01

The attack surface is changing

AI agents can retrieve sensitive information, use business tools, call APIs and execute actions with limited human involvement. Attackers are also using AI to accelerate phishing, credential abuse, vulnerability discovery and exploitation.

The security question is therefore wider than model safety. It includes every identity, permission, tool, data path and action that allows the agent to affect the organisation.

02

Six priorities for security leaders

  • Govern human, service and AI-agent identities through one coherent identity-security model.
  • Make identity context central to modern cyber defence.
  • Move SOC teams from alert queues towards contextual, AI-assisted investigations.
  • Identify and prioritise exploitable vulnerabilities at machine speed.
  • Apply least privilege, auditability and human approval to autonomous actions.
  • Turn AI governance into an operational capability rather than a policy document.

03

The right human and AI relationship

The future is not a contest between people and AI. It is skilled security professionals using governed AI to investigate faster, prioritise accurately and respond before an incident becomes a crisis.

The agent should accelerate evidence collection and recommendations. Accountable professionals should retain control of high-impact actions and security decisions.

04

Build governance into the architecture

I help organisations connect SOC transformation, identity protection, detection engineering, vulnerability remediation and Agentic AI security into one governed operating model. The objective is useful automation with explicit boundaries and evidence at every consequential step.

References

Primary sources