SERIES · PART 3

2025: The Rise of Agentic AI and the New Cybersecurity Boundary

If 2023 was the year people discovered what generative AI could create, and 2024 was the year AI moved into business workflows, 2025 marked a deeper shift: AI increasingly began moving from assisting with work toward performing work.

This article is Part 3 of From Generative AI to AI Agents: Why the Next Five Years Will Change Cybersecurity.

This transition is commonly described through the term agentic AI.

The difference is important.

A traditional generative AI system primarily responds to a request.

An AI agent can be designed to pursue a goal through multiple steps, potentially using tools, retrieving information, evaluating results, and taking actions along the way.

The interaction begins to change from:

Human → Prompt → AI → Response

toward:

Human → Goal → AI Agent → Tools → Actions → Results

That creates a completely different cybersecurity question.

The question is no longer only:

What information can AI access?

It increasingly becomes:

What authority does AI have to act?

This is the point where AI and cybersecurity become deeply connected.

From Generative AI to Agentic AI

The evolution did not happen overnight.

It followed a progression.

Generative AI

AI generates information.

AI Assistant

AI helps a human perform a task.

AI-Integrated Workflow

AI becomes part of an existing business process.

AI Agent

AI can pursue a goal through multiple steps and potentially interact with tools.

Multi-Agent System

Multiple agents can potentially coordinate tasks.

The boundaries between these categories are not always strict.

Different products use the word "agent" differently.

Some systems require human approval before every significant action.

Others can execute more independently.

Therefore, agentic AI should be understood as a spectrum of autonomy rather than a single technical architecture.

What Makes an AI Agent Different?

A simple chatbot might operate like this:

Question → Model → Answer

An agentic workflow can look more like:

Goal → Plan → Retrieve information → Use a tool → Evaluate result → Take another action → Complete task

The system may repeat this process several times.

The important difference is not simply that the AI is more intelligent.

It is that the system has a mechanism for acting within an environment.

That environment could contain:

  • APIs

  • Applications

  • Files

  • Databases

  • Browsers

  • Development tools

  • Business systems

  • Cloud services

  • Other AI systems

The security boundary therefore expands.

AI Became an Actor

This is one of the most important concepts in the series.

In earlier AI workflows, the primary actors were humans.

The AI generated information.

The human acted.

With agentic systems, the AI can potentially become another actor in the environment.

Consider:

Human → AI Agent → CRM → Customer Record

The agent may retrieve information.

It may create information.

It may update information.

It may initiate a workflow.

It may communicate with another service.

The AI is no longer simply observing information.

It may participate in changing the environment.

That makes identity, authorization, monitoring, and accountability much more important.

The New Question: What Can the Agent Do?

When evaluating a conventional application, organizations already ask:

  • What data does it access?

  • What permissions does it have?

  • What APIs does it use?

  • What systems does it connect to?

The same questions apply to AI agents.

But there is another layer.

An agent may dynamically decide which available tools to use based on the task.

Therefore organizations need to understand not only:

What can the system access?

but also:

What actions can it initiate?

Tool Use Changes Everything

Tools are one of the most important parts of agentic AI.

An agent can potentially be connected to tools such as:

  • Search

  • Browser

  • Database

  • CRM

  • Email

  • Calendar

  • File system

  • Code execution

  • Internal APIs

  • Cloud services

  • Business applications

The agent's usefulness can increase dramatically when it has access to tools.

But every tool creates another security boundary.

Consider a simple example.

An AI agent that can only read a knowledge base has one level of authority.

An agent that can:

  • read the knowledge base

  • create CRM records

  • send emails

  • modify customer information

  • execute code

has a much broader authority.

The second system requires significantly more careful security design.

Capability Is Not the Same as Authorization

This distinction is critical.

An agent may technically be capable of performing an action.

That does not mean it should be authorized to perform that action.

For example:

An agent may have access to an email API.

But perhaps it should only be allowed to draft messages.

It may have access to a CRM.

But perhaps it should only read records.

It may have access to a database.

But perhaps it should not modify production data.

This leads to an important principle:

AI capability should not automatically become AI authority.

Security architecture determines the difference.

Identity Becomes a First-Class Security Question

Traditional systems have identities.

Users have accounts.

Applications have service identities.

Machines may have identities.

AI agents introduce another possibility:

Agent identity.

An organization may need to distinguish between:

  • the human requesting an action

  • the application hosting the agent

  • the AI agent performing the task

  • the service identity used to access a system

This becomes important when investigating activity.

Suppose a customer record changes.

A security team may need to determine:

Which human initiated the request?

