惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google Online Security Blog
Google Online Security Blog
博客园_首页
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
V
V2EX
雷峰网
雷峰网
云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
F
Full Disclosure
Y
Y Combinator Blog
V
V2EX - 技术
Attack and Defense Labs
Attack and Defense Labs
S
Security @ Cisco Blogs
Schneier on Security
Schneier on Security
Microsoft Azure Blog
Microsoft Azure Blog
SecWiki News
SecWiki News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The GitHub Blog
The GitHub Blog
量子位
PCI Perspectives
PCI Perspectives
S
Secure Thoughts
D
Darknet – Hacking Tools, Hacker News & Cyber Security
AWS News Blog
AWS News Blog
Blog — PlanetScale
Blog — PlanetScale
爱范儿
爱范儿
K
Kaspersky official blog
B
Blog
A
Arctic Wolf
Hacker News: Ask HN
Hacker News: Ask HN
L
LangChain Blog
T
Tor Project blog
P
Privacy & Cybersecurity Law Blog
Recent Announcements
Recent Announcements
宝玉的分享
宝玉的分享
The Register - Security
The Register - Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
Lohrmann on Cybersecurity
D
Docker
A
About on SuperTechFans
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Google DeepMind News
Google DeepMind News
The Last Watchdog
The Last Watchdog
S
Security Affairs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Privacy International News Feed
Simon Willison's Weblog
Simon Willison's Weblog

