Skip to main content
Why Aspiron
For candidates
Vacancies
CyberBytes
Resources
Contact Us
Group
Group
Why Aspiron
For candidates
Vacancies
CyberBytes
Resources
Contact Us

The AI Threat We Should Be Talking About Isn't a Rogue Agent, It's a Compromised One.

Written by: 
Amy McLean

The AI Threat We Should Be Talking About Isn't a Rogue Agent, It's a Compromised One.

Ask executives what worries them about AI security, and one concern comes up repeatedly: the rogue AI agent, an autonomous system that ignores its guardrails and starts doing things nobody expected. It's an understandable concern, but Jaye Tillson, CTO Security within HPE's Networking CTO organisation, believes there is another, more immediate risk we should be paying attention to.

"I'm not talking about AI breaking outside of its guardrails," he says. "I'm talking about somebody who has downloaded an agent that's doing some work for them, and someone piggybacks on the back of that agent and can go everywhere."

The problem isn't necessarily an agent going rogue. It's what happens when an AI system behaving exactly as designed is compromised or hijacked. An AI agent is also an identity, potentially with access to applications, APIs, data, cloud services, and other agents. If compromised, an attacker could inherit that access, with the added problem that an agent can operate autonomously and at machine speed.

‍

AI Is Lowering the Barrier to Entry

Tillson has spent more than 25 years working across manufacturing, Formula One, enterprise technology and cybersecurity, including serving as Field CTO at Zero Trust pioneer Axis Security before its acquisition by HPE. For him, one of the biggest changes brought about by generative AI isn't that attackers have suddenly become fundamentally different; it's that capabilities that once required considerably more expertise are becoming accessible to many more people.

Attackers can research targets, create convincing phishing campaigns, write and modify code, and automate repetitive tasks using readily available AI tools. Expertise hasn't disappeared, but less-skilled attackers can now attempt things that were previously much harder. Meanwhile, experienced attackers can use the same technology to operate faster and at greater scale.

‍

The Coming Patch Tsunami

There is another consequence of AI that Tillson believes organisations need to prepare for: a coming "patch tsunami". Anthropic's Project Glasswing offers an early indication of what this could look like.

Glasswing gives selected cyber defenders access to Claude Mythos Preview, a frontier AI model with particularly strong cybersecurity capabilities. In the first weeks of the programme, Anthropic and approximately 50 partners reported finding more than 10,000 high- or critical-severity vulnerabilities, with several participants increasing their bug-finding rate by more than ten times.

That's an extraordinary development for defenders. Vulnerabilities that might have remained hidden for years can potentially be discovered and fixed much faster. But finding the vulnerability is only the beginning. Somebody still has to verify it, develop and test a fix, release a patch, and ultimately deploy that patch across affected systems.

Anthropic's early experience suggests the bottleneck may already be moving. Historically, progress was constrained by how quickly vulnerabilities could be found. Increasingly, the constraint could become how quickly the industry can verify, disclose, and patch what AI discovers. That's the beginning of the patch tsunami.

For vendors, this could mean releasing security updates at a much greater rate. For customers, every patch potentially needs to be assessed, prioritised, tested and safely deployed. Vendors can test extensively, but they cannot reproduce every customer environment or interaction between applications, operating systems and legacy infrastructure.

If AI moves vulnerability discovery towards machine speed, remediation and patch management will have to evolve with it. Greater automation, better prioritisation and a clearer understanding of assets, dependencies and business risk will become essential.

‍

Zero Trust Didn't Disappear. It Became Operational.

While AI has dominated recent cybersecurity conversations, Zero Trust has become less visible as a marketing term. That doesn't mean organisations have stopped implementing it. In many ways, the opposite is happening.

Organisations are implementing least privilege, using identity and device context to make access decisions, segmenting networks and applications, and continuously evaluating risk. They simply don't necessarily call it a "Zero Trust project". The terminology is becoming less important as the principles become part of normal security architecture.

Tillson often uses a hotel key to explain the idea. His key gives him access to the lift, his floor, and his room. It doesn't open every room in the hotel because there is no reason for it to do so. That's Zero Trust in its simplest form: give an identity access to what it needs, and nothing more.

The important change is that the identity isn't necessarily human. It could be a user, device, workload, service account, or, increasingly, an AI agent.

‍

Increasingly, Attackers Don't Break In. They Log In.

Many modern attackers seek legitimate credentials, sessions, tokens, and identities that already have access to the resources they want. Once they obtain an identity, their activity can look remarkably similar to legitimate activity.

That becomes particularly important with AI agents. An agent may legitimately need access to several applications, datasets and services, but there is a danger that agents accumulate permissions in much the same way human users and service accounts historically have.

That's where Zero Trust becomes critical. Organisations need to know what identities exist, human and non-human, understand what they can access; and continuously ask whether that access is still required.

If an agent only needs access to three systems, why can it reach thirty? If it only needs read access, why can it write? If it normally accesses one dataset, what happens when it suddenly attempts to access something completely different? These aren't uniquely AI security questions. They are Zero Trust questions applied to a new class of identity.

‍

AI Security Needs to Be About More Than AI

AI security discussions frequently focus on protecting the model itself: prompt injection, model manipulation, hallucinations, data leakage, and guardrails. Those risks matter, but they are only part of the problem.

We also have to secure the agent's identity, the access it has been granted, the data it can reach, and the actions it is authorised to perform. An agent doesn't need to break its guardrails to become dangerous. If an attacker compromises it, they may simply be able to use the access the agent was legitimately given.

The technology may be new, but the principles aren't. Know what is connecting, understand its identity and context, give it the minimum access required, continuously verify that access and monitor its behaviour. Most importantly, assume that any identity, including an AI agent, could eventually be compromised.

‍

There Is Good Reason for Optimism

None of this means organisations should be frightened of AI. Project Glasswing itself demonstrates the opportunity: finding vulnerabilities that have remained hidden and helping vendors fix them before attackers can exploit them is exactly the sort of advantage we should want AI to give defenders.

AI can analyse huge volumes of information, identify patterns humans might miss, automate repetitive work, and respond at speeds that aren't possible manually. But it doesn't remove the need for good security architecture; it makes that architecture even more important.

We've spent years learning how to secure human identities, devices, applications, and workloads. Now we're adding another identity: the AI agent. We should extend the same principles to agents from the beginning rather than creating another generation of overprivileged identities.

The AI agent itself isn't inherently the threat. The real question is what happens when that agent is compromised, what it can access, how quickly it can act, and how much trust we chose to place in it.

Tablet of Contents

TOC Element

Recent Posts

Continuous Never Existed: Cytix Co-Founder Ben Armstrong on Why the Rebrand Isn't Really a Pivot

September 15, 2026

Securing the Agentic Workforce: The EDR for AI Agents - Evoke Security

August 28, 2026

AI in Cybersecurity: The AI vs AI Arms Race Reshaping Security in 2026

August 5, 2026

North America

+1 315 556 2555

United Kingdom

+44 20 4530 6936

Company

Why Aspiron?
For Candidates
CyberBytes

Useful Links

Resources
Contact Us
Aspiron Group

Support

Privacy Policy
Cookies Policy
Terms & Conditions

North America

+1 315 556 2555

United Kingdom

+44 20 4530 6936

© {{year}}  Aspiron Search Limited – All rights reserved