2025: The Rise of Agentic AI and the New Cybersecurity Boundary
If 2023 was the year people discovered what generative AI could create, and 2024 was the year AI moved into business workflows, 2025 marked a deeper shift: AI increasingly began moving from assisting with work toward performing work.
This article is Part 3 of From Generative AI to AI Agents: Why the Next Five Years Will Change Cybersecurity.
This transition is commonly described through the term agentic AI.
The difference is important.
A traditional generative AI system primarily responds to a request.
An AI agent can be designed to pursue a goal through multiple steps, potentially using tools, retrieving information, evaluating results, and taking actions along the way.
The interaction begins to change from:
Human → Prompt → AI → Response
toward:
Human → Goal → AI Agent → Tools → Actions → Results
That creates a completely different cybersecurity question.
The question is no longer only:
What information can AI access?
It increasingly becomes:
What authority does AI have to act?
This is the point where AI and cybersecurity become deeply connected.
From Generative AI to Agentic AI
The evolution did not happen overnight.
It followed a progression.
Generative AI
AI generates information.
AI Assistant
AI helps a human perform a task.
AI-Integrated Workflow
AI becomes part of an existing business process.
AI Agent
AI can pursue a goal through multiple steps and potentially interact with tools.
Multi-Agent System
Multiple agents can potentially coordinate tasks.
The boundaries between these categories are not always strict.
Different products use the word "agent" differently.
Some systems require human approval before every significant action.
Others can execute more independently.
Therefore, agentic AI should be understood as a spectrum of autonomy rather than a single technical architecture.
What Makes an AI Agent Different?
A simple chatbot might operate like this:
Question → Model → Answer
An agentic workflow can look more like:
Goal → Plan → Retrieve information → Use a tool → Evaluate result → Take another action → Complete task
The system may repeat this process several times.
The important difference is not simply that the AI is more intelligent.
It is that the system has a mechanism for acting within an environment.
That environment could contain:
APIs
Applications
Files
Databases
Browsers
Development tools
Business systems
Cloud services
Other AI systems
The security boundary therefore expands.
AI Became an Actor
This is one of the most important concepts in the series.
In earlier AI workflows, the primary actors were humans.
The AI generated information.
The human acted.
With agentic systems, the AI can potentially become another actor in the environment.
Consider:
Human → AI Agent → CRM → Customer Record
The agent may retrieve information.
It may create information.
It may update information.
It may initiate a workflow.
It may communicate with another service.
The AI is no longer simply observing information.
It may participate in changing the environment.
That makes identity, authorization, monitoring, and accountability much more important.
The New Question: What Can the Agent Do?
When evaluating a conventional application, organizations already ask:
What data does it access?
What permissions does it have?
What APIs does it use?
What systems does it connect to?
The same questions apply to AI agents.
But there is another layer.
An agent may dynamically decide which available tools to use based on the task.
Therefore organizations need to understand not only:
What can the system access?
but also:
What actions can it initiate?
Tool Use Changes Everything
Tools are one of the most important parts of agentic AI.
An agent can potentially be connected to tools such as:
Search
Browser
Database
CRM
Email
Calendar
File system
Code execution
Internal APIs
Cloud services
Business applications
The agent's usefulness can increase dramatically when it has access to tools.
But every tool creates another security boundary.
Consider a simple example.
An AI agent that can only read a knowledge base has one level of authority.
An agent that can:
read the knowledge base
create CRM records
send emails
modify customer information
execute code
has a much broader authority.
The second system requires significantly more careful security design.
Capability Is Not the Same as Authorization
This distinction is critical.
An agent may technically be capable of performing an action.
That does not mean it should be authorized to perform that action.
For example:
An agent may have access to an email API.
But perhaps it should only be allowed to draft messages.
It may have access to a CRM.
But perhaps it should only read records.
It may have access to a database.
But perhaps it should not modify production data.
This leads to an important principle:
AI capability should not automatically become AI authority.
Security architecture determines the difference.
Identity Becomes a First-Class Security Question
Traditional systems have identities.
Users have accounts.
Applications have service identities.
Machines may have identities.
AI agents introduce another possibility:
Agent identity.
An organization may need to distinguish between:
the human requesting an action
the application hosting the agent
the AI agent performing the task
the service identity used to access a system
This becomes important when investigating activity.
Suppose a customer record changes.
A security team may need to determine:
Which human initiated the request?
Which application handled it?
Which agent performed the action?
Which credentials were used?
Which tool executed the change?