Latest from TechRadar in Security

Trellix confirms data breach after hack of 'a portion' of its source code 76% of UK organizations have faced deepfake attacks. Most weren’t ready OpenAI is making ChatGPT accounts much more secure – including some literal physical security keys Employees are now more dangerous to their company than external hackers 'The inbox is no longer the only front line': Report claims vast majority of phishing attacks are now generated by AI - here's how to stay safe AI agents create new risks requiring continuous monitoring and oversight Small Language Models trained for your industry can deliver more for your business Why software defects are now the biggest security threat Europe’s relationship with US Big Tech has reached a breaking point 'Beyond the financial risk, there are real public safety implications': Hackers crawled Canadian streets with… QR code phishing surges 146% as Microsoft detects and analyzes 8.3 billion phishing threats in Q1 2026 – attackers are changing tactics to bypass security FBI says hackers are making millions from stolen cargo - losses 'surged' to nearly $725 million in 2025 Error in Medicare database exposes US healthcare providers Social Security numbers – Trump administration directory designed to modernize Medicare encounters another setback 'An hour of scan time is all it took': "Copy Fail" flaw impacts all Linux kernels released since 2017, so patch now or face the consequences Unlocking science: building AI researchers can trust AI tools have made vulnerability exploitation faster and easier Why governance is moving to the middleware layer When stability became strategy: the post-upgrade enterprise We need a cybersecurity curriculum taught by hackers The rising cost of technical debt in IT service management 'Zombie Tech continues to haunt UK networks': Decade-old vulnerabilities fuel 67 million attacks, exposing… 'Nearly two-thirds of spam came from US-based infrastructure': Your free Gmail account could be helping… 'PIN and data remain encrypted at rest': This unhackable offline device is quietly solving a problem most… 'The Internet is falling down': Critical cPanel CRLF injection vulnerability puts tens of millions of websites at risk of total compromise – hosting providers urged to apply CVE-2026-41940 patch immediately Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and… 5 myths about crypto payments for merchants and e-commerce New report claims Trump is the most-deepfaked US politicans with over half of cases — these 3 political figures… 'We’re a good example of if you work smart, apply security, tools and procedures smartly, you can still operate and be very agile': From the wind tunnel to the drawing board, how 1Password is helping Oracle Red Bull Racing stay secure and focused Why one outage can still take down half the internet How to reliably connect LLMs to real-world data and systems World Cup 2026: how mobile networks can avoid cybersecurity chaos at kick-off 'Chaining vulnerabilities is the hallmark of a sophisticated attack': 750,000 websites must be patched as… Is this 'the largest breach in football history'? Hackers allegedly breach Cristiano Ronaldo's Saudi team and AFC governing body, leak passports, contracts, and emails online 'This campaign works because it feels ordinary': Experts reveal how hackers use fake DHL messages to lure in… 'The challenge is no longer identifying bots. It’s understanding what the bot, agent, or automation is doing': New report flags 40% of all internet traffic is now bad bots Why scaling connectivity is imperative to continue meeting demand 'An unauthorized actor accessed certain Vimeo user and customer data': Vimeo confirms security incident,… 'VECT is being marketed as ransomware...but it functions as a data destruction tool': Experts warn this "broken" ransomware is now acting as a data wiper, so protect your files now 'Watching, keeping tabs, and sharing': New report claims workplace apps gathering far more personal data than we all think — and its even being used for advertising 'The attacker completed in under five minutes': Experts warn of North Korea-linked campaign using fake Zoom… 'The data should be a wake-up call': Report finds cybersecurity workers feel underpaid, undervalued and overstressed — and that's putting everyone at risk Hackers exploit Robinhood account creation tool to launch worrying phishing scam Medtronic says ShinyHunters hackers stole around 9 million medical records in latest attack Top open source PyPI package with over 1 million downloads each month hacked to send out malware CheckMarx admits it was hit by major cyberattack that saw data leaked onto Dark Web ‘Human lives are already being lost’: Open letter signed by hundreds of Google employees requests CEO reject ‘unethical and dangerous’ US military AI use Geopolitical tensions create new risks for satellite operators globally The blueprint architecture for securing the AI data center Quantum can wait: Why CISOs should focus on today’s preventable cyber risks 'Unfortunately, it needs to be said: Do not send a text to confirm you are human': Experts reveal how fake CAPTCHAs are driving a global SMS scam campaign ‘This was not an isolated incident’: Chinese national exposed by NASA investigation in serial defense software theft phishing campaign that lasted years New 'Firestarter' malware