Security chiefs know they must use artificial-intelligence agents to defend against AI-powered hackers. Letting those agents operate on their own is another story.
Less than a quarter of security, technology and business leaders globally say they feel comfortable deploying agents without human controls, according to a survey by consulting giant PricewaterhouseCoopers.
One concern among current and former chief information security officers is that the agents can magnify weaknesses already lurking in corporate systems, making decisions and acting on them far faster than humans can, with potentially disastrous outcomes. A shortage of workers skilled in overseeing AI systems, and general distrust of an unproven technology, also factor in.
"They inherit every permission configuration mistake we've ever made and they operate at machine speed," said Melina Scotto, founder and executive vice president of consulting firm Mastin and Associates, and a former CISO at Hilton Worldwide.
The results of the survey, based on responses from nearly 4,000 corporate executives, offer a glimpse into the real-world complexities behind the belief that companies can fight AI-powered hackers with AI of their own.
"CISOs are cautiously advancing AI agent integration, but the journey to fully autonomous AI agents for cyber defense will happen in stages," Avinash Rajeev, global cyber, data and technology risk leader at PwC's U.S. business.
For now, most companies are limiting autonomous agents to routine tasks with predictable outcomes, he said. Among them, analyzing threat intelligence, quarantining dangerous emails, removing malware and fixing affected systems.
"Few security leaders I talk to are ready to give autonomous agents unsupervised authority over security decisions," said Kevin Gosschalk, founder and chief executive of Arkose Labs, a cybersecurity and fraud-prevention firm.
Part of their hesitation stems from AI agents' implacable, yet morally numb pursuit of their goals. Nick Kakolowski, a senior research director at cyber-risk consulting firm IANS Research, said autonomous agents don't possess the same intuitive boundaries as their human co-workers.
"We've seen indications of capabilities like agents potentially running phishing campaigns to do competitor research because they determined it was the best way to complete the assigned task," he said.
Corporate security controls are typically designed around systems that behave in expected ways, said Carlos Pignataro, program director at the Conference Board's CISO Council, a cyber industry group. Agents throw a monkey wrench into that model as their behavior is largely unpredictable.
"So CISOs are restricting autonomy now, and their highest concern is the agents inside their own enterprise," he said.
Put another way, autonomous agents need time to learn the ropes.
"Think about bringing on a new employee; you don't hand them the keys on Day One," said Martin Bally, chief AI security strategist and executive adviser at cyber startup Glow Security. Typically new workers are given access gradually and earn trust over time. "Autonomous agents should be treated the same way," said Bally, a former CISO at Campbell's.
George Gerchow, chief security officer at Bedrock Data, a data security, governance and management platform, said he runs much of the firm's security operations center through AI agents -- with more than 60% of a given incident worked out before a human steps in.
"On Day One a human approved every single step, and we gave up approvals one at a time only after the agent proved itself on that step," he said. Since most cyber teams haven't done that work yet, he said, deploying fully autonomous agents can feel like jumping off a cliff.
"You don't flip autonomy on. You hand it over one decision at a time after the agent has earned that decision," Gerchow said.