutting edge of AI,” he concluded.
Related:
Minimizing risk of AI agents for public sector
More Reasons to Migrate From VMware
Futurist Mike Bechtel Sees AI Shifting From Push to Pull in 2026
Rising Agentlakes Feed AI Agent Sprawl
Adam Stone is a journalist with more than 20 years of experience covering technology trends in the public and private sectors.
© 2026 Nutanix, Inc. All rights reserved. For additional information and important legal disclaimers, please go here.