flames on in spite of Cisco firewall updates and security patches Utility giant Itron confirms cyberattack, says internal systems were accessed 'They don't care': ShinyHunters strike again as hackers claim to have pinched 7.5 million Carnival cruise… 'An interesting evolution in tactics': Google security experts flag new cyber scam which abuses Microsoft… Shadow AI and agents like OpenClaw are hijacking corporate data too easily Smart TV vs Dedicated Media Player for digital signage 'We will be taking action to protect American innovation': White House accuses China of… CISA puts US government agencies on two-week deadline to patch Microsoft Defender BlueHammer zero-day exploit Dutch cosmetic powerhouse Rituals confirms breach and stolen data from 'My Rituals' membership database China-nexus cyber actors' are turning routers and IoT infrastructure into covert botnets 'at scale' – NCSC, Five Eyes, and others warn of campaign involving Typhoon-designated groups This Firefox vulnerability may have been tracking all your private Tor identities – even in Private Mode Balancing trust and control to unlock AI-powered networking AI is no longer borderless Health data from UK Biobank spotted for sale in China – Government confirms medical info from 500,000 participants… Australia joins countries trialing Claude Mythos 'to ​make sure we are aware of emerging vulnerabilities' 'Identity is the new battleground': Why your IT helpdesk is suddenly getting a lot of bizarre calls 'An AI-led defense strategy that's overseen by humans': Google is introducing more agents to its 'full AI stack' to allow AI security at 'infinite scale' Vercel identifies more accounts 'with evidence of prior compromise' exposed during security incident ShinyHunters exposes data on Mytheresa, Zara, Carnival, 7-Eleven – over 40 organizations tied up in new data trove… UK security agency officially declares passkeys superior to passwords – passkeys should be the 'first… Why early-career investment and AI training matter for tackling the productivity crisis AI-generated passwords aren't as secure as they appear 'We will reveal their identity photos, names, location, and other': Experts reveal extraordinary battle… Ransomware negotiator recruited by BlackCat ransomware gang pleads guilty to 2023 attacks, faces 20 years in prison 'Hacktivist attacks at scale’: UK could face hacktivist threats akin to some of the biggest ransomware incidents but with 'no option to pay a ransom to help recover' Building a great website now means simplifying your tech stack 'Felony murder law does not require that a defendant pull the trigger': Ex-FBI chief calls for ransomware attackers to face homicide charges if attacks lead to deaths ‘Big Game Hunters’: UK ransomware volume drops significantly 'but the reality is more alarming' – big orgs are being hit harder and with greater success Mythos accessed by unauthorized users as Anthropic says 'We’re investigating' — Cracks may be showing in Project Glasswing as unknown users access model via third parties French government agency admits data breach as hacker alleges up to 19 million sensitive records stolen – breach may have exposed 'data from individual and professional accounts' FCC router ban begs the question: Do you know what’s running in your network? CxOs need to heed the lessons of cloud transformation when dealing with AI Mythos and friends could be a 'net positive' for UK cyber security defenses but only if they're secured,… Default BitLocker configuration isn’t enough: Defending endpoints against physical attacks 'The math is simple': OpenClaw 'Trojan Horse' AI agents give hackers full control of 28,000+ systems 'Pushpaganda is, at the highest level, a case of social engineering': Experts warn scammers are flooding… Iran alleges systematic sabotage of US-made networking infrastructure mid-conflict — hardware shut down and… 'HACKED': Hacker defaces Seiko USA website and claims theft of 'entire customer database' –… 'Stop selling or sharing my personal information': Research finds that Big Tech could be tracking you even… North Korea's Lazarus makes off with $290M crypto in Kelp DAO heist after siphoning funds using fraudulent… '88% Confident 90% Misled': Government & critical infrastructure leaders fundamentally misunderstand the… Microsoft issues warning over Teams helpdesk impersonation attacks – hackers are 'blending into routine IT support activity' by abusing remote assistance access 'NHS users report that it is awful to use': Palantir could be forced to exit NHS after pushback from staff, MPs, unions, and pressure groups over Federated Data Platform Software 3.0 is speeding up coding - but delivery is a different story Spotting the spyware: How modern spies are weaponizing phishing Robots are fighting wars and helping to quash riots — China is arming riot police with squads of AI controlled drones and Ukraine wants to man the frontlines with 25,000 robots US security agency still using Mythos despite ban – government using new security tool despite Pentagon's… Struggling to launch Teams? Microsoft recalls update causing failed startup and infinite loading loops –… NIST is cataloging so many vulnerabilities it can only assign severity scores to the highest priority threats
AI agents are being deployed – but not to full effect
Aaron Perrott · 2026-06-09 · via Latest from TechRadar in Security

