CISOs Race to Control AI Agents Without Destroying Their Value
A recent survey by Team8, a venture capital firm, reveals that CISOs are struggling to manage the growing risks associated with AI agents. Seventy-one percent are experimenting with AI agents, but the rapid expansion of the attack surface and the difficulty in defining precise instructions for these agents are creating significant security challenges. The key takeaway is that traditional security practices are no longer sufficient, and a shift towards increased transparency, experience sharing, and robust guardrails is needed to prevent unintended consequences and mitigate risks.
Two major AI pain points for today’s security leaders are adjusting to new requirements for cyber hygiene, and preventing unintended consequences from over-privileged agents. Team8, a venture capital and private equity firm, has developed a ‘CISO Village’ – an invitation-only global community of security leaders – to understand these challenges. Their latest annual survey report, released this year, highlights a significant trend: Seventy-one percent of CISOs are experimenting with or augmenting existing security tools using AI agent capabilities.
CISOs are mobilizing before they feel fully ready, investing in platforms, skills, and new control mechanisms. However, the rapid expansion of the attack surface is outpacing control layers, creating a significant security gap. The survey indicates that AI and agent security is by far the biggest pain point (78%), twice that of the second most significant concern (39%).
Team8’s CISO, Tim Brown, emphasized that the core issue stems from the difficulty in defining precise instructions for these agents. He explained that AI agents are being created by employees using readily available coding tools like Claude Code, Cursor and Codex, leading to potentially unpredictable behavior. “An AI agent is not just another employee – it’s a very resourceful employee that will do whatever it takes to accomplish the task it believes it has been given.”
Brown highlighted the risk of agents accessing and manipulating data beyond their intended scope. For example, an agent designed to gather information about Tim Brown Systems could potentially explore any system on the internet. He stressed the importance of building guardrails into the agent development process to limit access and functionality, but cautioned that overly restrictive measures could stifle the agent’s utility. “It’s easy to create 100% successful guardrails,” he said, “I take the system, I unplug it, I throw it into the ocean. Then it’s safe. Useless, but safe.”
Brown recommended increased transparency and experience sharing among security leaders to accelerate the development of effective solutions. “Let’s share more often. Why do I have to learn everything from scratch when my friend in company X has already done this? We should come together as defenders.”
Related: Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
Related: OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
Related: ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
Related: Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware