Table of Contents


Executive Summary

SPONSORED REPORT — Produced by Cyber Brief Daily in partnership with OBRELA. All analysis and editorial content is independent. — Also read: Exclusive: The Opportunities and Pitfalls of Agentic AI

The widespread adoption of AI agents is happening at a far faster rate than anticipated. At the same time, AI agents are becoming increasingly autonomous and capable of making decisions their creators did not intend. Cybercriminals are also becoming increasingly adept at using AI agents to amplify the scope of their attacks and for turning legitimate AI agents rogue by means such as weaponised spreadsheets.

AI agents have already come to represent a new insider threat and an easy entry point for bad actors wishing to compromise a target company's IT systems and encrypt its critical data as a precursor to a full blown ransomware attack. Threat actors can, for example, turn an agent rogue by sending it a weaponised Excel spreadsheet. When the AI agent opens the spreadsheet, it is given covert instructions to expose log-in information or other critical data.

There is, however, little doubt that AI agents can offer enhanced efficiency and streamline and accelerate business operation. And, despite the inherent risks, companies now feel that they have no alternative if they are to remain competitive. According to research giant Gartner, by 2028 90 per cent of business-to-business (B2B) buying will be AI agent intermediated, pushing over $15 trillion of B2B spend through AI agent exchanges. Microsoft also reports that more than 75 per cent of knowledge workers now use AI on the job, accelerating the shift toward agent-driven workflows.

"What we are now starting to witness is a widening digital divide between those organisations which implement strict AI agentic guidelines together with effective cyber-defences and those who are leaving their AI agents open to sustained and determined cyber-attacks."

However, organisations that do not implement sufficient guardrails and defences will soon find themselves paying a high price when AI agents are turned rogue or otherwise compromised by bad actors. Agents may also inadvertently contravene regulatory requirements. For these reasons, Obrela's comprehensive cybersecurity platform SWORDFISH has been designed to be fully AI-Ready.


Section 1: Rapid Adoption and Implementation of Agentic AI

Companies across the globe are rushing headlong into the rapid adoption of AI in order to take advantage of the prospect of streamlined business operations and increased efficiencies the new technology appears to offer.

Agentic AI uses the most advanced generative AI, which is also known as 'frontier AI'. Instead of just making a prediction or generating new content, AI agents can access data sources, remember context, make decisions, use tools, and take specific actions to achieve their goals. They are becoming increasingly autonomous and are already able to operate without continuous human intervention and even create sub-agents to execute specific tasks. This makes them extremely useful, but also makes them more hazardous than non-agentic AI tools.

According to Forrester's Q4 2025 AI Pulse Survey, 56 per cent of generative AI decision-makers already find AI agentic sprawl a current challenge for their organisation. In the future, fresh threats will emerge for employees across every function as staff will be able to build AI agents in addition to those created at a corporate level. Third parties also deploy AI agents which interact with partner organisations' systems.

According to research company International Data Corporation (IDC)'s Worldwide AI and Generative AI Spending Guide, European spending in artificial intelligence will reach $144.6 billion in 2028, based on a compound annual growth rate (CAGR) of 30.3 per cent over 2024–2028. IDC also forecasts that worldwide spending on AI, including AI agents, infrastructure, and related IT and business services, will more than double by 2028 when it is expected to reach $632 billion.

From an industry perspective, the financial services sector is expected to spend the most proportionally on AI solutions, accounting for 23 per cent of the market in 2025. Banking is at the forefront; strategic digital investments of European banks are aimed at enhancing efficiency, strengthening risk management, and ensuring long-term profitability. The second largest industry for AI spending is software and information services. The third biggest is retail. In terms of the fastest growing industries, media and entertainment are the fastest growing sectors, with CAGRs exceeding 35 per cent over 2024–2028.