Deployment has become the wrong measure of progress.

Across every sector, the conversation about AI agents has moved on from whether to deploy them to how quickly more can be added.

Within that shift, a critical assumption has taken hold which now needs re-examining; running agents and getting value from them are not the same thing.

Chief Technology Officer (CTO) at KTSL.

Recent research has found that 88% of UK enterprises are actively deploying AI agents, but only 20% have reached measurable business impact.

That is a sequencing problem rather than a technology one.

The wrong business case

When AI agents first appeared on enterprise roadmaps, the business plan was almost always built around cost reduction: automating that, reducing headcount here, cut spend there. But this playbook was borrowed from every previous wave of enterprise technology, and for early-stage pilots it was a serviceable framing.

Since then, organizations that have moved beyond pilots into live operations have largely dropped it. The returns they care about now are faster resolution of operational problems and better experience for the people those systems serve. Cost reduction, where it appears, tends to be a byproduct rather than the objective.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

A deployment designed to cut costs will be measured on costs. If the same deployment was actually improving resolution speed or reducing failure demand on support teams, that value would go unrecorded and unmade as a case for further investment. The lesson is one as old as time, but one we need to keep reminding ourselves of: get the objective wrong at the start and you can easily make a successful deployment look like a failed one.

Why deployments underperform

A meaningful proportion of AI agent implementations do not meet expectations, and a significant share of organizations have responded by pausing further investment. Before treating this as evidence that the technology doesn’t work, it’s worth looking at what is actually causing this underperformance.

The most common barriers we see are skills gaps, poor business case definition, data quality problems, and the absence of a capable technology partner. Again, none of this is to do with tech problems, but more to do with preparation and execution.

In practice, I see a further problem in that agents need to be perceived as genuinely better than the process they replace by the people doing the work. If engineers and operators don’t feel the benefits, you’re never going to see effective adoption. After that, deployments will fade away before they have the chance to prove themselves. Buy-in, as ever, needs the same attention as the technical implementation.

Defining what success actually looks like

One consequence of deploying agents without agreed success metrics is the inability to demonstrate value even when it is being created. This is a particular problem in IT management, where AI agents are increasingly handling incident detection, triage and resolution.

Mean Time To Resolution (MTTR) is the metric that matters most in this context, and it repays closer examination. The stages of an incident lifecycle are:

Identification,

triage,

isolation,

diagnosis,

fix, and

Verification

Each of these carries a different weight depending on where the current process is slowest. An organization that takes ten minutes to identify an incident but two minutes to resolve it once identified has a different problem than one where diagnosis is more of a constraint. So agents need to be applied to the stage where they will provide a genuine efficiency gain.

Establish the baseline before selecting the intervention and know where time is actually being lost. Then you can set a specific target for reducing it, and measure against that. Without this, it is genuinely difficult to distinguish a successful deployment from a busy one.

The governance gap

Security and governance frameworks are still for the most part built for environments where humans make consequential decisions, even if software executed them. When you introduce autonomous agents into the mix, with the ability to access sensitive data and act on it in real time with limited human oversight, those frameworks become ineffective. This is not a criticism of how they were designed, more a description of a gap that has opened up as deployment has scaled.

When I look at where organizations are most exposed, it tends to be the enterprises whose existing frameworks are too deeply embedded to revisit easily. Legacy architecture is the constraint, and larger organizations carry more of it.

There’s a comparison to be made here with the eras SaaS sprawl and shadow IT. In both cases the technology moved faster than the controls around it, and the cost of establishing those controls retrospectively was higher than building them in would have been. With this in mind it’s easy to see that governance does not act as a brake on deployment of new tech, it’s a pre-requisite that ensures long-term effectiveness.

Integration decisions made late are expensive

Enterprise IT infrastructure is heterogeneous in ways that technology planning tends to underestimate. The mix of public cloud, private hosting and hybrid environments - layered over legacy systems running processes that are poorly documented and harder to change than anyone would prefer - creates conditions that require deliberate architectural thinking from the start. Agents designed without accounting for this environment will require significant rework once they encounter it.

There is also a less obvious use for AI in this process. Applied earlier in the planning cycle, it can identify where legacy systems are creating the most friction and where integration investment will produce the most return. Most organizations deploy AI to generate output; fewer use it to improve the quality of the decisions that shape deployments in the first place, making this application of agents a competitive differentiator.

The sequencing question

Fundamentally, the technology used in successful AI agent deployments and failed ones is the same. What separates them is sequencing: the conditions for success were established before the agents went live.

Those conditions require more discipline than sophistication, including tightly-scoped use cases, clean, well-governed data, integration as a priority and security frameworks that account for the presence of autonomous systems.

The question worth sitting with is whether your organization knows, specifically, what each AI agent is supposed to improve, whether it is improving it, and what will happen to that agent in eighteen months if it is not. Most enterprises cannot answer all three – if you can, you’ll already be one step ahead of the curve.

We list the best IT Automation software.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit