Agentic AI is being built on weak foundations, and adding more agent-specific guardrails may do little to address the underlying problem.
Recent incidents—from OpenAI agents hacking Hugging Face to a consumer assistant hacking a gym’s booking system, to suspected China-linked hackers attacking Taiwan in an autonomous AI operation—indicate that as model capabilities advance, breaches are likely to become more frequent and sophisticated.
As biometrics and identity expert Frances Zelazny, General Manager of New Market Innovations at Prove, told CX Today in an interview:
“The alarming piece of this is that we continue to perpetuate weak foundations and think that we can just pile on with more and more things, and something, somehow will magically fix itself. But it won’t.”
Zelazny argued that enterprises need to urgently address three areas before they can safely scale agentic systems.
“We need to fix perimeter security. We need to fix identity. We need to fix data governance. And if those things are fixed, a lot of problems that we see with agents today will go away.”
“These are the foundations for all of this that will allow us to really engage in an agentic world.”
As agents gain access to more enterprise systems and make decisions without a human approving each step, weaknesses that were previously contained within individual applications or processes can become much easier to exploit.
Strengthening security foundations rather than assuming another layer of controls is key to reducing the risks created by increasingly autonomous systems, according to Zelazny.
AI Agents Are Different From Conventional Bots
Traditional automation generally follows a defined sequence of actions. But an agent can have a goal and determine how to reach it, potentially interacting with multiple systems along the way.
“Agents have agency, they have objectives, and they will try to do whatever is in their power to achieve that objective. So, if they can’t do it one way, they’re going to do it another way,” Zelazny noted.
This creates a problem for security controls built around assumptions about how software will behave.
An organization might impose permissions, policies or guardrails around an agent, but those controls have to account for what happens when the agent encounters a barrier and searches for another route to complete its task.
Rather than continually adding layers around insecure foundations, enterprises need to address the underlying infrastructure on which agents will operate.
The three areas Zelazny highlighted are closely connected. An agent needs clearly defined access to systems and data. The enterprise needs to know who authorized that agent and who remains responsible for its actions. And the data the agent can reach needs to be properly classified, governed and protected.
1. Perimeter Security Needs to Account for Agents
The traditional enterprise perimeter has already become more complicated as employees, applications, APIs, cloud platforms and third-party services interact across organizational boundaries. Agents add another participant to that environment, potentially with the ability to access and act across multiple systems.
“Perimeter security is all the access rules, the orchestration, who has access to what, when, why and who grants them those permissions,” Zelazny said.
An agent should not receive broad access simply because the employee or application behind it has access to a particular system.
Zelazny proposes that permissions need to reflect the specific task an agent has been authorized to perform.
“As you cross thresholds, you have to get new permissions… [and] have access controls for the agents.”
This becomes particularly important when an agent moves from routine information into sensitive data or higher-risk actions.
The implication for enterprise security teams is that agent access cannot be treated as a single authorization event. Permissions may need to change as an agent moves through different levels of risk.




