By Todd Thorsen
AI agents are coming for your business.
Industry predictions claim the number of tasks executed by agents will grow at a CAGR of 524 percent to reach 415 trillion by 2030. In manufacturing, the technology could transform business processes from planning to production. But organizations must look before they leap.
AI agents can reduce costs, improve operational efficiency, enhance product quality and design, and much more. But they also introduce new risks. Machine-speed, autonomous workers are a game-changing prospect. But without the right governance and guardrails in place, projects could generate more risk than value.
AI has already come a long way from the “prompt-and-response” models we’ve seen evolving over recent years. Now the leash is off for LLM-powered agents to work independently on tasks as diverse as software development, customer support, security investigations, and financial analysis.
This should make CISOs nervous. Agents are often over-permissioned.
Widen Blast Radius
This can widen the blast radius of incidents stemming from rogue agents and malicious third parties. They might have access to highly sensitive corporate and customer information. And they may carry out high-risk business processes. According to one study, 93 percent of global organizations are already using or planning to use agents for security-related helpdesk tickets.
Indirect prompt injection (IPI) is an acute concern. Agents often roam across domains interacting with a range of corporate assets and external resources. This provides ample opportunity for adversaries to hide malicious instructions in anything from emails to web pages.
Another study revealed 10 in-the-wild IPI payloads designed to commit financial fraud, data destruction, API key theft, and more.
Because of their speed and autonomy, even nominally safe agents can go rogue before IT teams even realize what’s happening.
To that end, in April, the founder of developer PocketOS claimed a Claude-powered version of AI coding tool Cursor deleted the firm’s production database in just seconds. A couple of months prior, Meta AI safety researcher Summer Yue ended up forced to step in after an OpenClaw instance “lost” her original instructions and tried to delete her entire inbox.
Shadow AI compounds these risks. IBM estimates 20 percent of global organizations suffered a data breach last year due to security incidents involving unmanaged AI tools, adding $675,000 to average breach costs. Separate research reveals 82 percent of organizations believe they have unmanaged agents running in their environment. If IT teams can’t see what’s there, they can’t securely manage it.
Positives for Agents
Agents are quick and easy to adopt and deploy. Business users love the potential to enhance productivity, efficiency and customer-facing innovation. But agents are often spun up only for short periods, making it difficult for traditional scanning tools to track them. The way they chain tasks across distributed workflows adds further challenges for many monitoring systems. And their adaptive, probabilistic nature means it is difficult to predict future behavior.
The result is not just greater exposure to security and reputational risk. Demonstrating visibility and control of all IT assets is critical for regulators of GDPR, HIPAA, and other frameworks. AI agents risk creating significant compliance gaps for CISOs and their teams.
This is why security teams must be a part of agentic AI projects from the very start. At CrashPlan, we’ve be in the process of rolling out agentic AI tooling, and have spent the past considerable time up-front on configurations, building in the appropriate controls and stop gaps.
The technology may be new but the security principles underpinning best practices remain the same. It’s about managing access controls and permissions along zero trust lines. Gaining visibility into usage and putting controls in place to eliminate data leakage. Mitigating poisoning and prompt injection risk. And putting strong governance in place to reduce the risk of destructive autonomous actions. Human in the loop principles are vital.
The final piece of the puzzle is auditability. When incidents do happen, we need to be able to reconstruct, address any issues and learn from what happened.
Widen Blast Radius
There’s a role here for best practice standards. ISO 4200, for example provides a structured, risk-based framework for the governance and management of AI systems throughout their lifecycle. Governance will play an important part in helping organizations meet the diverse regulatory requirements they face as well.
For organizations beginning their agentic AI journey, observability must end up treated as a foundational security and governance capability. Security teams need visibility not only into what agents are doing, but what the decisions are, what data ends up accessed, where the data is flowing, and what are the protections?
As AI agents move from assisting users to taking autonomous actions, the ability to monitor, audit, and explain agent behavior becomes critical for managing risk, maintaining trust and meeting compliance obligations. Expect demand for AI observability, governance, and control platforms to accelerate rapidly as enterprises increasingly leverage agents to enhance productivity, innovation and competitive advantage.
The good news is a new wave of innovative tech startups are already helping customers illuminate agentic AI security blind spots. This is good news for CISOs and security teams, as our environments are becoming increasingly complex.
Todd Thorsen brings more than 15 years of information security experience across various disciplines and a proven track record of building and leading security programs to CrashPlan as its Chief Information Security Officer. He leads all security aspects, including global security operations, risk and compliance, incident response, resilience, and data protection.

