- What: Discussion on security questions for agentic AI
- Impact: Focus on securing AI systems
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Application Security 2-Click Cursor Exploit Enables Dev Environment Takeover 2-Click Cursor Exploit Enables Dev Environment Takeover by Nate Nelson Jul 15, 2026 6 Min Read Vulnerabilities & Threats Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes by Jai Vijayan Jul 14, 2026 5 Min Read World Related Topics DR Global Asia Pacific Europe Latin America Middle East & Africa See All The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cybersecurity Operations Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Agentic AI Is Untamable: Ask the Right Security Questions Forget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe. Arielle Waldman , Features Writer , Dark Reading July 16, 2026 4 Min Read Source: Image Flow via Shuttershock Agentic security challenges stem from a mindset, not the technology so solving them requires a fundamental shift in how organizations think about control. While agentic systems can save organizations time across several operations, from cybersecurity and software development to customer support, agents also introduce significant risks to the organization. These systems require alarmingly high levels of access to sensitive information, as well as the use of external tools, to complete tasks with little to no human oversight. They constitute yet another attack surface for threat actors to target. Organizations can deploy access and other technical controls to monitor agent behaviors, but overall, agentic security remains thorny. Agentic security is not hard because it's new — it's hard because it violates the assumptions on which security models were built 40 years ago, when the industry emerged, says Ben Hanson, global field CTO and director of field engineering at Zenity. Security depends on predictability to identify threats and determine how to respond based on past threat intelligence. And agents are, by virtue of their ability to adapt to the situation and make decisions on the fly, unpredictable. Related: Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook? Meeting the challenge requires recognizing that the solution is a combination of technology, processes, and people. Cybersecurity has never been about just focusing on technology, and the same principle applies to agentic systems, Hanson says. The human factors shaping the technology environment are also important. "They [customers] were confused by that because the understanding in cyber is that if you have all the right widgets that you'll be able to be effective and that's simply not true," Hanson tells Dark Reading. You Can't Predict What Is Unpredictable Organizations often think that if they address the problem in technical chunks, they can fix it end-to-end, and that's just not true , he warns. That's a common struggle he's observed across Zenity customers and is the basis of his Black Hat USA presentation next month in Las Vegas. The industry relies on predictability to quell threats. Threat intelligence tracks and documents tactics, techniques, and procedures. Researchers highlight attack indicators of compromise for organizations' radars. Security teams rely on expected behaviors and system baselines to detect suspicious activity and trigger alerts. Artificial intelligence (AI) is changing that, and conversations around agentic security need to reflect the shift. Related: 'Yellow Teams' Are Defining the Future of AI Security "What happens when you can't predict what you're trying to align a control to?" Hanson asks. "What happens when you do get the failure mode right, but the agent adapts, and now it's outside what you expected it to do?" The idea of agency is important to focus on because of the inherent way agents and AI broadly work — users cannot always predict how they will behave, he stresses. And the security industry's myopic approach to agency is "dangerous" because the underlying assumptions are incorrect and can lead to unexpected results, Hanson says. Instead, security practitioners should focus on eight broader concepts: trust, context, intent, behavior, authority, control, boundaries, and risks. These are more realistic ways to address unpredictability. When security teams don't consider all of these factors in their planning, that's when agents can go rogue. Keep the Questions Flowing The PocketOS incident, in which a Cursor coding agent deleted the company's entire production database, including coveted backups, is a good example. The error exemplified the difference between can versus should , which is something organizations should consider when it comes to how agents operate. Hanson attributes the incident to the control being contingent on the authority. Related: Jen Ellis: Connecting Cyber Community With Political Machinery "Because the control was contingent on authority, when the agent found something, a token in this case, it could use to do a database deletion; there were no other controls that could get in the way," he explains. "Those are separate dimensions of agency and must be managed separately." Organizations cannot just go and swipe their credit cards to solve agentic security. Instead, Hanson urges them to build systems structurally capable of governing agency, not just trying to align with known bad behaviors, because that list is growing increasingly erratic. Organizations are also trying to apply the principle of least agency without defining what is required to govern it. Igniting more conversations, debates, and even arguments around agentic security is actually a good starting point. Organizations can build agentic programs around widgets, but that must be followed up with questions to disrupt the lack of systemic thinking across the industry, generally, urges Hanson. Some questions to consider include: How are organizations thinking about enforcing trust end-to-end as a system property? How are they thinking about consistent mechanisms of control? Questions like this are important because organizations often ask the wrong ones. Rather than asking what control failed, he recommends asking what about the structure of this system allowed the behavior to occur, and then go fix that. Structural conditions are the cause; control failures are consequences, he adds. Tooling teams are in silos and have different ways of approaching the problem, which means conversations are even more essential. "There are a lot of technical controls, but how do we ensure the agent is pursuing the right goals?" Hanson asks. "Enforce it across the entire architecture, not only at one point in time. Even just taking a step back and asking that question is something people are not doing." Black Hat USA Aug 1, 2026 TO Aug 6, 2026 | Mandalay Bay Convention Center, Las Vegas, USA The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered, six‑day program built to ignite innovation, push boundaries, and bring the global security community together like never before. This year’s event features four days of immersive, expert‑led Trainings (August 1–4), followed by Summit Day on Tuesday, August 4, and a two‑day main conference packed with groundbreaking Briefings, open‑source tool demos in Arsenal, a dynamic Business Hall, and unlimited learning & networking opportunities. Use code: DARKREADING to save $200 on a Briefings pass or $100 on a Business pass. GET YOUR PASS GET YOUR PASS Read more about: Black Hat News About the Author Arielle Waldman Features Writer, Dark Reading Arielle spent the last decade working as a reporter, transitioning from human interest stories to covering all things cybersecurity related in 2020. Now, as a features writer for Dark Reading, she delves into the security problems enterprises face daily, providing context and actionable steps. She looks for stories that go past the initial news to understand where the industry is going. Her coverage areas include identity and access management, cyber risk and operations, industrial control systems, operational technology, and ransomware trends. She previously lived in Florida where she wrote for the Tampa Bay Times before returning to Boston where her cybersecurity career took off at TechTarget SearchSecurity. When she's not writing about cybersecurity, she pursues personal projects that include a mystery novel and poetry collection. See more from Arielle Waldman Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars When AI Becomes an Insider: Rethinking Risk in Critical Infrastruc