Artificial intelligence (AI) is undergoing a fundamental shift. Systems that once served as assistive tools(e.g., predictive models and generative AI) are now evolving into agentic systems capable of planning andexecuting complex, multistep tasks with minimal human input. As AI systems’ ability to plan and executetasks autonomously accelerates, so too does the potential speed and scale of cyberattacks. Compoundingthis risk, traditional cyber defenses were designed to react to human-driven threats rather thanautomated, machine-speed attacks. As such, organizations may be increasingly vulnerable to cyber lossesunless their security frameworks evolve to keep pace.
What Makes Agentic AI Different?
Agentic AI refers to systems that can plan, execute and adapt to tasks in real time with minimal humanoversight. These systems consist of autonomous, interconnected components—often referred to as AIagents—that work together. Components may include a large language model (LLM) for reasoning anddecision-making; integrated tools such as APIs, scanners and scripts to interact with external systems; andfeedback loops to assess results, learn from outcomes and refine actions.
Unlike generative AI, which primarily produces outputs in response to human prompts, agentic AI isdesigned to act independently. In the context of cybersecurity, AI’s capabilities mean that it is movingbeyond passive support and can directly enable threat actors to carry out cyberattacks. Rather thanwaiting for instructions, agentic systems can autonomously scan networks, identify vulnerabilities, writeand test malicious code, and access or exfiltrate data. They can also retain memory between sessions,allowing them to build on actions, observe outcomes and retry approaches until they meet theirobjectives. As a result, cyberattacks may become more persistent and difficult to detect.
How Attackers Are Using Agentic AI
Cybercriminals may use agentic AI to achieve several nefarious goals, including the following:
- Autonomous network movement—Agentic AI can independently map a network’s architecture,identify critical assets (e.g., financial data) and escalate privileges (e.g., by exploiting systemmisconfigurations) to gain broader access. This enables cybercriminals to move laterally across systems, significantly increasing the scope and impact of intrusions. Such movement may occurrapidly. According to CrowdStrike’s 2026 Global Threat report, the average time between an attacker’sinitial access and their first instance of lateral movement fell to just 29 minutes in 2025, with thefastest observed time just 27 seconds.
- Hyperpersonalized social engineering at scale—Agentic AI can autonomously harvest data fromsources such as social media and public records to generate highly-targeted phishing and socialengineering campaigns at scale. Unlike traditional phishing, which relies on generic messages sent tolarge audiences, these systems can refine their approach in real time based on the success or failure ofprior attempts, potentially exposing organizations to more frequent and sophisticated threats,including business email compromise and deepfake impersonation.
- Memory poisoning—Cybercriminals can introduce false or malicious information into an agenticsystem’s memory to alter its behavior over time. For example, a procurement AI could be poisoned toroute payments for a specific vendor to an external account, triggering fraudulent payments when alegitimate invoice is later processed.
- Attacks at scale—Agentic AI can be used to deploy multiple agents to launch cyberattackssimultaneously. This approach increases the volume and speed of attacks, potentially overwhelmingimpacted organizations’ defenses and making threats more difficult to detect and contain.
This shift toward more autonomous, agentic AI-driven cyberattacks is already evident in real-worldactivity. In September 2025, a Chinese state-sponsored group used an AI coding tool to targetapproximately 30 organizations in a coordinated campaign, showing how rapidly these capabilities arebeing applied in practice.
What Businesses Should Do
Businesses can consider the following measures to reduce the potential impact of agentic AI:
- Microsegment networks. Organizations should divide networks into smaller isolated zones, eachwith its own security rules, to reduce the risk of lateral movement. This approach, known asmicrosegmentation, restricts communication between devices, applications and other networkcomponents. Alongside this, organizations should adopt a zero-trust approach, where all connections,including internal ones, are continuously verified, and access is limited to only what is necessary,following the principle of least privilege.
- Switch to behavior-based endpoint detection. Organizations should implement behavior- andanomaly-based monitoring alongside antivirus tools. While antivirus software detects known threatssuch as malware signatures, agentic AI can change its signature with each execution to evadedetection. Behavior-based monitoring, in contrast, identifies deviations from normal system activity,using defined or learned baselines to detect and respond to previously unknown threats.
- Audit permissions on internal AI tools. Organizations should regularly review and audit thepermissions granted to AI tools and agents to ensure they are appropriate for their defined tasks,thereby reducing the risk of exploitation. This includes limiting access to specific systems (e.g.,allowing an agent that schedules meetings access to a calendar application, but not to corporateemail systems) and, where possible, using just-in-time permissions so access is temporary andavailable only when needed, rather than permanent.
- Update incident response plans for AI-driven threats. Organizations should review and updatetheir incident response plans to account for the speed and autonomy of AI-driven attacks, which canunfold far more quickly than traditional incidents. Regular tabletop exercises should be used to testhow teams respond and to identify any gaps in readiness. Plans should include scenarios where AItools and agents are compromised, such as through manipulation or data poisoning.
- Talk to a broker. Organizations should work with brokers to ensure their cyber insurance policiesadequately address evolving AI-related risks. Most cyber policies today are silent on AI—coverage is neither expressly granted nor excluded—so organizations should press for clarity on how AI-enabledattacks are treated, seek affirmative endorsements where available and watch for emerging AIexclusions at renewal, including coverage for incidents involving misused or compromised AI toolsand losses arising from autonomous or automated activity.
As agentic AI increases the speed and scale of cyberattacks, organizations must adapt their securityframeworks accordingly, strengthening governance, improving preparedness and evolving controls todetect, contain and respond to more autonomous attacks. Reviewing cyber insurance policies can helpensure adequate financial coverage. Contact us today for further information.