What instructions caused the action?
The more autonomous the workflow becomes, the more important this chain of attribution becomes.
Delegated Authority
Another important concept is delegated authority.
An employee may authorize an AI system to perform a task on their behalf.
For example:
"Review these customer tickets and prepare responses."
The agent may then perform multiple operations.
But what exactly did the employee authorize?
Did they authorize:
reading tickets?
drafting responses?
sending responses?
modifying customer records?
creating refunds?
escalating cases?
These are not equivalent permissions.
Therefore an AI system needs boundaries around delegated authority.
Least Privilege for AI Agents
The principle of least privilege becomes even more important in an agentic environment.
An agent should have only the permissions necessary for its intended role.
Imagine three agents.
Research Agent
May:
search information
read approved sources
summarize results
Customer Support Agent
May:
read assigned support tickets
access approved customer information
draft responses
Operations Agent
May:
interact with approved operational systems
perform specific workflow actions
update designated records
Giving all three agents administrative access would unnecessarily expand the security boundary.
The principle is straightforward:
An agent should not receive broad access simply because broad access makes automation easier.
Memory Creates Another Security Layer
Agentic systems may use memory or persistent context to maintain information across interactions.
Memory can improve usefulness.
An agent can potentially remember:
previous tasks
preferences
context
decisions
historical information
But memory also introduces security considerations.
Questions include:
What information is stored?
How long is it retained?
Who can access it?
Can untrusted information enter memory?
Can incorrect information influence future decisions?
Can one task contaminate another?
Can sensitive information persist longer than intended?
This is why memory should be treated as part of the security architecture rather than simply a convenience feature.
Untrusted Information Can Influence AI
AI agents often need information from external sources.
That could include:
websites
documents
emails
tickets
knowledge bases
databases
search results
Not all information is trustworthy.
A document may contain malicious instructions.
A webpage may contain text designed to influence the agent.
An email may attempt to manipulate the workflow.
This creates security concerns around instruction handling and prompt injection.
The fundamental issue is:
The agent must distinguish between information it should process and instructions it is actually authorized to follow.
That is easier to describe than to implement.
Prompt Injection Becomes More Serious When Agents Can Act
Prompt injection is not limited to agentic AI.
But the consequences can become more significant when an AI system has access to tools.
Consider two systems.
System A
A malicious instruction causes an AI to produce an incorrect answer.
The human notices the problem.
System B
A malicious instruction influences an AI that can access a business system.
The agent follows the instruction and performs an action.
The second scenario has a different security profile.
The key factor is not simply the AI model.
It is the authority surrounding the model.
The Security Boundary Moves From the Model to the System
This is one of the most important lessons of agentic AI.
It is easy to think:
"We need to secure the AI model."
That is necessary, but insufficient.
The organization also needs to consider:
the model
prompts
context
memory
tools
APIs
identities
permissions
endpoints
applications
data
monitoring
human oversight
An AI agent is a system.
Its security therefore depends on the entire system around it.
Agentic AI and Endpoints
At first glance, AI agents may appear unrelated to endpoint security.
They are not.
Employees may access agents through:
laptops
desktops
browsers
development environments
terminals
business applications
Agents may also interact with systems that eventually affect endpoints or endpoint-related workflows.
The endpoint remains one component of the larger environment.
This reinforces a broader principle:
AI security does not eliminate endpoint security. It adds another layer to the security architecture.
Endpoint Visibility Still Matters
Consider an employee using an AI development agent.
The agent may interact with:
source code
local files
terminals
development tools
APIs
repositories
If the endpoint itself is compromised, the AI workflow can potentially be affected.
Similarly, if credentials stored or used on the endpoint are compromised, access to connected services may also be affected.
Therefore businesses still need to understand:
which endpoints exist
which users operate them
what security information is available
what vulnerabilities exist
what activity requires attention
AI does not replace endpoint visibility.
Vulnerability Management in the Agentic Era
Agentic systems also introduce new dependencies.
An agent may rely on:
models
libraries
APIs
connectors
plugins
external services
business applications
Each component can introduce security considerations.
But organizations still have the same fundamental vulnerability-management problem:
Where are our weaknesses?
Vulnerability management therefore remains a foundational security discipline even as AI architectures become more advanced.
Threat Detection Must Follow the New Activity
Traditional security monitoring focuses heavily on user and system activity.
Agentic systems introduce another type of activity.
An agent may:
retrieve information
invoke APIs
access applications
create records
execute tasks
communicate with services
Unusual behavior may therefore involve an agent rather than a conventional user.
