A significant gap exists between security leaders' confidence in AI management and their actual ability to respond quickly to rogue AI incidents.

A majority of IT and security leaders express high confidence in their ability to identify rogue AI agents, yet there's a concerning disconnect when it comes to timely responses. While a survey by WanAware reveals that 90% believe in their detection capabilities, only 26% can trace the downstream impact of incidents within minutes. Over 45% report that fully understanding the effects of an AI agent malfunction could take hours, a delay that poses substantial risks.
Jeffrey Collins, CEO of WanAware, highlights that this lag in action can result in major operational disruptions or data breaches. "The critical issue isn't whether you notice a problem; it's how quickly you can respond to it," Collins advises. With malfunctioning agents capable of causing damage almost instantaneously, this delay in detection and mitigation is alarming.
Speed of Response is Key
Kevin Paige, field CISO at C1, reinforces the importance of speed, remarking that AI agents operate at machine speed. "The time it takes to catch an agent malfunction isn’t measured in minutes but in actions," he explains. Once a problem begins, especially when agents operate with borrowed credentials, it can quickly escalate before an organization even realizes there’s an issue.
In many scenarios, organizations discover AI malfunctions not through their own monitoring tools but rather through external feedback from customers or failures in downstream systems. "The worst way to learn about a malfunction is second-hand," Paige says, noting that such incidents erode trust and can halt the adoption of AI technologies. The failure to rapidly contain a malfunction can have long-term implications for organizational trust in AI systems.
Visibility vs. Control
While many organizations boast visibility of their AI systems, the reality is that true control is often lacking. Paige points out that when an agent operates out of its designated scope, the deviations are typically subtle and might not trigger alerts within conventional access models. "Often, it uses legitimate access in ways that weren't approved, leading organizations to discover issues only after the fact," he states.
Chris Camacho, COO of Abstract Security, stresses the necessity of having tailored identities and permissions for each AI agent. "Every agent should have distinctly scoped permissions and a comprehensive audit trail," he emphasizes. Alongside these measures, organizations must have systems in place to disable rogue agents swiftly without manual intervention across multiple platforms.
Camacho also notes that the complexity of AI activities, which span various identities and tools, complicates detection and response efforts. Many organizations know where their AI agents are deployed, yet understanding the actions they take during unexpected events is a different challenge altogether.
Questioning Overconfidence
The results of the WanAware survey exhibit a stark contrast between perceived capabilities and actual readiness. Joe Brinkley, director of offensive security research at Cobalt, interprets the high confidence in problem detection as more reflective of compliance requirements than organizational effectiveness. “The reality is that tracing the impact of an agent malfunction quickly is a brutal process,” he says. Traditional logging systems often fail to capture the entire execution context, leading to significant gaps when incidents occur.
By the time an alert is issued, the rogue agent may have already executed multiple downstream actions, complicating the recovery process. Brinkley also points out vulnerabilities related to data flows, which can lead to unexpected behavior when untrusted inputs compromise the agent's function.
Brinkley highlights the necessity for security measures that go beyond simple monitoring. "Implementing 'hard kill' switches at the API layer is essential. It’s not enough to apply soft controls," he insists. The immediate revocation of access tokens, similar to dealing with a compromised user account, is vital in these scenarios.
Overall, organizations that excel in AI management will be those capable of providing detailed accounts of their agents' actions and ensuring they operate within defined policies. Rapid identification and cessation of any deviation from these policies will be key to maintaining control and fostering trust in AI systems.
Discussion
Sign in to join the discussion.