Agentic AI Security: What Can an Agent Execute Once It’s Running?

Application control may stop unapproved software from running at the endpoint, but agentic agents need guidance to stop repeating actions or try other ones. This is where the concept of Agentic Steering comes in. It helps to keep agentic agents within the parameters of your organization’s security policies. 

Application Control Is Just the Start for Agentic Agents  

Effective application control gives you a huge advantage in controlling Agentic AI. As Daniel Schell explains in his April blog post and demo, application control blocks unapproved executions at the endpoint even when an agentic agent is attempting the unapproved execution using a tool that your company allows.

Weirdly, the way in which application control works reminds me of Neo stopping bullets in The Matrix. It doesn’t matter who is shooting them or why. He knows the system so well that he just raises his hands and brings them to a stop before they can attack his endpoints (his meatbag, if you will). But your organization isn’t The Matrix, and the agentic agents in your environment are being created by humans to perform tasks that they need done—particularly ones that are repetitive, tedious, or prone to human error. The agent I build to update a spreadsheet isn’t designed to perform anything nefarious (as far as I know).

Agentic AI has the added benefit of not requiring you to be a programmer to set up complex workflows because you don’t have to consider every contingency for where it might fail, the way you would with a traditional application. But that same ability to take instructions in plain English and run with them does change what your security team needs to control once an agentic agent is running.

 


When an Agentic Agent Isn’t Like One of Your Employees 

You can’t do better than having a Neo at your endpoints because application control solves many of the immediate risks posed by agentic agents by stopping unapproved, often risky executions. With traditional applications, you decide whether they are trusted to run—and if they’re not, they don’t get past Neo. End of story.

Agentic agents complicate that model because allowing the agent to run is only the first execution decision. Once it is running, you also have to decide whether the commands and actions it initiates should be allowed to execute—even when the underlying tools themselves are approved. For example, your organization may approve PowerShell because administrators, developers, and automated workflows legitimately need it. At the same time, your agent shouldn’t have the ability to run any command on PowerShell. They need to comply with limits akin to what your human employees and related apps must follow, such as role-based access control (RBAC) and principles of least privilege.

In other words, when I build an agentic agent to update a series of spreadsheets every evening, it may need to use PowerShell to complete the task (I say this as if I have any idea how my agent does what it does). That doesn’t mean it should be able to attempt scripts that go against your security policies or are limited to high-level security employees.

Unlike their meatbag counterparts, however, agentic agents haven’t been designed to pause, let alone consider, what may be causing a blocked execution. Nor do they act like a traditional application, following the logic its developers defined in advance. Instead, an agent tries different commands, other tools, or even other agents to reach its objective.

In addition to being an obvious security risk, this endless trial and error has a financial cost. You don’t want your growing population of agents burning through time, tokens, and compute without moving your work forward. Therefore, you need to set things up to guide agents to, well, act a little more human. And that means steering the agent to act right when it gets no for an answer.

 

Steering Agentic Agents to the Right Outcomes  

If you remember The Matrix, Neo didn’t always know how to stop bullets (or how to do kung fu, for that matter). He had Morpheus as a guide. Similarly, agentic agents need parameters on what to do when they encounter a block. Think of Agentic Steering as a sort of Morpheus that helps get the agents to perform the proper actions to complete their tasks. Instead of leaving the agent to interpret a denied action as another problem to work around, Agentic AI steering communicates the policy decision back to the agent along with context it can use to proceed within your organization’s permitted boundaries.

While the choice isn’t as stark as red pill versus blue pill, Agentic Steering gives the agent approved ways to handle a task that it can use instead of the unapproved actions that application control keeps stopping. In many cases, it may be telling the agent an approved alternative path to take. In others, it may instruct the agent to pause for human authorization or to stop altogether.

And what’s kind of cool is that Agentic Steering gives you and your security teams the power to be Morpheus in your own network. You get to set the boundaries based on your security and access policies, and steering gives you the power to enforce them, so that your agentic agents no longer put your organization at risk!

 

Hard Boundaries Work Better When Agents Know How to Respond to Them 

The need to steer an agent after a denied action doesn’t diminish the value of application control. Neo still stops the bullet: if an unapproved execution reaches the endpoint and application control blocks it, the control has done exactly what it is supposed to do. What makes agentic AI particularly dangerous is what the agent might do after that block. Because the agent is still pursuing an objective, it needs more information than a denied action to know whether to take an approved route, wait for authorization, or stop.

That’s why application control and Agentic Steering solve different parts of the same problem. Application control decides what can run and enforces that decision before execution. Agentic Steering helps the agent respond without weakening that boundary, so it can continue only in ways the organization permits. As autonomous agents take on more complex work, security needs both: hard limits on execution and a safe way for agents to operate when they encounter them.

 

 

Next Steps

Your agents have work to do, and repeated attempts at blocked actions aren’t getting it done. See how Airlock Digital Agentic Steering works to explore how your team can define permitted commands and provide policy context or approved alternatives when an action is denied, helping agents proceed within the boundaries you set.