Which application handled it?

Which agent performed the action?

Which credentials were used?

Which tool executed the change?

What instructions caused the action?

The more autonomous the workflow becomes, the more important this chain of attribution becomes.

Delegated Authority

Another important concept is delegated authority.

An employee may authorize an AI system to perform a task on their behalf.

For example:

"Review these customer tickets and prepare responses."

The agent may then perform multiple operations.

But what exactly did the employee authorize?

Did they authorize:

  • reading tickets?

  • drafting responses?

  • sending responses?

  • modifying customer records?

  • creating refunds?

  • escalating cases?

These are not equivalent permissions.

Therefore an AI system needs boundaries around delegated authority.

Least Privilege for AI Agents

The principle of least privilege becomes even more important in an agentic environment.

An agent should have only the permissions necessary for its intended role.

Imagine three agents.

Research Agent

May:

  • search information

  • read approved sources

  • summarize results

Customer Support Agent

May:

  • read assigned support tickets

  • access approved customer information

  • draft responses

Operations Agent

May:

  • interact with approved operational systems

  • perform specific workflow actions

  • update designated records

Giving all three agents administrative access would unnecessarily expand the security boundary.

The principle is straightforward:

An agent should not receive broad access simply because broad access makes automation easier.

Memory Creates Another Security Layer

Agentic systems may use memory or persistent context to maintain information across interactions.

Memory can improve usefulness.

An agent can potentially remember:

  • previous tasks

  • preferences

  • context

  • decisions

  • historical information

But memory also introduces security considerations.

Questions include:

  • What information is stored?

  • How long is it retained?

  • Who can access it?

  • Can untrusted information enter memory?

  • Can incorrect information influence future decisions?

  • Can one task contaminate another?

  • Can sensitive information persist longer than intended?

This is why memory should be treated as part of the security architecture rather than simply a convenience feature.

Untrusted Information Can Influence AI

AI agents often need information from external sources.

That could include:

  • websites

  • documents

  • emails

  • tickets

  • knowledge bases

  • databases

  • search results

Not all information is trustworthy.

A document may contain malicious instructions.

A webpage may contain text designed to influence the agent.

An email may attempt to manipulate the workflow.

This creates security concerns around instruction handling and prompt injection.

The fundamental issue is:

The agent must distinguish between information it should process and instructions it is actually authorized to follow.

That is easier to describe than to implement.

Prompt Injection Becomes More Serious When Agents Can Act

Prompt injection is not limited to agentic AI.

But the consequences can become more significant when an AI system has access to tools.

Consider two systems.

System A

A malicious instruction causes an AI to produce an incorrect answer.

The human notices the problem.

System B

A malicious instruction influences an AI that can access a business system.

The agent follows the instruction and performs an action.

The second scenario has a different security profile.

The key factor is not simply the AI model.

It is the authority surrounding the model.

The Security Boundary Moves From the Model to the System

This is one of the most important lessons of agentic AI.

It is easy to think:

"We need to secure the AI model."

That is necessary, but insufficient.

The organization also needs to consider:

  • the model

  • prompts

  • context

  • memory

  • tools

  • APIs

  • identities

  • permissions

  • endpoints

  • applications

  • data

  • monitoring

  • human oversight

An AI agent is a system.

Its security therefore depends on the entire system around it.

Agentic AI and Endpoints

At first glance, AI agents may appear unrelated to endpoint security.

They are not.

Employees may access agents through:

  • laptops

  • desktops

  • browsers

  • development environments

  • terminals

  • business applications

Agents may also interact with systems that eventually affect endpoints or endpoint-related workflows.

The endpoint remains one component of the larger environment.

This reinforces a broader principle:

AI security does not eliminate endpoint security. It adds another layer to the security architecture.

Explore Endpoint Security →

Endpoint Visibility Still Matters

Consider an employee using an AI development agent.

The agent may interact with:

  • source code

  • local files

  • terminals

  • development tools

  • APIs

  • repositories

If the endpoint itself is compromised, the AI workflow can potentially be affected.

Similarly, if credentials stored or used on the endpoint are compromised, access to connected services may also be affected.

Therefore businesses still need to understand:

  • which endpoints exist

  • which users operate them

  • what security information is available

  • what vulnerabilities exist

  • what activity requires attention

AI does not replace endpoint visibility.

Vulnerability Management in the Agentic Era

Agentic systems also introduce new dependencies.

An agent may rely on:

  • models

  • libraries

  • APIs

  • connectors

  • plugins

  • external services

  • business applications

Each component can introduce security considerations.