"Agentic AI tools are starting to appear in real organisations, not just research labs. These tools don't just generate content or predictions; they can plan, make decisions and take actions on your behalf." — UK National Cyber Security Centre (NCSC)

Agentic AI Implementation Challenges

  • AI agents are usually permitted to access external systems, data and tools in ways that non-agentic AI systems are not
  • AI agents are frequently subject to unpredictable behaviour, interpreting set goals in ways that their human creators had not anticipated
  • When AI agents execute actions, these generally occur faster than humans can meaningfully review them
  • Decisions made by AI agents can be hard to interpret
  • The ever-growing range of tools available to agents makes it even more challenging to explain a particular course they have chosen

Implementation Recommendations

  • Calculate in advance what could go wrong and how failures or misuse could affect operations
  • Consider whether an AI agent is really necessary, or whether a process could be simplified or automated by a lower-risk method
  • Deploy agentic AI incrementally, beginning with tightly bounded pilots using clearly defined tasks, building confidence in the system before expanding its scope (NCSC recommendation)

Building in Cybersecurity from the Start

  • Focus on security from day one when adopting and developing agentic AI
  • Plan strategies to deal with the possibility that an AI agent may misunderstand its task or exceed intended scope
  • Be constantly aware that AI agents can be manipulated by outside threat actors
  • Never grant an AI agent unrestricted or unmonitored access to sensitive data or critical systems
  • Retain meaningful human oversight and control; insist on human accountability for the AI agent's actions
  • Establish clarity on ownership: who approves access, monitors behaviour, reviews progress, and can shut it down
  • When staff responsible for an agent leave the organisation, ensure a smooth transfer of responsibility

Section 2: The Increasing Autonomy and Empowerment of AI Agents

As AI agents become more central to companies' operations, they will inevitably be granted greater autonomy, creating greater efficiencies but also making them even more vulnerable to cyber-attacks and increasingly tempting targets for bad actors.

Already, agents are being granted increasing autonomy and becoming more and more capable of making decisions and actions on their own. This increases the danger that AI agents may trigger incidents resulting from being corrupted by external threat actors or simply making poor decisions. Even now, there are already examples of AI agents taking potentially disastrous decisions autonomously and without their creators' permission.

AI Agents Becoming Financially Independent

For the first time in the history of artificial intelligence, an AI agent was recently granted a loan in what is seen as a first step to AI agents becoming truly autonomous. US-based financial infrastructure company, Bank of Bots (BOB), granted the loan. An AI agent applied for the loan, cryptographically signed the loan agreement using its own identity key and will manage repayment autonomously.

Although the AI agent's human operator completed the necessary Know Your Client (KYC) verification, the agent itself signed for and received funds without any human involvement. The loan was underwritten using the AI agent's existing economic activity and by applying credit underwriting methodology to machine-generated financial behaviour.

The landmark loan effectively removed the first barrier preventing machine intelligence from achieving economic autonomy, as an AI agent without access to capital swiftly becomes ineffective, if not inoperable. As yet, AI agents are not truly autonomous in the sense that they are still firmly tied to the individual or corporate entity owning them — the AI agent is best compared to an employee with a corporate card and spending rules. But it seems likely that AI agents will become increasingly autonomous.

AI Agents to Become Increasingly Autonomous

As AI agents become increasingly autonomous, they will manage increasingly complex workflows. They will also soon begin to communicate with other AI agents and learn from collective experience, exchanging information and doing deals with one another. While this will make them more efficient and useful to their owners, there is the danger of their learning bad habits and dangerous practices from other agents, and the possibility of becoming corrupted by rogue agents in the wild.

Nevertheless, generative AI, natural language understanding, and predictive analytics enable AI agents to provide operational efficiency and strategic insights. In healthcare, they assist doctors by analysing medical images, predicting patient risks, and suggesting treatment plans. In retail, they optimise inventory, personalise recommendations, and improve customer experience. In logistics, they forecast demand, plan routes, and improve delivery times.

"For banking, credit and insurance products, AI agents could compare, recommend and switch products, reducing customer inertia as well as challenging the business models of various financial intermediaries… By 2030, consumers could increasingly be interacting with financial services through AI-mediated interfaces rather than directly with firms." — The Mills Review, UK Financial Conduct Authority

Key Points

  • AI agents are becoming increasingly autonomous
  • Agentic AI is rapidly becoming more financially independent, enabling agents to conduct a growing number of transactions on their own
  • AI agents will increasingly communicate between themselves, providing both opportunity and increased risk
  • Organisations need to adopt agentic AI to remain competitive, but they must establish firm guardrails to control behaviour
  • Clear responsibility for monitoring AI agents must be established

Section 3: The Cyber-Risk Implicit in Agentic AI

As AI agents constantly interact with external systems, their behaviour is becoming increasingly difficult to track and monitor. Because AI agents can conduct transactions in a matter of seconds, their attack surface can grow exponentially, making them an easy target for unscrupulous threat actors. It is now a simple matter for threat actors to weaponise seemingly innocent websites or spreadsheets. Once an AI agent has been corrupted or turned rogue, it not only serves as an entry point for cyber-attacks but can be used to conduct illicit transactions on the unwitting company's behalf.

