惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google Online Security Blog
Google Online Security Blog
G
Google Developers Blog
云风的 BLOG
云风的 BLOG
阮一峰的网络日志
阮一峰的网络日志
L
Lohrmann on Cybersecurity
Security Latest
Security Latest
博客园 - 【当耐特】
Microsoft Security Blog
Microsoft Security Blog
N
Netflix TechBlog - Medium
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The GitHub Blog
The GitHub Blog
Vercel News
Vercel News
The Register - Security
The Register - Security
T
Tenable Blog
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
有赞技术团队
有赞技术团队
C
CXSECURITY Database RSS Feed - CXSecurity.com
Simon Willison's Weblog
Simon Willison's Weblog
S
Schneier on Security
Scott Helme
Scott Helme
C
Cyber Attacks, Cyber Crime and Cyber Security
C
CERT Recently Published Vulnerability Notes
罗磊的独立博客
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
H
Hackread – Cybersecurity News, Data Breaches, AI and More
K
Kaspersky official blog
Know Your Adversary
Know Your Adversary
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
Spread Privacy
Spread Privacy
P
Proofpoint News Feed
博客园 - 聂微东
NISL@THU
NISL@THU
T
Threat Research - Cisco Blogs
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
A
Arctic Wolf
V2EX - 技术
V2EX - 技术
H
Heimdal Security Blog
C
Check Point Blog
D
DataBreaches.Net
H
Help Net Security
www.infosecurity-magazine.com
www.infosecurity-magazine.com
L
LangChain Blog
宝玉的分享
宝玉的分享
V
Vulnerabilities – Threatpost
PCI Perspectives
PCI Perspectives
Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler

Cloud Security Alliance

SearchLeak: Copilot Data Exfiltration Exploited | CSA Zero-Trust AI Governance for Multi-Agent Systems | CSA Dangling CNAMEs: Hidden Cloud Risk | CSA Agentic Payments in Financial Services | CSA Mythos and the Future of Cybersecurity | CSA AI-Driven Cloud Risk: Defenders Lose Ground | CSA Financial Services Industry Shifts from AI Adoption to | CSA CSAI Foundation Announces RiskRubric V2 as the Next Key | CSA RiskRubric Updates: AI Risk Assessment | CSA Over 80% of Organizations that Miss 24-Hour Patch Window Report | CSA ORCHIDEAS & MAESTRO: Secure AI Design | CSA Top 6 Claude Security Risks to Watch | CSA Cloud Cost Optimization in 2026 | CSA HIPAA Rule Overhaul in 2026 | CSA AI-Driven Exploits Outsmart Detection | CSA MCP Risks CISOs Should Prepare For | CSA AI Governance for Trust and Compliance | CSA MTTP: Patch Cycles Too Slow | CSA Cloud Security Evolution: Security Teams Lead | CSA Misconfigurations Break Customer Trust in Apps | CSA Taming Shadow AI: C-Suite Strategies | CSA Agentic AI Threats: Five Powers | CSA AIUC-1: Agentic AI Governance | CSA 2026 Threat Report for CISOs | CSA Securing AI in AWS: Runtime Detection & Response | CSA SLMs, LLMs, and the DSPM Difference | CSA OT Security Timeline: Mythos and Patch Pace | CSA Blast Radius and Cloud Threat Detection | CSA State of AI Cybersecurity 2026: 92% Concerned | CSA AI in MDR for Franchise & Multi-Location Ops | CSA AI Regulation: Identity and Authorization Gap | CSA MITRE ATT&CK for Cloud: Detection Coverage Guide | CSA Shadow AI Agents: The Insider Threat | CSA Medical Device Breaches Reveal Cloud Security Gaps | CSA AISMM: AI Security Maturity Model for Cloud | CSA Globee® Awards for Artificial Intelligence (AI) Honors Cloud | CSA Patching Smarter for Mythos Security | CSA SDP v3: Identity-First Zero Trust for AI | CSA AI-Ready Security Documents Beyond STIX, OSCAL, and SARIF | CSA Penetration Testing for ISO 42001 & Trust | CSA AI Agent Posture: Data-First Security Guardrails | CSA AI Agent Security Starts with Scope Control | CSA Identity Spoofing vs. Identity Abuse | CSA AARM: Securing the Agentic Runtime | CSA Securing the Agentic Control Plane | CSA CSAI Foundation Announces Key Milestones to Secure the Agentic | CSA Catastrophic AI Risk Controls | CSA Cloud to AI: Building Secure Programs | CSA Identity in AI Era: Zero Trust's First Pillar | CSA SDLC Visibility: Securing Multi-Cloud Development Lifecycles | CSA Cloud Risk: Top 3 Threats & AI Tools | CSA AI Agent Identity Is Solved Backwards | CSA 8 Truths About Cloud Privilege Risk | CSA AI Governance: Mature Programs | CSA Agent Access Management: Data-First Security | CSA Glasswing: AI-Driven Security for Safer Software | CSA Runtime Security: Detection & Real-Time Cloud | CSA Identity as the OS for AI Security | CSA Cloud Misconfigurations Drive Attacks at Scale | CSA Sensing AI Behavior with the WBSC Probe Library | CSA An Actionable Guide to GDPR Compliance for Startups | CSA Cloud Security LIVE 2026: AI Risk & Trust | CSA Shadow AI Agents: Enterprise Governance | CSA Rethinking Non-Human Identity Security | CSA New Cloud Security Alliance Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments More Than Half of Organizations Experience AI Agent Scope | CSA SANS Institute, Cloud Security Alliance, [un]prompted, and OWASP | CSA AI Agents Are Talking: Are You Listening? | CSA Software Supply Chain Security Needs an Upgrade Choosing the Right AI Standard: 7-Point Guide | CSA Audience-Driven Authorization for AI Agents | CSA A CISO's Guide to Cloud Security Architecture | CSA Who’s Behind That Action? The AI Agent Identity Crisis SSCF Adoption for SaaS Security | CSA Mythos and the Vulnpocalypse: Cloud Defenses | CSA AI Security Risks and Data Visibility | CSA From Compliance to Credibility with CAIQ/CCM | CSA The State of Cybersecurity in the Finance Sector: Six Trends to Watch EU AI Act Compliance with prEN 18286 & ISO 42001 | CSA AI Security in the Cloud: Exposure Management | CSA Rethinking Incident Response as Engineering System | CSA Defense Depends on the Creator: AI Security | CSA ATF: Zero Trust for AI Agents | CSA Cybersecurity Needs a New Data Architecture | CSA CSA STAR v4.1 Updates for Cloud Security | CSA Unstructured Data Surges as Enterprises Struggle to Maintain | CSA SC Media Names Cloud Security Alliance’s Trusted AI Safety | CSA Exposed AWS Key Leads to Full Account Takeover | CSA Post-Quantum Cloud Migration for CSA Members | CSA AI Identity Security Compliance Checklist | CSA The Agentic Trust Deficit: MCP's Authentication Vacuum | CSA More Than Two-Thirds of Organizations Cannot Clearly Distinguish | CSA AI Cybersecurity 2026: Insights from 1,500 Leaders | CSA Three-Body Security: Data, AI & Identity | CSA IAM as Safety for AI-Controlled Systems | CSA Kubernetes Cost Savings and Security Debt | CSA Code to Cloud Security: Unified Exposure Management | CSA Retail Misconfigurations Attackers Exploit | CSA Rethinking Authorization for the Age of Agentic AI | CSA Enterprise AI: Guardrails to Governance | CSA
AI Agents Go Beyond Output: Enterprise Security | CSA
2026-05-01 · via Cloud Security Alliance

Written by Harish Peri, SVP and General Manager for AI Security, Okta.