But organizations still have the same fundamental vulnerability-management problem:

Where are our weaknesses?

Vulnerability management therefore remains a foundational security discipline even as AI architectures become more advanced.

Threat Detection Must Follow the New Activity

Traditional security monitoring focuses heavily on user and system activity.

Agentic systems introduce another type of activity.

An agent may:

  • retrieve information

  • invoke APIs

  • access applications

  • create records

  • execute tasks

  • communicate with services

Unusual behavior may therefore involve an agent rather than a conventional user.

Security teams may need to ask:

  • Is this expected?

  • Is the agent operating within its intended scope?

  • Is the volume unusual?

  • Is the destination unusual?

  • Is the sequence of actions unusual?

  • Did an unexpected tool become involved?

This does not mean every unusual agent action is malicious.

It means unusual activity may warrant investigation.

Explore Threat Detection →

Security Monitoring Becomes More Important

As the environment becomes more automated, visibility into activity becomes increasingly valuable.

A security platform needs to help organizations understand what is happening across the environment.

For example:

Endpoint → User → Application → AI Agent → Tool → Business System → Data

The more connections involved, the more useful contextual security information becomes.

Explore Security Monitoring →

Alerts Are Not the Same as Incidents

This distinction should remain clear.

An unusual agent action may generate a security alert.

That does not automatically mean a confirmed security incident has occurred.

The appropriate workflow may be:

Monitoring → Potential Security Event → Alert → Investigation → Decision → Appropriate Action

The goal of security monitoring is not simply to generate more alerts.

It is to help security teams understand meaningful events.

Explore Endpoint Security Alerts →

Human Oversight Still Matters

Increasing AI autonomy does not necessarily mean humans disappear.

Different workflows can use different levels of human oversight.

Human approval

The agent proposes an action.

A human approves it.

Human supervision

The agent performs routine work.

A human supervises the overall workflow.

Restricted autonomy

The agent can act independently within clearly defined boundaries.

Greater autonomy

The agent has broader authority to perform tasks.

The appropriate model depends on the organization, the risk of the task, and the controls surrounding the system.

There is no universal autonomy level that applies to every business process.

The Agentic Attack Surface

Traditional applications already have attack surfaces.

Agentic systems add additional dimensions.

A simplified view is:

Model

How is the model used?

Instructions

What instructions influence it?

Context

What information does it receive?

Memory

What information persists?

Identity

Which identity does it operate under?

Tools

What tools can it invoke?

Permissions

What actions are authorized?

APIs

Which external systems can it access?

Data

What information can flow through the system?

Human Oversight

Where is human approval required?

Monitoring

Can activity be observed and reconstructed?

These layers form a much larger security architecture.

Why Agentic AI Changes Cybersecurity Strategy

The traditional security mindset often begins with:

Protect users and systems.

Agentic AI adds:

Protect automated actors.

That means organizations increasingly need to understand not just:

  • users

  • devices

  • applications

but also:

  • AI systems

  • agents

  • tools

  • automated workflows

  • delegated permissions

This is a significant expansion of the security model.

The Rise of Multi-Agent Systems

Once organizations have one useful AI agent, it is reasonable to imagine specialized agents working together.

For example:

Research Agent → Analysis Agent → Operations Agent → Business System

This can create efficiency.

It can also create a chain of dependencies.

If one agent is compromised, manipulated, or incorrectly configured, its output may influence another agent.

The security question therefore becomes:

Can we trust the entire chain?

Agent-to-Agent Communication

Multi-agent systems introduce another boundary:

Agent → Agent

The receiving agent needs to know:

  • Who sent the message?

  • Is the sender trusted?

  • What authority does the sender have?

  • Is the information trustworthy?

  • Is the requested action permitted?

  • Can the message be manipulated?

These questions are still developing as agentic architectures evolve.

But the underlying cybersecurity principles are familiar:

Identity.

Authentication.

Authorization.

Integrity.

Monitoring.

The Agent Supply Chain

Modern software already depends on supply chains.

Applications rely on:

  • libraries

  • packages

  • APIs

  • cloud services

  • third-party components

Agentic systems can introduce another type of dependency chain.

An agent may depend on:

  • a model

  • an orchestration framework

  • tools

  • connectors

  • external APIs

  • plugins

  • data sources

  • other agents

This means security teams increasingly need to understand not only what an organization operates directly, but also what external components its automated workflows depend on.

The Security Platform Becomes More Important

This is where the broader cybersecurity platform becomes critical.

AI agents do not operate in a vacuum.

They operate inside an organization's technology environment.