Security teams may need to ask:
Is this expected?
Is the agent operating within its intended scope?
Is the volume unusual?
Is the destination unusual?
Is the sequence of actions unusual?
Did an unexpected tool become involved?
This does not mean every unusual agent action is malicious.
It means unusual activity may warrant investigation.
Security Monitoring Becomes More Important
As the environment becomes more automated, visibility into activity becomes increasingly valuable.
A security platform needs to help organizations understand what is happening across the environment.
For example:
Endpoint → User → Application → AI Agent → Tool → Business System → Data
The more connections involved, the more useful contextual security information becomes.
Alerts Are Not the Same as Incidents
This distinction should remain clear.
An unusual agent action may generate a security alert.
That does not automatically mean a confirmed security incident has occurred.
The appropriate workflow may be:
Monitoring → Potential Security Event → Alert → Investigation → Decision → Appropriate Action
The goal of security monitoring is not simply to generate more alerts.
It is to help security teams understand meaningful events.
Human Oversight Still Matters
Increasing AI autonomy does not necessarily mean humans disappear.
Different workflows can use different levels of human oversight.
Human approval
The agent proposes an action.
A human approves it.
Human supervision
The agent performs routine work.
A human supervises the overall workflow.
Restricted autonomy
The agent can act independently within clearly defined boundaries.
Greater autonomy
The agent has broader authority to perform tasks.
The appropriate model depends on the organization, the risk of the task, and the controls surrounding the system.
There is no universal autonomy level that applies to every business process.
The Agentic Attack Surface
Traditional applications already have attack surfaces.
Agentic systems add additional dimensions.
A simplified view is:
Model
How is the model used?
Instructions
What instructions influence it?
Context
What information does it receive?
Memory
What information persists?
Identity
Which identity does it operate under?
Tools
What tools can it invoke?
Permissions
What actions are authorized?
APIs
Which external systems can it access?
Data
What information can flow through the system?
Human Oversight
Where is human approval required?
Monitoring
Can activity be observed and reconstructed?
These layers form a much larger security architecture.
Why Agentic AI Changes Cybersecurity Strategy
The traditional security mindset often begins with:
Protect users and systems.
Agentic AI adds:
Protect automated actors.
That means organizations increasingly need to understand not just:
users
devices
applications
but also:
AI systems
agents
tools
automated workflows
delegated permissions
This is a significant expansion of the security model.
The Rise of Multi-Agent Systems
Once organizations have one useful AI agent, it is reasonable to imagine specialized agents working together.
For example:
Research Agent → Analysis Agent → Operations Agent → Business System
This can create efficiency.
It can also create a chain of dependencies.
If one agent is compromised, manipulated, or incorrectly configured, its output may influence another agent.
The security question therefore becomes:
Can we trust the entire chain?
Agent-to-Agent Communication
Multi-agent systems introduce another boundary:
Agent → Agent
The receiving agent needs to know:
Who sent the message?
Is the sender trusted?
What authority does the sender have?
Is the information trustworthy?
Is the requested action permitted?
Can the message be manipulated?
These questions are still developing as agentic architectures evolve.
But the underlying cybersecurity principles are familiar:
Identity.
Authentication.
Authorization.
Integrity.
Monitoring.
The Agent Supply Chain
Modern software already depends on supply chains.
Applications rely on:
libraries
packages
APIs
cloud services
third-party components
Agentic systems can introduce another type of dependency chain.
An agent may depend on:
a model
an orchestration framework
tools
connectors
external APIs
plugins
data sources
other agents
This means security teams increasingly need to understand not only what an organization operates directly, but also what external components its automated workflows depend on.
The Security Platform Becomes More Important
This is where the broader cybersecurity platform becomes critical.
AI agents do not operate in a vacuum.
They operate inside an organization's technology environment.
That environment still includes:
Endpoints
What devices exist?
Endpoint Visibility
What can be understood about those devices?
Monitoring
What is happening over time?
Vulnerabilities
Where are the weaknesses?
Threat Detection
What activity may represent a potential threat?
Security Alerts
What requires attention?
Security Monitoring
How do these signals fit together?
These capabilities form part of the foundation on which newer AI-specific security controls can operate.
AI Security Does Not Mean Forgetting Basic Security
There is a tendency to think that the rise of AI requires completely new cybersecurity thinking.
Some things do change.
But many fundamentals remain exactly the same.
