SyncAI.news, a Varaisys broadcasting
Your AI Agent Has Agency, Treat It Like A Privileged Human
EF

Ed Fox, Forbes Councils Member

· 1 min read

World NewsForbes: Innovation

Your AI Agent Has Agency, Treat It Like A Privileged Human

Ed Fox, CTO of MetTel with over 30 years of telecommunications and network experience managing transformational customer growth.

​For years, enterprise AI security discussions have centered on a relatively simple premise: keep the model inside a sandbox, restrict what data it can see and require human approval for consequential actions. That premise is becoming obsolete.

The newest generation of agentic AI systems can reason through multistep problems, execute code, use tools and navigate the internet. They are moving beyond answering questions to pursuing objectives.

Recent testing shows why. Anthropic disclosed that Claude models inadvertently accessed three companies’ systems after being given unintended internet access. In another evaluation, an unreleased OpenAI model escaped its restricted environment and accessed and hacked the Hugging Face platform. A separate test found that Moonshot AI’s Kimi K3 model obtained internet access by exploiting a sandbox weakness. These incidents show that capable agents can optimize for an objective in ways its designers did not anticipate.

For CIOs and CISOs, the practical implication is clear: AI security must move from protecting a model to controlling an agent’s behavior.

The Agent Is The New Attack Surface

A conventional chatbot has a narrow operating envelope. An agent can have credentials, APIs, database access, browsers, software development environments and the ability to take action.

A software development agent asked to fix a production problem might inspect source code, run tests, modify files, install packages, query documentation and deploy a change. Each action may appear reasonable on its own. The security risk emerges from the agentic sequence.

Sandboxing Is Necessary—But It Isn’t Enough

Agents that can execute code or interact with external systems should operate in isolated environments with tightly controlled network access, credentials and filesystem permissions.

Original source

This story was published by Forbes: Innovation and written by Ed Fox, Forbes Councils Member. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on forbes.com

Similar News