Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Meta’s new AI can shop for you. The question is whether anyone wants it to

Meta’s new AI can shop for you. The question is whether anyone wants it to

11 September 2026
Closing The Gap Between AI Ambition And Data Reality

Closing The Gap Between AI Ambition And Data Reality

11 September 2026
​Digital Finance Needs A New Kind Of Identity For AI-Driven Economies

​Digital Finance Needs A New Kind Of Identity For AI-Driven Economies

11 September 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Agentic AI Is The New Attack Surface
Innovation

Agentic AI Is The New Attack Surface

Press RoomBy Press Room11 September 20265 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Agentic AI Is The New Attack Surface

Ivan Mans, SecurityBridge Co-Founder, builds SAP cybersecurity software to keep critical business systems secure.

For most of its history, application security has assumed a clean line between the user and the application. A person makes a request, and the application validates and authorizes it before acting. We built our controls, authentication, input validation and change management around that boundary.

Agentic AI erases it. Autonomous agents now write code, call APIs and take actions on a user’s behalf with minimal human oversight. Rather than sitting at the perimeter waiting to be let in, they operate within trusted workflows, often with credentials and privileges granted for legitimate purposes.

That changes the security question entirely. The issue is no longer whether you can keep an attacker out. It’s whether you can account for what an agent already inside your systems is allowed to do—and prove it afterward.

Nowhere is this more consequential than in SAP, which runs the financials, payroll, supply chain and master data of most large enterprises. As SAP itself becomes an AI platform, with products such as Joule and embedded agents in S/4HANA and BTP, every new agent is a new privileged actor operating directly against the most valuable data a company holds.

The risk of an agent behaving unexpectedly inside a production ERP system isn’t theoretical. According to an April 2026 Cloud Security Alliance study, 53% of surveyed organizations said AI agents had exceeded their intended permissions.

Why The Perimeter Mindset Fails Here

Agentic systems introduce a class of risk that traditional perimeter defenses were never designed to handle. Three patterns stand out.

1. Injection moves inside the trust boundary. Prompt injection is becoming the new SQL injection. A malicious instruction smuggled into data an agent reads can redirect what that agent does from within a workflow your controls already trust.

2. Privilege escalation becomes ambient. An agent chaining API calls can assemble an effective level of access no single human was ever granted without any individual step looking abnormal.

3. The software supply chain extends into AI-generated artifacts. When agents write and configure code, your composition analysis must reason about components no human author ever reviewed.

The Hacker News noted in April 2026 that compromised SAP-related npm packages planted malicious configuration files that hijack AI coding agents. The report cited StepSecurity research that described this as “one of the first supply chain attacks to target AI coding agent configurations as a persistence and propagation vector.”

This isn’t the first time SAP’s move into AI has widened the attack surface. In 2024, Wiz researchers disclosed a set of flaws in SAP AI Core that let them execute arbitrary code, move laterally and reach customer data and cloud credentials.

None of these threats announce themselves at the network edge. Rather, they originate inside trusted workflows, which is precisely why application security—not network security—is the layer that matters most for agentic risk.

AppSec Controls Must Evolve

The good news is we’re not starting from zero. The disciplines we need already exist; they must be pointed at a new kind of actor.

Runtime application self-protection must monitor agent-initiated actions, not only human-driven sessions, and treat an autonomous caller as a first-class subject for real-time scrutiny. API security needs to assume that the most prolific, fastest and least predictable client is now an agent and apply least-privilege and behavioral baselining rules accordingly.

Software composition analysis must extend its reach to AI-generated and AI-configured code, closing the gap between what a human committed and what an agent produced. The organizations that come through this well wrap rigorous AppSec controls around their agents rather than relying on model guardrails.

That last point deserves emphasis. Model guardrails are necessary, but they constrain what an agent is told to do rather than what a compromised agent can access. VentureBeat cited research showing those guardrails can be bypassed in a majority of attempts under the right conditions, and any control an attacker can talk their way past isn’t a control you can take to an auditor.

Durable assurance comes from the surrounding application architecture: what data an agent can reach, what it’s permitted to change and whether every action it takes is observable and reversible.

Keep A Human In The Lead

This is where I’d push the industry’s favorite phrase a step further. “Human in the loop” has come to mean a person watching a process—present but passive. For any agentic AI touching production systems, watching alone isn’t enough. A human must be in the lead.

