What's Happening?
Rubrik Zero Labs has issued a warning regarding significant security gaps emerging as enterprises rapidly adopt agentic AI systems. New research, based on a survey of over 1,600 IT and security leaders, indicates that organizations are deploying autonomous
AI systems without adequate controls, creating a disparity between innovation speed and security measures. A staggering 86% of respondents anticipate that AI agents will outpace their organization's security guardrails within the next year. Furthermore, only 23% report full visibility into the agents operating in their environments, a figure likely overestimated. This lack of visibility is compounded by 'identity sprawl,' where non-human identities tied to agents proliferate faster than enterprises can track or govern, leading to potential misuse and compromise. Kavitha Mariappan, Chief Transformation Officer at Rubrik, emphasized that AI adoption is outpacing control capabilities, making operational safety a critical challenge as decision-making shifts from human to machine.
Why It's Important?
The rapid, uncontrolled deployment of agentic AI poses substantial risks to enterprise security and operational integrity. The lack of visibility and governance over AI agents creates new attack vectors and vulnerabilities, potentially leading to data breaches, system failures, and significant financial and reputational damage. The report highlights that over 80% of respondents find agents require more manual oversight than they save in efficiency, and 88% lack the ability to roll back agent actions without system disruption. This indicates that the promise of AI-driven efficiency is currently undermined by operational challenges and security concerns. The shift from human to machine decision-making necessitates a robust resilience strategy, making AI strategy inseparable from security strategy for boards and executive teams. Without proper controls, organizations risk creating environments where failures cannot be contained or reversed, with nearly half of respondents expecting agentic systems to drive the majority of attacks in the coming year.
What's Next?
Organizations will need to prioritize the development and implementation of comprehensive security frameworks specifically designed for agentic AI. This includes enhancing visibility into AI agent operations, establishing robust identity verification processes for non-human identities, and developing mechanisms for governing and restoring AI systems. Steven Ramirez, VP, Chief Information Security & Technology Officer at Renown Health, stressed that verification and visibility are prerequisites for sound, secure agentic implementation. Enterprises will likely invest more in security solutions that can monitor, control, and audit AI agent activities. Furthermore, there will be an increased focus on integrating AI strategy with overall resilience strategy, ensuring that deployment speed does not compromise control mechanisms. Regulatory bodies may also introduce new guidelines or requirements for securing AI systems, prompting organizations to accelerate their efforts in this area.
Beyond the Headlines
The security challenges presented by agentic AI extend beyond technical vulnerabilities to fundamental questions about trust and control in increasingly autonomous systems. The concept of a 'shadow workforce' of non-human identities raises ethical concerns about accountability and transparency in automated decision-making. As AI agents gain more autonomy, the line between insider risk and external compromise blurs, necessitating a re-evaluation of traditional security paradigms. The struggle to maintain operational safety in an autonomous landscape could lead to a broader societal debate about the appropriate level of autonomy for AI and the necessary human safeguards. This situation underscores the critical need for a holistic approach to AI governance that encompasses not only technical security but also ethical considerations, regulatory compliance, and a clear understanding of human-AI collaboration to ensure responsible and beneficial AI deployment.