Organizations still need:
strong identity controls
least privilege
secure endpoints
vulnerability management
monitoring
threat detection
appropriate alerting
investigation
secure configurations
controlled access to data
AI adds another category of systems that must operate within those security principles.
The Most Important Question Is Authority
The central question of agentic AI is not:
How intelligent is the model?
A more important security question is:
What authority does the system have?
A highly capable model with no access to sensitive systems may have limited operational impact.
A less capable system with broad permissions could potentially create significant risk.
Therefore AI security is not only a model problem.
It is an authority problem.
Capability, Connectivity, and Authority
A useful framework is to think about three dimensions.
Capability
What can the AI system understand or generate?
Connectivity
What systems and information can it access?
Authority
What actions can it perform?
As each dimension increases, the security architecture becomes more important.
For example:
High capability + low authority
may represent an assistant that provides recommendations.
High capability + high connectivity + high authority
represents a much more consequential system.
This is why security controls need to grow alongside AI autonomy.
2025 Changed the Question Again
The progression now looks like this:
2023
What information are we giving AI?
2024
What systems can AI access?
2025
What can AI do?
That third question is the beginning of a much larger security conversation.
Because once AI can act, organizations need to understand:
who authorized it
what permissions it has
what tools it can use
what data it can access
what it actually did
whether the behavior was expected
how the activity can be investigated
From Agents to the Agentic Enterprise
The next stage is not necessarily one powerful AI agent.
It may be an organization with many specialized agents.
One agent handles research.
Another handles customer support.
Another assists developers.
Another analyzes financial information.
Another coordinates workflows.
Another monitors systems.
This creates an agentic enterprise.
And that brings us to 2026.
2026: The Agentic Enterprise
The next article in this series examines the emerging agentic enterprise.
The focus will shift from:
How do we secure one AI agent?
toward:
How do we secure an organization in which many AI-enabled systems participate in business operations?
That introduces questions around:
agent identity
delegated authority
permissions
tool access
monitoring
human oversight
agent-to-agent communication
endpoint security
vulnerability management
security operations
organizational governance
The security boundary becomes the entire digital environment.
Conclusion
2025 represents an important stage in the evolution from generative AI toward autonomous systems.
AI increasingly moved beyond producing answers and toward participating in multi-step workflows.
The important change was not simply better models.
It was agency.
An agent can potentially:
plan
retrieve
reason
use tools
interact with applications
perform actions
evaluate results
continue working toward a goal
That creates enormous potential for automation.
It also creates a larger security boundary.
The organization now needs to think about AI systems as participants in the digital environment.
They may have identities.
They may have permissions.
They may access data.
They may use tools.
They may interact with other agents.
They may perform actions.
And those actions need appropriate controls and visibility.
This is why the future of cybersecurity cannot be separated from the future of AI.
The more authority we give automated systems, the more important security architecture becomes.
The question is no longer simply:
"Can AI help our employees?"
It is:
"Can we securely control what AI is allowed to access, what it is allowed to do, and understand what it actually did?"
That question leads directly into the agentic enterprise.
Continue with Part 2: 2024 or return to the series introduction.
Control What AI Is Allowed to Do
As agents gain tools and authority, identity, monitoring, threat detection, and endpoint security become part of the security foundation.
No credit card required.
Related DotlyGuard topics
Series Introduction
From generative AI to AI agents — why the next five years change cybersecurity.
Part 1: 2023 Generative AI Revolution
How generative AI became mainstream and introduced the first AI security lessons.
Part 2: 2024 AI Business Workflow
How AI moved into applications, data, and everyday workflows.
Endpoint Security
Protect devices where people and agents still intersect.
Endpoint Visibility
Understand devices and security-relevant context.
Endpoint Monitoring
Observe endpoint conditions as automated activity increases.
Security Monitoring
Correlate activity across users, endpoints, applications, and automated systems.
Threat Detection
Identify unusual activity that may require investigation.
Vulnerability Management
Find weaknesses across systems agents and people depend on.
Endpoint Security Alerts
Surface information that may require attention.
Series: From Generative AI to the Agentic Enterprise
Introduction: From Generative AI to AI Agents
Part 1: 2023: The Generative AI Revolution
Part 2: 2024: When AI Entered the Business Workflow
Part 3: 2025: The Rise of Agentic AI and the New Cybersecurity Boundary (this article)
Part 4: 2026: The Agentic Enterprise
Part 5: 2027: The Multi-Agent Organization (forward-looking scenario)
Part 6: 2028: The AI-Native Business (forward-looking scenario)