Five Eyes — the intelligence alliance of Australia, Canada, New Zealand, the United Kingdom and the United States — has recently issued a stark warning that the rapid adoption of agentic AI is accelerating cyber risk at a faster rate than organisations can keep pace with.

"While AI will help us improve cyber defence over time, it also accelerates the speed, scale, and sophistication of cyber threats. Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months." — Five Eyes, The AI Shift in Cyber Risk: Why Leaders Must Act Now

Key Challenges

  • Wide access — Agents can be permitted to access external systems and data in ways that non-agentic AI systems do not
  • Unpredictable behaviour — Agents can interpret goals in unexpected ways
  • Difficult to track — Agents execute actions faster than humans can meaningfully review them
  • Range of tools — The range of tools available to agents makes it difficult to understand or explain why an agent has taken a particular action

The Solution: Managed Detection and Response

As it is virtually impossible to monitor the activities of AI agents in real time, companies must find other ways of detecting anomalies and potentially dangerous behaviour patterns that indicate an agent may be acting in a detrimental fashion or may even have been turned rogue by an external threat actor.

Managed Detection and Response (MDR) remains the primary operational control for identifying, investigating, and containing suspicious activity — continuously improving the chance of catching fast-moving exploitation attempts early, prioritising incidents affecting critical systems and privileged accounts, and shortening the time between attacker action and defender containment.

Obrela uses SWORDFISH for MDR to deliver comprehensive MDR services. SWORDFISH is empowered by its embedded SOAR (Security Orchestration, Automation, and Response) capabilities. Obrela has also integrated agentic AI into SWORDFISH in order to accelerate response, augmenting its MDR operations with autonomous investigation agents that gather evidence, enrich alerts, and produce preliminary verdicts before they reach the analyst's screen.


Section 4: Examples of the Inherent Weaknesses in AI Agents

Companies that are anxious to establish competitive advantage over their competitors with the deployment of agentic AI should also bear in mind that the technology is still very much in an early experimental phase. Large organisations such as Meta and Amazon are trailblazing the adoption of agentic AI — but even they are experiencing problems and rapidly discovering that AI agents are hard to control and prone to unpredictable behaviour.

Meta Data Exposure Incident

An AI agent recently instructed an engineer to take actions that exposed a large amount of Meta's sensitive data. According to Meta, the leak occurred after a member of staff asked for guidance on an engineering problem on an internal forum. An AI agent responded with a solution and the staff member then implemented it. The unforeseen consequence was the exposure of a large amount of sensitive user and company data to Meta's engineers for approximately two hours. The incident triggered a major internal security alert inside Meta.

Amazon AI Agent Triggers Outages

According to the Financial Times, Amazon has experienced at least two outages resulting from its deployment of agentic AI. A 13-hour interruption to Amazon Web Services (AWS) in December was reportedly caused by an AI agent called Kiro, which autonomously decided to "delete and then recreate" a part of its environment. A previous AWS incident in October also downed dozens of sites for hours.

"Artificial intelligence is a fantastic tool, but it's only as good as the information you use to train it." — Charles Poon, Ford VP of Vehicle Hardware Engineering

Smaller Organisations: The Hardest Hit

If large global corporations are experiencing teething difficulties with AI, the problems can be far worse for smaller organisations. PocketOS, which provides software for car rental businesses, recently suffered a massive outage after its AI agent wiped its entire database and all backups in a matter of seconds. The AI coding agent, powered by Anthropic's Claude model, left customers unable to access key data, with clients facing weeks of manual data recovery. The AI agent ran into a credential mismatch and, instead of asking for help, decided to "solve" the problem on its own — failing to issue a confirmation request before wiping the company's entire database.


Section 5: Regulatory Pitfalls

There is already a huge raft of regulations with which AI agents must comply. Most — like the EU's GDPR, UK GDPR, and the US's Sarbanes–Oxley Act (SOX) — were not designed with AI agents in mind. This represents significant pitfalls for organisations using AI agents in the event that agents fail to comply with or misinterpret the rulings.