Recent test results from an AI labopens in a new tab have renewed attention on a question that is becoming harder for enterprises to ignore: What happens when AI systems are no longer limited to generating output, but are increasingly able to take action?

In the tests, AI agents tasked with a relatively simple business function – creating LinkedIn posts from company data – found ways to publish sensitive password information, work around security controls, override antivirus protections to download malware, forge credentials, and even pressure other agents to bypass safeguards.

Taking into consideration the growing number of public examples of AI systems behaving unexpectedlyopens in a new tab, these findings point to something bigger than a couple of isolated incidents.

OpenClaw image 

They point to a shift in the role AI is beginning to play inside organizations.

AI moves from output to action

For much of the recent AI cycle, enterprise attention centered on outputs — how well systems could summarize information, generate content, answer questions, or assist employees in completing tasks. That was only the beginning. AI agents are now being designed to retrieve data, call tools, interact with applications, trigger workflows, and carry out tasks across systems.

That changes the enterprise security and governance equation.

Once an AI system can take action inside business environments, the issue is no longer just whether its output is accurate. Organizations must now consider what it can access, what it has permission to do, and how its access is governed over time.

That is why the latest discussion around rogue AI agents matters. It reflects a broader reality: Organizations are beginning to delegate access and authority to software in ways that were once reserved for people. An AI agent can now determine the next step in a process, retrieve sensitive information, invoke downstream tools, and act on behalf of a user.

The ripple effect (and risk) of autonomous actions 

The risk is not just what a single agent can do. It is the scale at which these systems can operate. A single prompt can trigger chains of actions across multiple applications, APIs, databases, and tools, creating a surge in machine-to-machine access decisions that can quickly outpace human oversight. 

As more teams deploy agents, including ungoverned shadow AI agents, that volume will only accelerate. The more connected and autonomous these systems become, the more important it is to define what they can connect to, what they can do, and where the limits should be.

This is where traditional models of trust begin to show strain. Enterprise security has historically focused on managing access for human users and governing applications that generally followed fixed rules. 

AI agents introduce something different: non-human actors that can interpret goals, adapt to context, and chain actions together. Trust can no longer be defined only by a login event or a static role. It also cannot depend on security and access controls embedded within a single cloud or platform provider’s “walled garden.” It has to include visibility, least-privilege access, and continuous governance over what an agent is permitted to do, which requires a centralized identity control plane that can work across models, tools, clouds, and frameworks.

Three essential questions for the secure agentic enterprise

For organizations adopting AI agents, that starts with three foundational questions.

Where are my agents? What can they connect to? What can they do?

Where are my agents?

Before teams can govern AI agents, they need visibility into where those agents exist across their environment. That means understanding what agents are running and which teams are deploying them.

What can they connect to?

An agent’s usefulness is often defined by the systems, data, APIs, and tools it can reach, but this connectivity is also where risk expands. Organizations need a clear picture of which applications and resources each agent can access, whether that access is necessary, and whether it is constrained by policy and least-privilege principles.

What can they do?

This is ultimately the most important question. There is a significant difference between an agent that can summarize a support case and one that can reset a credential, approve a request, modify a record, or trigger a transaction. As AI agents move from assistance to action, enterprises need stronger control over which actions are allowed, under what conditions, and with what oversight.

Taken together, these questions point to a larger requirement: AI agents need to be treated as first-class identities in the enterprise. That means organizations need to configure identity for those agents, gain visibility into where they operate, enforce controls over what they can access, and govern that access over time.

In the era of the agentic enterprise, success will be defined not just by how many agents an organization can deploy, but how well you can secure them across real systems and workflows.

Harish Peri is the SVP and General Manager for AI Security at Okta. In this role he is responsible for the product strategy, GTM strategy, commercial execution and customer experience for securing agentic AI. He has over 20 years of experience spanning engineering, product management, marketing and general management, across multiple industries including Financial Services, Technology and Human Capital Management.