What does this look like operationally? The agent recommends and prepares, but a person authorizes consequential actions. That authorization is bound to the specific action approved, and a named human signs the audit trail. The agent does the work. Ultimately, the accountability stays human.

Pair that with a second principle: Let customers bring their own AI. The model should belong to the enterprise, the data should stay inside the enterprise’s perimeter and the customer should choose their provider. An agent you can’t inspect, running on data you’ve handed to someone else’s cloud, is the opposite of a defensible position. Sovereignty over the model and data is the foundation that makes everything auditable.

The Question To Ask Before You Deploy

Another thing: Boards have been asking the wrong question.

Board members who ask whether the organization is using AI tell you nothing about your exposure. The salient question is: Which decisions are we letting AI make in production, and who signs for them? If the answer is “We’re not sure” or “Everything,” the deployment isn’t ready.

Agentic AI is one of the most significant shifts enterprise software has seen, and its upside is significant. However, the layer that determines whether that upside is safe to capture is application security applied with discipline, extended to a new kind of actor and led by a human.

Treat your agents with the same rigor you’d demand of any privileged user, and you’ll be positioned to move fast without handing the keys to the workflow.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Ivan Mans
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Closing The Gap Between AI Ambition And Data Reality

Closing The Gap Between AI Ambition And Data Reality

11 September 2026
​Digital Finance Needs A New Kind Of Identity For AI-Driven Economies

​Digital Finance Needs A New Kind Of Identity For AI-Driven Economies

11 September 2026
Design Choices That Reduce User Friction And Digital Fatigue

Design Choices That Reduce User Friction And Digital Fatigue

11 September 2026
When Finance Leaders Break Their Own Rules

When Finance Leaders Break Their Own Rules

11 September 2026
The AI You Didn’t Know You Bought

The AI You Didn’t Know You Bought

10 September 2026
Vibe Hacking Lowered The Barrier To Entry For Attackers

Vibe Hacking Lowered The Barrier To Entry For Attackers

10 September 2026
Don't Miss
Trump’s Tariffs Will Make AI Data Centers More Expensive

Trump’s Tariffs Will Make AI Data Centers More Expensive

By Press Room4 April 2025

Donald Trump’s administration has gone all-in on AI: A day after his inauguration, the newly-elected…

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

27 December 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Agentic AI Is The New Attack Surface

Agentic AI Is The New Attack Surface

11 September 20262 Views
The AI writing debate is eerily similar to the one that rocked ancient Greece 2,700 years ago

The AI writing debate is eerily similar to the one that rocked ancient Greece 2,700 years ago

11 September 20261 Views
Design Choices That Reduce User Friction And Digital Fatigue

Design Choices That Reduce User Friction And Digital Fatigue

11 September 20260 Views
.999 and maxed out: California diesel prices overwhelm pump displays as supply crunch worsens

$9.999 and maxed out: California diesel prices overwhelm pump displays as supply crunch worsens

11 September 20261 Views

Recent Posts

  • Meta’s new AI can shop for you. The question is whether anyone wants it to
  • Closing The Gap Between AI Ambition And Data Reality
  • ​Digital Finance Needs A New Kind Of Identity For AI-Driven Economies
  • The betrayal behind the data-center backlash: AI promised to break the rules of class but is just rewarding them so far
  • Agentic AI Is The New Attack Surface

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Meta’s new AI can shop for you. The question is whether anyone wants it to

Meta’s new AI can shop for you. The question is whether anyone wants it to

11 September 2026
Closing The Gap Between AI Ambition And Data Reality

Closing The Gap Between AI Ambition And Data Reality

11 September 2026
​Digital Finance Needs A New Kind Of Identity For AI-Driven Economies

​Digital Finance Needs A New Kind Of Identity For AI-Driven Economies

11 September 2026
Most Popular
The betrayal behind the data-center backlash: AI promised to break the rules of class but is just rewarding them so far

The betrayal behind the data-center backlash: AI promised to break the rules of class but is just rewarding them so far

11 September 20261 Views
Agentic AI Is The New Attack Surface

Agentic AI Is The New Attack Surface

11 September 20262 Views
The AI writing debate is eerily similar to the one that rocked ancient Greece 2,700 years ago

The AI writing debate is eerily similar to the one that rocked ancient Greece 2,700 years ago

11 September 20261 Views

Archives

  • September 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.