That environment still includes:

Endpoints

What devices exist?

Endpoint Visibility

What can be understood about those devices?

Monitoring

What is happening over time?

Vulnerabilities

Where are the weaknesses?

Threat Detection

What activity may represent a potential threat?

Security Alerts

What requires attention?

Security Monitoring

How do these signals fit together?

These capabilities form part of the foundation on which newer AI-specific security controls can operate.

AI Security Does Not Mean Forgetting Basic Security

There is a tendency to think that the rise of AI requires completely new cybersecurity thinking.

Some things do change.

But many fundamentals remain exactly the same.

Organizations still need:

  • strong identity controls

  • least privilege

  • secure endpoints

  • vulnerability management

  • monitoring

  • threat detection

  • appropriate alerting

  • investigation

  • secure configurations

  • controlled access to data

AI adds another category of systems that must operate within those security principles.

The Most Important Question Is Authority

The central question of agentic AI is not:

How intelligent is the model?

A more important security question is:

What authority does the system have?

A highly capable model with no access to sensitive systems may have limited operational impact.

A less capable system with broad permissions could potentially create significant risk.

Therefore AI security is not only a model problem.

It is an authority problem.

Capability, Connectivity, and Authority

A useful framework is to think about three dimensions.

Capability

What can the AI system understand or generate?

Connectivity

What systems and information can it access?

Authority

What actions can it perform?

As each dimension increases, the security architecture becomes more important.

For example:

High capability + low authority

may represent an assistant that provides recommendations.

High capability + high connectivity + high authority

represents a much more consequential system.

This is why security controls need to grow alongside AI autonomy.

2025 Changed the Question Again

The progression now looks like this:

2023

What information are we giving AI?

2024

What systems can AI access?

2025

What can AI do?

That third question is the beginning of a much larger security conversation.

Because once AI can act, organizations need to understand:

  • who authorized it

  • what permissions it has

  • what tools it can use

  • what data it can access

  • what it actually did

  • whether the behavior was expected

  • how the activity can be investigated

From Agents to the Agentic Enterprise

The next stage is not necessarily one powerful AI agent.

It may be an organization with many specialized agents.

One agent handles research.

Another handles customer support.

Another assists developers.

Another analyzes financial information.

Another coordinates workflows.

Another monitors systems.

This creates an agentic enterprise.

And that brings us to 2026.

2026: The Agentic Enterprise

The next article in this series examines the emerging agentic enterprise.

The focus will shift from:

How do we secure one AI agent?

toward:

How do we secure an organization in which many AI-enabled systems participate in business operations?

That introduces questions around:

  • agent identity

  • delegated authority

  • permissions

  • tool access

  • monitoring

  • human oversight

  • agent-to-agent communication

  • endpoint security

  • vulnerability management

  • security operations

  • organizational governance

The security boundary becomes the entire digital environment.

Conclusion

2025 represents an important stage in the evolution from generative AI toward autonomous systems.

AI increasingly moved beyond producing answers and toward participating in multi-step workflows.

The important change was not simply better models.

It was agency.

An agent can potentially:

  • plan

  • retrieve

  • reason

  • use tools

  • interact with applications

  • perform actions

  • evaluate results

  • continue working toward a goal

That creates enormous potential for automation.

It also creates a larger security boundary.

The organization now needs to think about AI systems as participants in the digital environment.

They may have identities.

They may have permissions.

They may access data.

They may use tools.

They may interact with other agents.

They may perform actions.

And those actions need appropriate controls and visibility.

This is why the future of cybersecurity cannot be separated from the future of AI.

The more authority we give automated systems, the more important security architecture becomes.

The question is no longer simply:

"Can AI help our employees?"

It is:

"Can we securely control what AI is allowed to access, what it is allowed to do, and understand what it actually did?"

That question leads directly into the agentic enterprise.

Continue with Part 2: 2024 or return to the series introduction.

DotlyGuard

Control What AI Is Allowed to Do

As agents gain tools and authority, identity, monitoring, threat detection, and endpoint security become part of the security foundation.

No credit card required.

Series: From Generative AI to the Agentic Enterprise

Introduction: From Generative AI to AI Agents

Part 1: 2023: The Generative AI Revolution

Part 2: 2024: When AI Entered the Business Workflow

Part 3: 2025: The Rise of Agentic AI and the New Cybersecurity Boundary (this article)

Part 4: 2026: The Agentic Enterprise

Part 5: 2027: The Multi-Agent Organization (forward-looking scenario)

Part 6: 2028: The AI-Native Business (forward-looking scenario)