Home Technology Security Autonomous agents are a new class of security principal

Autonomous agents are a new class of security principal

- Advertisement -

Every major technology shift forces enterprises to revisit long-standing assumptions about governance. Cloud computing changed where applications run; mobile changed where work happens; today, AI is changing how decisions are made and executed inside core enterprise networks.

The recent cybersecurity incident involving OpenAI and Hugging Face illustrates this paradigm shift. While detected early with limited operational impact, its broader significance extends beyond a single event. As AI models become increasingly capable of reasoning, adapting, and discovering novel execution paths, traditional assumptions around containment are becoming harder to rely upon. Even hardened software infrastructure should no longer be regarded as an absolute security boundary.

This is not a reason to slow AI adoption. Autonomous agents can streamline complex workflows and accelerate business outcomes. Rather, it highlights the need for governance to evolve alongside capability.

- Advertisement -

In cybersecurity, a security principal is any entity authenticated, granted permissions, and held accountable within a system. Historically, security principals have included employees, service accounts, applications, and machine identities. Autonomous agents increasingly meet this definition because they are given credentials and permissions to execute multi-step business processes across enterprise systems.

The question is no longer whether organisations will deploy autonomous agents, but how existing governance models must adapt to manage them responsibly. Three areas deserve immediate executive focus.

Identity controls must account for agents as active enterprise actors

Identity remains the foundation of trust. Establishing verifiable identities for autonomous agents, supported by distinct credentials, lifecycle governance, and scoped permissions, is an essential starting point for enterprise deployments.

However, recent events demonstrate that identity alone is insufficient assurance. An authenticated agent is not necessarily a trustworthy one throughout its entire execution. Conventional software follows predefined, predictable workflows. Autonomous agents dynamically generate subtasks, invoke operational tools, and adapt their approach as conditions change. As capabilities grow, an agent may move laterally across connected environments, exploit software flaws, or acquire credentials beyond its assigned scope.

Authentication establishes initial access, but maintaining trust requires continuous validation that an agent’s behaviour remains aligned with its intended business objective. Enterprise leaders must view identity as the beginning of trust, rather than its endpoint.

An agent’s risk is determined by everything it can reach

The OpenAI and Hugging Face event highlights why organisations must fundamentally reconsider how they calculate operational risk. The evaluated agent was not expected to have unrestricted internet access, yet it identified a path beyond its isolated environment. While contained quickly, the breach illustrates a principle: An autonomous agent’s effective blast radius is determined not only by the permissions it has been granted, but also by every service, dataset, API, and connected system it can ultimately reach.

This marks an important shift in enterprise risk management. Traditional access reviews focus primarily on assigned permissions. Autonomous agents require organisations to evaluate reachable systems as well, including those accessible through lateral movement, compromised credentials, proxy services, or unintended pathways.

Emerging attack vectors further compound this challenge. Techniques like indirect prompt injection show that untrusted instructions hidden in emails, documents, or third-party web content can manipulate how an agent prioritises actions. When agents cross application boundaries, trusted business workflows can inadvertently become vectors for broader compromise.

This is why regulators and cybersecurity agencies, including the Cyber Security Agency of Singapore, are emphasising end-to-end visibility across interconnected cloud environments and supply chains. Controlled sandboxes remain valuable for identifying early failure modes, but they cannot fully mirror live, evolving enterprise systems. Assessing an agent’s true risk requires mapping everything it can reach, not simply what it was designed to access.

Trust depends on whether agent decisions can be reconstructed and challenged

The incident also underscores the distinction between auditing and active monitoring. Auditing remains essential for post-hoc accountability. It enables organisations to reconstruct events, inspect prompts, verify tool selections, and evaluate data lineage to satisfy compliance inquiries and explain outcomes after the fact.

Active monitoring serves a different purpose: continuously evaluating whether an agent’s actions remain aligned with assigned objectives while execution is happening. When agents operate continuously at machine speed, waiting to analyse logs after an event occurs is insufficient to prevent unintended outcomes.

Crucially, monitoring engines must operate on systems that are physically and logically distinct from the agent’s execution environment. Out-of-band separation ensures oversight remains reliable even if an agent behaves unexpectedly or becomes compromised. Equally important, organisations must establish dedicated incident response procedures for autonomous software, including automated mechanisms to isolate or suspend agent activity in real time.

Balancing risk and reward in the agentic era

This recent incident should not be viewed as a cautionary tale against deploying AI, but rather as an early preview of how enterprise governance must mature. Enterprise security has repeatedly adapted to changes in computing. The internet expanded security beyond corporate perimeters; cloud computing introduced machine identities and software-defined infrastructure. Autonomous agents represent the next phase, combining delegated authority with advanced reasoning.

Organisations should continue evaluating both the opportunities and risks of deploying highly capable models, particularly in research or evaluation environments where safety guardrails may be relaxed. The objective is not to eliminate risk, but to ensure governance, visibility, and operational controls keep pace with autonomous capabilities.

Existing security principles remain sound, but the environments they govern are becoming far more dynamic. Adapting governance models today will allow organisations to use agentic AI while maintaining the resilience, accountability, and trust that modern enterprises require.

- Advertisement -