Agentic AI cyber offense defense and shadow AI risks
Back to Blog
AI Security

Agentic AI in Cyber Offense, Defense & Shadow AI Risks

PublishedJune 9, 2026
Read time10 min read
Share
Originally reported viaOWASP Top 10 for LLM Applications 2025 · Gartner Emerging Tech: Security of AI Systems · NIST AI Risk Management Framework 1.0

Agentic AI — systems that autonomously plan, execute multi-step tasks, and interact with external tools and APIs — has moved from research into operational deployment on both sides of the cybersecurity divide in 2026. Offensive actors are using agents to compress the reconnaissance-to-payload timeline from days to hours. Defenders are deploying them to automate Tier-1 triage, execute playbooks, and respond to incidents faster than human analysts can. And in the middle sits shadow AI: employee-deployed agents operating entirely outside security governance.

How attackers are operationalising agentic AI

Red team exercises in Q2 2026 have demonstrated AI agents that autonomously identify network entry points, select and customise payloads based on detected host configurations, and execute lateral movement — all without human operator involvement. The most concerning pattern is adaptive evasion: agents that observe EDR telemetry responses and modify their own behaviour to stay below detection thresholds in near-real-time.

Source: OWASP Top 10 for LLM Applications 2025 — Agentic Update
OWASP's 2025 update to the LLM Top 10 identified Excessive Agency (LLM08) and Unbounded Consumption (LLM10) as the highest-risk agentic patterns. Agents granted broad tool permissions without human-in-the-loop controls represent a significant lateral movement risk in enterprise environments.

Defensive agentic AI: where it delivers value today

Furix customers deploying AI agents for SOC automation report 60–70% reduction in Tier-1 triage workload and 45% improvement in mean time to escalate within the first 90 days. Agents are effective at three tasks: alert enrichment (pulling context from threat intel, asset databases, and prior incidents), false positive closure (applying deterministic rules at machine speed), and playbook execution (running isolation, blocking, and notification steps without analyst involvement).

Shadow AI: the governance gap no one is measuring

A Furix 2026 survey found 71% of enterprise employees had used at least one unapproved AI agent or tool in the preceding 90 days. The risk is not just data exfiltration — shadow AI agents may be granted OAuth access to corporate systems, acting on behalf of employees with elevated permissions, executing actions that generate no traditional audit trail. The CISO's blind spot is that shadow AI operates at agent speed: thousands of API calls per hour that look like normal SaaS traffic.

Source: Gartner Emerging Tech: Security of AI Systems — Q1 2026
Gartner estimates that by 2027, 40% of enterprise data breaches will involve an AI agent as either an attack vector or an uncontrolled data exfiltration channel, driven primarily by ungoverned agentic deployments rather than sophisticated external attacks.
  • Log every tool call made by AI agents — treat agent tool calls as privileged command execution requiring audit trails.
  • Implement OAuth scope restrictions for all agents: an agent reading Confluence should not hold write or delete permissions.
  • Deploy network-level monitoring to detect AI service traffic and build a baseline of sanctioned vs. unsanctioned AI usage.
  • Create a tiered AI agent registry: fully approved, conditionally approved (with data restrictions), and prohibited.
  • Run a shadow AI discovery exercise — scan DNS, proxy, and OAuth consent logs for undiscovered AI service connections.
  • Require data classification checks before any agent is permitted to access repositories containing sensitive data.

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.