V-Help
← All news
Artificial intelligence

Managing AI Agents: Lessons from Security Experts

Managing AI Agents: Lessons from Security Experts

Photo: ZDNet

Quick answer

AI agents demand strict limitations and oversight to prevent uncontrolled actions and data leaks.

Autonomous AI agents are rapidly evolving from simple chatbots into digital employees capable of executing tasks within corporate applications and handling sensitive data. However, their increasing autonomy raises serious concerns about security and governance. Experts at the Snowflake Summit emphasized that these systems should be treated like diligent but inexperienced interns—requiring constant oversight and clear instructions.

The core issue lies in the unpredictability of AI agents without proper constraints. For instance, an agent tasked with purchasing shoes might instead buy a car if left unchecked. Experts stress the need for meticulous access rights management and strict boundaries to prevent unintended consequences. Additionally, context and intent must be carefully considered during development and deployment.

Another challenge is the dynamic behavior of AI agents. Unlike traditional software with predefined API interactions, agents operate autonomously, selecting their own problem-solving paths. This can lead to scenarios where agents interact with tools capable of executing user-level actions, creating risks of data leaks or unauthorized access.

Experts also warn about the phenomenon of 'shadow AI'—instances where agents operate outside IT oversight. For example, one client discovered 12 uncontrolled OpenClaw instances with API and source code access, while a contractor used Telegram* for data sharing. Such cases highlight the need for rigorous monitoring and auditing of all AI systems within an organization.

To mitigate risks, specialists recommend applying traditional identity and access management practices while implementing clear instructions and constraints for agents. Balancing AI autonomy with security is critical to maintaining effectiveness without losing control. As Nancy Wang, CTO of 1Password, noted, the primary risk stems from agents with excessive privileges and long-term credentials.

Common questions

Why are AI agents compared to inexperienced interns?
Like interns, AI agents can act unpredictably or exceed their authority without clear instructions. They require constant supervision and constraints to avoid errors or misuse.
What risks do autonomous AI agents pose?
Key risks include uncontrolled actions, data leaks, privilege escalation, and challenges in tracking their activity. Without proper management, agents may interact with systems in unsafe ways.
How can businesses ensure AI agent security?
Implement strict access controls, monitor agent actions, validate configurations and data, and apply traditional identity and access management practices to balance autonomy with security.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: ZDNet