Enterprises Unprepared for Malicious AI Agents

Enterprises Unprepared for Malicious AI Agents

Enterprises are rapidly deploying AI agents into core operations — but their security and identity systems are not ready, warned Nikesh Arora, CEO of Palo Alto Networks, in a recent media briefing. Arora cautioned that the growing use of autonomous AI agents capable of making system-level decisions is expanding corporate attack surfaces and outpacing existing identity and access management (IAM) frameworks. 

Unlike traditional AI tools, agentic AI systems can access databases, applications, and privileged resources to execute complex tasks, often interacting across multiple platforms via protocols like the Model Context Protocol (MCP). However, Arora said most organizations “don’t have visibility into what credentials agents have,” creating conditions akin to a “Wild West” of unsecured automation. 

Key concerns highlighted include: 

  • Broken identity management: Current systems track privileged human users but fail to monitor AI agents, leaving up to 90% of access points unverified. 
  • Expanding threat surface: AI agents act as both users and privileged entities, increasing opportunities for data exfiltration and credential-based attacks. 
  • Rising cyber risks: Palo Alto’s research identified over 194,000 domains used in smishing attacks, signaling a surge in automated credential theft. 

To address these risks, Palo Alto is integrating capabilities from its CyberArk acquisition to build a unified identity management platform across human and non-human users. Arora also announced Cortex AgentiX, a new automation-driven cybersecurity solution that uses AI agents trained on 1.2 billion threat playbooks to detect and respond to attacks in real time. 

While emphasizing that “humans must stay in the loop,” Arora predicts enterprises will increasingly rely on AI-driven security automation — a move he describes as essential as agentic AI becomes deeply embedded in corporate infrastructure. 

 

Source: 

https://www.zdnet.com/article/enterprises-are-not-prepared-for-a-world-of-malicious-ai-agents/  

Get Started

Ready to Build Your Next Product?

Start with a 30-min discovery call. We'll map your technical landscape and recommend an engineering approach.

000 +

Engineers

Full-stack, AI/ML, and domain specialists

00 %

Client Retention

Multi-year partnerships with global enterprises

0 -wk

Avg Ramp

Full team deployed and productive