











LAS VEGAS – Companies are deploying AI agents into everyday work at a pace no security program was built for.
Related: AI layoffs pays for AI infrastructure
As Black Hat USA 2026 gets underway in Las Vegas, that question is moving rapidly from theoretical concern to operational reality.The rush is competitive. Nobody wants to be the last one still doing this by hand. What’s getting skipped is the harder question: once an agent is acting on a company’s behalf, how does anyone know what it’s actually doing?
Companies are handing routine tasks to AI agents. Each one moves through the same screens a person would, and every check along the way comes back clean. The login names whose credential is in use. It says nothing about who, or what, is actually operating the account.
Identity systems answer one question well: who is logging in. Multifactor authentication and single sign-on are built for that, and only that. Nothing checks what the login is then allowed to do.
Machines have been logging in for years too. That got handled by predictability. A script ran the same steps every time, so anything different stood out. Two populations — human and machine — two ways of checking, and that covered most of what needed watching. Then came something that belongs to both checks at once: generative AI.
Into the machine layer
Companies are tripping over themselves right now, racing to beat each other to market with AI agents everywhere they can put them. Each one signs in with a username and password like a human user would.
Once that hurdle clears, the agent moves into the machine layer, the systems built to talk to other systems, where a company would normally expect the predictability check to catch anything off. But that check was built to catch a script behaving strangely. An AI agent making its own decisions at every step doesn’t behave strangely. It behaves like a legitimately signed-in person, so nothing ever trips.
This is no longer a thin slice of traffic. Automated activity reached 53 percent of all web traffic last year, according to Imperva’s 2026 Bad Bot Report, which for the first time counted AI agents as a third category because the old sorting stopped working. The Cloud Security Alliance found non-human identities outnumbering human ones 45 to 1, and 78 percent of organizations have no written policy for creating or retiring an AI identity.
That is the exposure. Two systems, both working exactly as designed, and neither built for an AI agent that clears the human door while slipping past the machine gate. Companies are deploying agents into that opening right now, racing to keep up with each other, without pausing to close it.
Shira Sagiv, Radware’s vice president of product portfolio, has spent her career on the other side of exactly this problem. Last Watchdog connected with her ahead of Black Hat USA 2026 to talk through what changes once a valid login no longer tells you who, or what, is on the other end.
LW: When a company hands a routine task to an AI agent, what does the login actually confirm, and what does it leave completely unknown?
Sagiv: A login confirms that the agent has permission to enter a system. It doesn’t tell you whether the agent should take a specific action, whether that action is safe, or whether the behavior matches the business purpose it was given.
Authentication establishes identity. It does not control what happens next. An internal AI agent may have access to sensitive applications, APIs, data and tools, and the autonomy to act across all of them. If it is over-permissioned, manipulated through a malicious prompt, or simply behaves in a way no one intended, valid credentials will not prevent it from causing harm.
LW: You’ve spent your career on the predictability side of this problem. What used to make enterprise automation easy to govern, and why doesn’t that hold for an AI agent?
Sagiv: Traditional automation was easy to govern because it was narrow and repetitive. A script performed the same task the same way every time. When it changed, that stood out.
AI agents are built to do the opposite. They interpret, decide and adapt. They use valid credentials, work through legitimate applications and call APIs in ways that look ordinary on the surface. What they do next depends on the prompt, the data they receive and the tools they are allowed to reach.
Sorting traffic into people on one side and scripts on the other no longer covers what is out there.
LW: Once an agent clears the login and starts acting across a company’s systems, what’s actually different about how it behaves compared to traditional automated activity?
Sagiv: The difference is variability, and it shows up in what the agent does once it is inside.
It may reach sensitive data it has no need for, invoke the wrong tool, or pass information to a system that was never authorized to receive it. It may also take a series of individually valid actions that add up to an outcome nobody intended.
None of that requires the agent to be compromised. It can happen while the agent is performing the legitimate business task it was assigned, using approved credentials and approved tools.
LW: Companies are racing to deploy agents faster than they can figure out how to secure and govern them. What does that race actually cost a security team, in practical terms?
Sagiv: It creates blind spots. Security teams are being asked to protect activity they cannot fully see or classify yet.
They may not know which agents are running, what those agents can reach, what permissions they hold or whether any of that has changed since deployment. Detection slows down. Governance gets harder, because a team cannot manage what it cannot see.
The practical cost is time. An agent that has been manipulated or over-permissioned goes unrecognized until after the business impact shows up.
LW: If the old checks don’t catch this, what does? What can a company actually put in place today?
Sagiv: Organizations need to move past checking identity alone and start looking at what an agent can access and how it behaves across its whole lifecycle.
Discovery comes first. Security teams need to know where AI agents are running, including agents connected to SaaS applications, developer environments and internal business workflows. Sanctioned agents and shadow AI both have to be found and accounted for.
Governance follows. Organizations need to understand what those agents can access, which actions they can take, who owns them and whether their permissions match their intended purpose. Compliance sits here too, against the EU AI Act, the NIST AI Risk Management Framework, ISO 42001, GDPR and HIPAA.
Then runtime protection. Approving an agent at deployment and assuming it will behave as expected is not enough. Teams need behavioral signals showing whether the agent is operating inside its guardrails, and controls that can stop a risky action while it is happening.
Agent behavior is dynamic, and it changes with prompts, data and tool interactions. That argues for defenses that evaluate activity continuously and respond at machine speed. Radware’s Agentic AI Protection is built along those lines, to discover, govern and protect agents through the lifecycle.
LW: A board is told its identity controls are working. What’s the one question it should ask next about the AI agents operating inside the business?
Sagiv: Do we know which AI agents are operating across our business, what they can access, and whether we can stop them from taking an action we never intended?
It sounds simple. Authentication tells a board who or what entered the system. It says nothing about whether everything that followed was appropriate.
If the answer is no, the organization has a visibility and control gap, even if its identity controls are working exactly as they should.
Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.
(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)
August 3rd, 2026 | Black Hat | Black Hat Podcasts | Q & A | Top Stories
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。