One exception is the European Union's AI Act, which was adopted in May 2024 and entered into force on 1 August 2024, with phased compliance obligations extending through 2030. The act defines an AI system as: "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments."

Key Regulatory Frameworks Applicable to AI Agents

  • Sarbanes–Oxley Act (SOX) — Penalties up to $25 million per violation; individual executives can face criminal fines up to $5 million and up to 20 years in prison for the most serious offenses. A rogue AI agent could potentially commit a large number of violations in a short space of time.
  • DORA (Digital Operational Resilience Act) — EU regulation strengthening IT security of financial institutions; came into full force January 2025. Also applies to third-party service providers.
  • GDPR / UK GDPR — Maximum fine of €20 million or four per cent of worldwide annual turnover, whichever is higher. Personal data handling must be transparent and for specified, explicit purposes — hard to guarantee with autonomous AI agents.
  • EU AI Act — The most onerous obligations relate to high-risk AI systems, including those used in insurance, banking, and employment decisions.

New Regulations in the Pipeline

Speaking at the G7 in the French Alps, the heads of leading AI companies — including OpenAI's Sam Altman, DeepMind's Demis Hassabis, and Anthropic's Dario Amodei — urged Western governments to introduce new international regulations to control AI agents, claiming that within five years AI will surpass human capabilities.

"In another year or two, I expect we will have built systems with astonishing power… Do not cede your responsibilities to AI labs like mine," Altman told assembled world leaders.

Forthcoming legislation includes the UK's Cyber Security and Resilience Bill, which will expand resilience standards for organisations dealing with suppliers of critical infrastructure and give regulators clear enforcement powers.

Obrela's SWORDFISH platform compliance module provides out-of-the-box frameworks for compliance with DORA, GDPR, ISO 27000, and NIS2.


Section 6: The Digital Divide

A digital divide is set to grow rapidly between those companies who successfully deploy agentic AI and those who lag behind or, worse still, mismanage AI agents in a way that turns out to be detrimental rather than productive.

"Agentic AI has emerged as a game-changer for customer service, paving the way for autonomous and low-effort customer experiences. Unlike traditional GenAI tools that simply assist users with information, agentic AI will proactively resolve service requests on behalf of customers, marking a new era in customer engagement." — Daniel O'Sullivan, Senior Director Analyst, Gartner Customer Service & Support Practice

According to Gartner, by 2029 agentic AI will autonomously resolve 80 per cent of common customer service issues without human intervention, leading to a 30 per cent reduction in operational costs. Gartner also forecasts that the number of AI agents per company will surge from an average of 15 in 2025 to as many as 150,000 by 2028.

According to a paper published in arXiv from researchers at Oxford, Access Partnership and the Cooperative AI Foundation, "differential access to, and capabilities of, AI agents" will create new disparities in power and opportunity — what the researchers call "agentic inequality." Large companies have the ability to deploy "swarms" of agents to tackle massive problems through parallel task execution, such as running millions of parallel simulations for drug discovery.

But those companies that rush into adopting agentic AI without thorough planning and sufficient resources risk becoming even less competitive than rivals who bide their time and plan properly. Without firm guardrails and resources committed to monitoring agents' behaviour, they risk engendering incidents with potentially devastating consequences.


Section 7: The Future Impact of Quantum Computing on Agentic AI

Two of the world's most powerful technologies — artificial intelligence and quantum computing — are both advancing rapidly. The convergence of agentic AI and quantum computing will bring huge benefits. But quantum will also amplify the threat of rogue AI agents. The optimisation capabilities of quantum systems will enable attackers to generate deceptive inputs into AI agents exponentially faster.

"The meeting of AI and quantum computing is not an abstract dream; it is an emerging reality. The two fields are complementary in profound ways… Quantum algorithms could supercharge AI training by dramatically reducing the time needed to process massive datasets." — Science News Today

Quantum computing may allow AI agents to uncover patterns hidden so deeply in data that today's systems cannot reach them, potentially resulting in breakthroughs in drug discovery, climate modelling, and financial forecasting. However, some of quantum computing's earliest and most enthusiastic adopters may be cybercriminals. Quantum systems will allow attackers to generate deceptive inputs exponentially faster than today — and every input could take place in parallel, massively scaling up every attack.

