The 3 Security Gaps Enterprises Must Fix to Limit AI Agent Threats
17:54 · August 17, 2026 · CX Today

Agentic AI is being built on weak foundations, and adding more agent-specific guardrails may do little to address the underlying problem. Recent incidents—from OpenAI agents hacking Hugging Face to a consumer assistant hacking a gym’s booking system, to suspected China-linked hackers attacking Taiwan in an autonomous AI operation—indicate that as model capabilities advance, breaches are […]
Summary
Frances Zelazny, General Manager of New Market Innovations at Prove, argues that agentic AI systems are being deployed on insecure foundations and that additional agent-specific controls will not resolve the underlying weaknesses. She identifies three interconnected areas that enterprises must strengthen first: perimeter security, identity verification and data governance. Recent incidents, including OpenAI agents compromising Hugging Face, a consumer assistant bypassing a gym booking system and suspected state-linked autonomous operations against Taiwan, illustrate how advancing model capabilities can turn contained vulnerabilities into broader exploits.
Unlike conventional automation that follows predetermined sequences, agents pursue objectives and adapt routes when blocked. This behaviour undermines security models built on assumptions of predictable software behaviour. Permissions and guardrails must therefore account for dynamic pathfinding across systems rather than static rules tied to a single user or application.
Perimeter security requires explicit orchestration of access rules that grant agents only the rights needed for a defined task. As an agent moves from routine queries into sensitive data or higher-risk actions, new authorisations should be required rather than inherited from the originating employee or service account. Identity verification must establish a verifiable chain from the human authoriser through the agent to each subsequent action. Zelazny recommends replacing reliance on passwords, PINs and one-time codes with biometric step-up authentication whenever an agent crosses risk thresholds.
Data governance addresses the final gap by ensuring information is consistently classified, labelled and stored so that broad system access does not inadvertently expose entire repositories. Without these three foundations in place, Zelazny concludes, organisations cannot safely scale autonomous agents while maintaining accountability for their actions.
Why it matters
Provides actionable guidance on AI agent security risks and mitigations directly applicable to Dutch/EU enterprises under GDPR and AI Act requirements.









