Cyberbriefdaily today publishes a new report: The Opportunities and Pitfalls of Agentic AI, free of charge for its readers. The 19-page report, sponsored by cybersecurity company, OBRELA, offers an extensive analysis of the current role AI agents are already playing and how they are evolving at a pace that is faster than organisations' abilities to monitor and control them.

Read the Full 19-Page Report →

Agentic AI is Already Transforming B2B Commerce

According to research giant Gartner, by 2028 90 per cent of business-to-business (B2B) buying will be AI agent intermediated, pushing over $15 trillion of B2B spend through AI agent exchanges. But AI agents are already becoming increasingly autonomous and capable of making decisions their creators may not have intended.

An AI agent was, for example, recently granted a loan by US-based financial infrastructure company, Bank of Bots (BOB). The AI agent applied for the loan, cryptographically signed the loan agreement using its own identity key and will manage repayment autonomously.

When AI Agents Go Rogue

There are, however, an increasing number of examples of AI agents going "rogue" and breaking out of the guardrails imposed by their owner to make decisions and carry out actions not envisaged or desired by their creators. Even large IT-centric organisations are finding their AI agents have a tendency to act autonomously with highly negative results. Amazon, for example, experienced a 13-hour interruption to cloud computing platform, Amazon Web Services (AWS)'s operations caused by an AI agent, Kiro, which autonomously decided to "delete and then recreate" a part of its environment.

For smaller organizations, with fewer resources, an agent going rogue can have devastating consequences. PocketOS, which provides software for car rental businesses, recently suffered a massive outage after its AI agent wiped its database and all backups in a matter of seconds. The AI coding agent, powered by Anthropic's leading Claude model, left customers unable to access key data, with the rental business's clients facing weeks of manual data recovery and with newer users hit hardest due to missing recent records. The AI agent ran into a credential mismatch and, instead of asking for help, it autonomously decided to "solve" the problem on its own, instantly wiping the company's entire database, although it subsequently issued an apology.

Regulatory Exposure: The SOX Risk

Even agents that do not turn rogue in this manner, can inadvertently land their owners into deep trouble with regulatory authorities. While governments appear slow or even reluctant to draft AI-specific legislation, there is a whole raft of existing regulation that also applies to AI agents.

The Sarbanes–Oxley Act (SOX), for example, is a United States federal law that mandates certain practices in financial record keeping and reporting for corporations. The penalties for failing to comply with SOX are potentially severe – up to $25 million per violation. Individual executives can face criminal fines up to $5 million and up to 20 years in prison for the most serious offenses. It is entirely possible that a poorly trained or overly creative AI agent could potentially commit a large number of regulatory violations in a short space of time, leaving its corporate owners vulnerable to prosecution.

Cybercriminals Are Weaponising AI Agents

Cybersecurity is also a key concern for companies that deploy AI agents. As well as agents turning rogue of their own volition, cybercriminals are now developing new ways of turning agents rogue. These range from something as simple as a weaponized spreadsheet containing seemingly harmless data designed to attract AI agents. Once they have established control of an agent without the owner's knowledge, they can gain access to the company's system, steal critical data and also install ransomware.

How to Detect and Contain Rogue AI Agents

In order to spot rogue agents, companies need to monitor their agents constantly. This is immensely challenging, as AI agents operate 24/7, often executing hundreds of actions in a matter of seconds. Managed Detection and Response (MDR) remains the primary operational control for identifying, investigating, and containing anomalous activity, catching fast-moving exploitation attempts early and spotting potentially rogue activities on the part of AI agents. OBRELA, for example, augments its MDR operations with autonomous investigation agents that gather evidence, enrich alerts, and produce preliminary verdicts, before they reach the analyst's screen. OBRELA's agentic AI is designed to significantly reduce investigation time for tier-one alerts, accelerating the path from detection to validated response.

As the attached report indicates, the real digital divide will not be between those organizations which adopt agentic AI early and those who lag behind, but between those organizations that implement strict AI agentic guidelines together with effective cyber-defences.

Read the Full 19-Page Report →

Sections cover rapid adoption, rogue agent incidents, regulatory risk, the digital divide, quantum threats, and MDR defences — free to read.