Two major AI pain points for today’s security leaders are adjusting to new requirements for cyber hygiene, and preventing unintended consequences from over-privileged agents.
Team8 is a venture capital and private equity firm that invests in companies specializing in enterprise technologies, cyber, AI, fintech and digital health. To be successful, VC needs to thoroughly understand current technology and associated problem areas to select the right solution-delivering firms in which to invest.
To help its own understanding, Team8 has developed a ‘CISO Village’ – an invitation-only global community of security leaders from the world’s major enterprises. Each year, Team8 produces an annual survey report based on the latest opinions from this CISO Village. This year it tackled the era of AI, and the result confirms it is now AI software that is eating the world.
- Seventy-one percent of CISOs are experimenting with or augmenting existing security tools using AI agent capabilities.
- The risk surface is expanding faster than the control layer.
- CISOs are mobilizing before they feel fully ready, investing in platforms, skills, and new control mechanisms.
- AI and agent security is by far the biggest pain point (78%), exactly twice that of the second pain point (39%)
SecurityWeek talked to Team8’s CISO, Tim Brown, about why agent security is such a problem.
“When we look at AI, there are two aspects we need to consider. The first is our own attack surface as targeted by adversaries using AI,” said Brown. “What has been considered good security hygiene for the last 10 to 20 years is no longer adequate. We used to believe use of MFA and firewalls and good endpoint protection would prevent us becoming the victim of an opportunistic attack. Not anymore. The attacks and our attack surface have changed.”
CISOs’ first pain point is the struggle to change the corporate viewpoint of security hygiene to the new reality of AI.
The second pain point, he continued, is finding the right balance between AI-driven business enablement and new threats introduced by the use of agentic AI. If we get the balance wrong, we end up with unintended consequences.
“We’re using AI agents for many different purposes, from simple to complex, and they’re being created by our own employees through easily available coding tools like Claude Code, Cursor and Codex. The agent could be simple, like ‘I want to have my email summarized every day and be told if I need to get back on anything’. Or it could be more complex: ‘I’m going to rework my sales process. I’m going to be using enterprise data to generate recommendations on how I should focus my people working on sales’.”
The more complex the agent, the more critical parts of the network it touches. This brings in the human failing of poor textual exactitude. People generally fail to say in words exactly what they want to happen. The agent will attempt to do precisely what it understands to be its instruction, which may not necessarily be what you want.
Consider your own experiences using a standard chatbot. You ask a question and get a reply, which is sometimes clearly and obviously balderdash. Recognizing the reply as balderdash, you can refer back to your input question and see that your own lack of explicit textual precision caused the chatbot’s response. AI attempts to do exactly what it believes it is instructed to do, but with the added non-deterministic probability inherent in all AI models. These same tendencies occur in the development of an AI agent, except that the author never sees anything he can recognize as balderdash.
“An AI agent is not just another employee – it’s a very resourceful employee that will do whatever it takes to accomplish the task it believes it has been given.” He gave an example. “If you have an agent designed to get background information on Tim Brown Systems from whatever it can find, whether public or private information, it could go anywhere and search anything – it could poke around in a production system anywhere on the internet as opposed to a test system.”
So, that’s the second issue with agents: unintended consequences. The problem for security leaders is to create the right level of guardrails around the agents to prevent harmful consequences without destroying the business purpose. “It’s easy to create 100% successful guardrails,” he added. “I take the system, I unplug it, I throw it into the ocean. Then it’s safe. Useless, but safe.” Finding the right balance between utility and security is the difficulty.
These guardrails should be built into the agent development process, limiting where any agent can go and what it can do. Then, if it interprets its purpose in a way that is harmful, it cannot do it.
Brown has one specific recommendation to help security leaders navigate these new problems from AI: increased transparency and experience sharing with other security leaders who have suffered, and perhaps already solved, the same issues.
“Let’s share more often. Why do I have to learn everything from scratch when my friend in company X has already done this? We should come together as defenders. With increased transparency and sharing, we’ll produce better AI, make it harder for our adversaries to do what they do, and enable our business to succeed without those harmful unintended agentic consequences.”
Related: Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
Related: OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
Related: ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
Related: Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
