News

AI Agents Create New Security Risks Beyond Chatbots

AI Agents are Changing Digital Tasks While Raising New Security Concerns Around Access and Data Protection

Written By : Akshita Pidiha
Reviewed By : Pranchal Srivastava

Artificial Intelligence is evolving from answering questions to completing tasks. This shift has raised fresh concerns about security and digital access. Unlike traditional chatbots, AI agents are designed to complete actions across software, databases and online services. They can book travel, manage subscriptions, transfer information between applications and carry out workplace tasks with limited human involvement. 

Security experts say this growing autonomy also creates new risks if an AI agent makes a mistake or falls into the wrong hands. An AI agent needs permission to interact with business applications and personal accounts to complete assigned tasks. If that access is too broad, a single error could lead to financial transactions, accidental data deletion, or exposure of sensitive information. The concern is not limited to cyberattacks. Industry experts say an AI system could unintentionally act outside its intended role. It creates operational and security issues at machine speed.

Survey Highlights Visibility Gap

Rubrik said organizations are already struggling to monitor autonomous AI systems inside their environments. Research from Rubrik Zero Labs found that 86% of global IT and security leaders expect AI agents to move faster than existing security controls within the next year. At the same time, only 23% confirmed that they have complete visibility into the AI agents operating across their organizations. 

Rubrik has introduced Agent Identity as part of its Agent Cloud platform to address this challenge. The system is built around a just-in-time access model rather than permanent credentials. Instead of giving an AI agent unrestricted access to business systems, the platform provides temporary permissions for a specific task. Once the action is completed, that access expires automatically. As Dev Rishi, General Manager of AI at Rubrik, said, "Agents are no longer just synthesising information; they are acting on behalf of employees."

Checking Actions

Rubrik's platform also reviews an AI agent's requested action before execution. It evaluates the task, checks security policies, and verifies the agent's identity before granting a short-lived access token. If an AI agent attempts an action outside its authorized scope, the request can be blocked before it reaches business systems.

The company has also introduced Agent Rewind, a capability designed to reverse certain destructive actions carried out by AI agents. As autonomous AI becomes part of everyday business operations, security controls such as limited access, continuous verification, and recovery tools are expected to play a larger role in reducing operational risk.

Also Read: Beyond ChatGPT: OpenAI Reportedly Building Expressive AI Companion With Moving Parts

Alibaba Changes AI Playbook with Revenue Share for Large Qwen Users

Beyond ChatGPT: OpenAI Reportedly Building Expressive AI Companion With Moving Parts

Record Emigration of Professionals Sparks Fears Over Israel’s Talent Pipeline

Israel Faces Rising Exit of High-Earning Professionals

Mass Applications No Longer Work, Say UAE Recruiters