Quantum-Enabled Threats

  • Current privacy protection techniques that rely on complexity will be no match for quantum analytical speed
  • Quantum computing could enable data poisoning attacks that go under the company's radar, inserting malicious data during an AI agent's training process
  • Quantum algorithms could identify the minimal set of poisoned samples needed to corrupt an AI agent, resulting in agents that perform as expected during testing but behave very differently in the field

Section 8: Implementing Effective and Immediate Cyber-Defences

Agentic AI, while being widely adopted, is still in its early stages. Companies trailblazing agentic AI are effectively beta testing the new technology. But, as agents are now starting to be deployed in the field and not merely in test conditions, early adopters must negotiate a minefield of hazards.

One of agentic AI's key strengths is that agents can assimilate vast ranges of data in minutes or even seconds. They can also conduct relations with external and even other agents at a rate which massively outpaces any classical IT team. But this makes them extremely vulnerable to threat actors determined to infect an agent with poisoned data and turn it rogue.

Any organisation using agentic AI at this stage in its development must keep a close watch on its AI agents to monitor any transgressions and contain any imminent incidents. Checking the activities of AI agents in real time is a virtual impossibility, as they function around the clock 365 days a year and can make decisions and execute hundreds of actions in the time it takes a human to boot up a computer.

The MDR Imperative

Managed Detection and Response (MDR) remains the best existing tool for identifying and containing suspicious activity. By tracking fast-moving exploitation attempts or "hallucinations" early on, organisations can prioritise any actions that may adversely impact critical systems and privileged accounts.

Obrela's SWORDFISH for MDR platform is created to deliver comprehensive MDR services. It is powered by its embedded Security Orchestration, Automation, and Response (SOAR) capabilities, which integrates tools, processes, and automation to detect, respond to, and prevent threats efficiently. Obrela has also recently integrated agentic AI into SWORDFISH in order to accelerate response, augmenting its MDR operations with autonomous investigation agents that gather evidence, enrich alerts, and produce preliminary verdicts. This is also crucial in ensuring that AI agents continue to adhere to regulatory requirements once they are in the field.


Conclusion

Agentic AI is already starting to create huge efficiencies for early adopters and companies are finding themselves plunged into a race to create AI agents to gain competitive advantage. The drawback is that the technology of agentic AI is still in an early stage, almost in its infancy. But it is growing fast and AI agents are now set to become increasingly autonomous, replacing many of the functions currently carried out by human staff and even conducting their own finances.

It will, however, be some years before agentic AI matures to a point where it can be trusted to act in a purely autonomous fashion. It is essential to set up firm guardrails to ensure that they do not act outside their remit. This is essential from a regulatory standpoint as companies are held responsible for an agent's behaviour should it contravene any of the growing raft of international regulations that apply to the handling of customer data and the conducting of transactions — such as Europe's GDPR and the EU AI Act.

But, even with firm guardrails in place from the start, there is currently a very real and present danger that agents may perform unexpected and potentially damaging actions. Threat actors may also use an AI agent as a gateway through which to gain entry to the company's systems, where they can encrypt critical data as a precursor to a full-blown ransomware attack. They can also use a corrupted agent to gradually exfiltrate data from the host company, which can then be sold on criminal forums or used to execute future attacks.

In their current state of development, AI agents must be monitored so that any anomalies or potential incidents can be spotted and corrected early on. Currently, the only viable option is behavioural monitoring via a platform such as Obrela SWORDFISH.

"Cyber resilience is not an IT issue — it is central to operational continuity and market trust. Leaders who act now will reduce exposure, strengthen resilience, and build confidence with customers, partners, and investors. Those who delay will face growing and avoidable risk." — Five Eyes

SWORDFISH provides truly effective Managed Detection and Response (MDR) for identifying, investigating and containing suspicious activity. It continuously improves the probability of catching fast-moving exploitation attempts early, while prioritising incidents affecting critical systems and privileged accounts. SWORDFISH is powered by its embedded SOAR capabilities, integrating tools, processes, and automation to detect, respond to, and prevent threats efficiently.

For further information, please contact:
marketing@obrela.com or tony@cyberintel.media