Laura I. Harder: How to Prepare Boards for the Security Risks of Agentic AI
Agentic artificial intelligence (AI) is set to significantly impact organizational operations. Unlike previous AI tools that were primarily designed for summarizing documents or generating content, these systems function autonomously, executing tasks and…
Agentic artificial intelligence (AI) is set to significantly impact organizational operations. Unlike previous AI tools that were primarily designed for summarizing documents or generating content, these systems function autonomously, executing tasks and interacting with enterprise systems. This evolution presents new categories of security concerns for governing boards overseeing technology risks. According to Laura I. Harder, Vice President of the Information Systems Security Association (ISSA) International, these risks can emerge rapidly due to the high level of autonomy granted to AI agents. Effective governance structures are necessary to manage systems capable of making decisions and taking actions independently.
Agentic AI Changes the Security Equation
Historically, corporate AI deployments have focused on tools analyzing information or generating outputs, which introduced privacy and data integrity concerns. However, Agentic AI changes this dynamic by enabling agents to trigger workflows, access databases, and interact with various software systems within an organization. This autonomy introduces new security challenges, as these systems can be manipulated through techniques such as prompt injection, similar to social engineering tactics. The opaque nature of many AI models further complicates security, as organizations often utilize third-party tools without full transparency into their decision-making processes.
When evaluating agentic AI, a critical vulnerability often underestimated is permissions. AI agents operate within a network of systems, data sources, and applications, and the level of access granted determines potential damage if issues arise. For instance, AI systems connected to internal collaboration tools or document repositories can access sensitive information within shared folders, acting on data that may not be actively monitored. Additionally, third-party AI services can pose risks if proprietary information, intellectual property, or sensitive customer data is used inappropriately during AI interactions.
Building Governance That Can Keep Up With AI
AI governance should be integrated as a structured program rather than an additional technology layer. Organizations are advised to establish a dedicated AI governance board, modeled after existing privacy or risk governance committees. Adoption of established frameworks, such as the NIST AI Risk Management Framework or ISO 42001, is recommended. These frameworks provide guidance on policies, risk assessments, and operational controls, enabling organizations to define AI functionality and data access within their environments. An emerging practice is creating an "AI bill of materials" to inventory AI tools, their system connections, and accessible data.
Agentic artificial intelligence (AI) is set to significantly impact organizational operations.
Guardrails That Prevent AI From Going Rogue
Effective governance of agentic systems requires technical safeguards that limit operational scope. Security controls should be integrated during the initial design phase, with systems developed in controlled sandbox environments utilizing test data and limited privileges. Red teaming exercises, where security professionals attempt to exploit vulnerabilities, are essential for identifying weaknesses before deployment. Isolation techniques, such as containing agents within virtual machines, further mitigate risks by restricting command execution and system access.
For governing boards, agentic AI presents a challenge in governance and accountability. Organizations are responsible for their AI systems' actions, necessitating due diligence and oversight. Legal and fiduciary implications require boards to ensure autonomous technologies are implemented with clear oversight, constrained authority, and continuous monitoring. Successful organizations will prioritize governance and security as foundational requirements in the integration of agentic AI into core operations.
For further insights, follow Laura I. Harder on LinkedIn .
Based on reporting by TechBullion.
