AI Agents Behave More Like Employees Than Applications

Security teams spent decades controlling what software does; Agentic AI is forcing them to control what it decides to do next — and that starts with knowing it's there at all. 

The other day, a friend and former coworker told me she needed to build a drip email campaign targeting their company’s entry-level customer base after her team identified a cross-sell opportunity. She needed to identify which customers were likely fits for the related product, pull the matching accounts from Salesforce, organize them in a dynamic spreadsheet, draft a cross-sell email for each one, and log it all back into Salesforce so the reps could review, send, and follow up—and then make the whole thing repeatable for the next campaign. 

So, she used her personal Claude Pro account to build an agent that would automate these processes into a multistep workflow. And she did so by describing what she wanted in plain English.  


Agentic AI Poses a New Threat 

The most obvious security issue is the shadow AI one: under pressure to get this up and running, she built her agent outside her organization’s approved AI tools and fed it confidential customer data.

And I can’t blame her. She had a deadline and leveraged a tool that worked.

But even if she had built a comparable agent using ChatGPT Enterprise, security practitioners face a problem that goes beyond which application built the agent: How do you control what the agent decides to do? Unlike a traditional application, an AI agent can get to its goal more than one way. If direct export of the customer data is blocked, the agent keeps trying—a shared drive, an API call—until it finds a way.

And who approved this agent? No one. No interview, no access review, no manager. Worse, there’s a good chance you won’t even know it exists.

That last claim isn’t me being dramatic. In a survey the Cloud Security Alliance published last spring titled Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises, 82% of organizations said they’d discovered AI agents running in their environments that IT or security teams didn’t know existed.

 

AI agents—they’re just like us! And that’s the security problem. 

Traditional applications, no matter how complex, execute a fixed sequence. If a given step fails, the application breaks down. To get it working again, you need a capable, intentional actor—a human being, if you will.

But AI agents work more like the proverbial intern eager to prove their value, exhausting all avenues if necessary to achieve an objective. If the task is drafting a first-pass summary of last week’s support tickets, this persistence is harmless for the most part. But once the task involves downloading a file, executing a script, or installing something the agent decides it needs to finish the job, that same persistence is exactly what burns you.

 

More troubling: you usually can’t see how an agent gets from point A to point B (and beyond). Without that visibility, you can’t easily determine whether it’s broken a security protocol along the way. That’s what makes an agent more like an employee than an application: it makes judgment calls. Except this employee skipped the interview, the background check, and the security training.

An unmonitored agent puts your organization at risk twice over.

  1. There’s the insider-style risk: an agent with legitimate access doing things no one authorized, like our cross-sell agent hunting for a workaround to a blocked export. Then there’s the external one: attackers now target AI tools and agents directly, and a compromised agent inherits every blind spot you’ve left around it.

  2. That second risk runs on a clock. CrowdStrike's 2026 Global Threat Report puts the average eCrime breakout time—the time from initial access to lateral movement—at 29 minutes. The fastest breakout on record clocked in at 27 seconds. In one documented intrusion, data exfiltration began within four minutes of initial access.

29 Mins
Average eCrime Breakout Time
27 Secs
Fastest Breakout Time Recorded
4 Mins
Until Data Exfiltration Can Begin

 

You can’t respond in 29 minutes—let alone 27 seconds—to activity you can’t see. And agent activity is exactly what most organizations can’t see.

The Workforce Nobody Hired (but Attackers Love) 

Attackers have noticed. The CrowdStrike report shows that AI-enabled adversary activity rose 89% year over year in 2025. Attackers are using AI across the whole lifecycle—recon, credential theft, evasion—while hiding behind legitimate identities and SaaS platforms. The result: intrusions that move faster, look more like routine activity, and leave defenders with less time to respond.

AI itself has become a target, too. At more than 90 organizations, attackers manipulated legitimate generative AI tools with malicious prompts that produced working commands for credential and cryptocurrency theft. They exploited weaknesses in AI development platforms to maintain access and deploy ransomware. They stood up malicious AI servers masquerading as trusted services to intercept sensitive data. Prompts, models, plugins, agent infrastructure—all of it can be turned against you.

Which brings us back to my friend’s cross-sell agent. Shadow agents emerge inside the same automation, scripting, LLM, and custom-assistant environments your teams already use to get work done, so their activity looks legitimate even when an agent is unauthorized, compromised, or acting beyond its intended scope. From the outside, an agent doing its job and an agent doing an attacker’s job can look remarkably alike.

So, treat your agents like the employees they resemble. You’d never let a new hire touch customer data before anyone checked their references, scoped their system access, or at minimum learned their name. Agents deserve the same scrutiny: know which ones are running, what tools and data they can reach, what actions they’re taking, and whether those actions comply with policy. You can’t govern a workforce you haven’t met.

 

Preparing for a Secure Future with Agentic AI

AI agents are becoming part of the enterprise workforce, whether security teams approve them or not. The first step toward governing them is knowing they're there. Watch our on-demand webinar Redefining Application Control for a Post AI World, featuring Paddy Harrington, Senior Analyst, Security and Risk at Forrester to learn more.