
A chatbot can give a bad answer. An AI agent can send it, execute it or use credentials to act on it. That turns model risk into operational security.
A chatbot that gives a wrong answer may confuse someone. An AI agent that performs the wrong action can modify a database, send a message, execute code or use credentials it should never have touched. That difference turns agent security from a variation of model safety into an operational security problem.
In 2026, NIST launched work specifically focused on AI-agent standards and collected input on their security. The emerging conclusion is straightforward: much of traditional cybersecurity still applies, but it has to be adapted to systems that can plan and act autonomously.
A language model on its own produces output. An agent becomes operational when it can call tools: browsers, APIs, terminals, databases, email, calendars, CRMs or payment systems. Every tool adds capability, and every capability adds an attack surface.
NIST emphasizes precisely this combination. Some risks are familiar software problems — weak authentication, vulnerable dependencies, poor credential handling — while others emerge because probabilistic model output can determine which function gets called and with what parameters.
That changes the security question. It is not enough to ask whether a model “knows” dangerous information. We have to ask what it can do with the information it receives.
One of the best-known risks is prompt injection. An agent browsing the web or reading documents can encounter text deliberately written to alter its behaviour. To a human, a hidden sentence in a page is just text. To a system that treats language as instruction, it can become a command.
The danger increases when the agent has access to private data or operational tools. A malicious document may try to convince it to send information outside the organization, ignore a policy or misuse an available tool.
There is no single definitive protection. Systems need separation between instructions and content, validation of actions, limits on available tools and specific controls for high-impact operations.
Traditional software distinguishes users from applications. Agents complicate that model because they act on behalf of someone while potentially operating without an immediate human request. Identity and authorization are therefore becoming central issues in agentic AI.
On September 29, 2026, the NIST National Cybersecurity Center of Excellence published a summary of comments on software and agentic-AI identity and authorization. The core question is simple: a system should be able to identify the agent as a distinct actor, know on whose behalf it is operating and understand which permissions have been delegated to it.
Giving the agent the user’s full credentials is the easiest solution and often the worst one. An agent should receive only the privileges required for the task, ideally temporary and revocable. That is the principle of least privilege, applied to software that dynamically decides how to use those privileges.
A sound architecture can distinguish at least three classes of action. Some are low risk, such as reading non-sensitive information or preparing a draft. Some are reversible, such as updating an internal record. Others are high impact: making payments, deleting data, publishing content or sending confidential information.
The higher the impact, the stronger the confirmation requirement should become. The goal is not to eliminate autonomy, but to define boundaries of autonomy. An agent might be allowed to prepare a bank transfer without being allowed to execute it, or modify code in a test environment without deploying it to production.
This becomes even more important with autonomous and persistent AI agents, which may continue working without a person watching every step.
An autonomous system needs to leave a readable trace of its actions. It is not enough to know that a file was deleted. We need to reconstruct the agent’s objective, the information it received, the tools it used and the rule that authorized the operation.
Traceability matters for security, but also for accountability. When an agent becomes part of a business process, the answer to “who did this?” cannot simply be “the AI.” There has to be an intelligible chain of delegation.
The most important point is that a secure agent is not created by selecting the most reliable model. Security depends on the whole system: authentication, permissions, tool isolation, policies, supervision, logging, credential management and the ability to stop activity.
Agentic AI makes an old principle of computing impossible to ignore: capability and risk rise together. The more a system can do, the less we can afford to base security on the hope that it will interpret every instruction correctly.