2026: The Agentic Enterprise and the New Cybersecurity Boundary
The more important question is no longer simply what an individual AI agent can do. What happens when AI agents become part of the operating structure of an organization?
This article is Part 4 of From Generative AI to AI Agents: Why the Next Five Years Will Change Cybersecurity.
The story of artificial intelligence changed significantly between 2023 and 2025.
In 2023, generative AI made it possible for ordinary users to interact with powerful AI systems through natural language.
In 2024, AI became increasingly embedded into business applications and workflows.
By 2025, the conversation had moved toward AI agents that could use tools, retrieve information, execute tasks, and take actions with varying degrees of autonomy.
In 2026, the more important question is no longer simply what an individual AI agent can do.
The question is:
What happens when AI agents become part of the operating structure of an organization?
That is the beginning of the agentic enterprise.
An agentic enterprise is not necessarily a company where every employee has an autonomous AI assistant. It is better understood as an emerging architecture in which AI systems can participate directly in business workflows, interact with applications and data, use tools, and perform tasks on behalf of people or organizations.
This changes cybersecurity because the security boundary is no longer limited to people, devices, applications, servers, and networks.
It increasingly includes AI agents as participants in the environment.
And that means organizations need to understand not only who their users are and what devices they have, but also which software systems are acting, what authority they have, what they can access, and what they actually did.
The Evolution Continues
The progression from 2023 to 2026 can be simplified into four stages.
| Year | AI evolution | Central security question | | --- | --- | --- | | 2023 | AI generates | What information are we giving AI? | | 2024 | AI integrates | What systems can AI access? | | 2025 | AI acts | What can AI do? | | 2026 | AI operates across workflows | How do we secure an organization where AI can act? |
This progression is important.
The technology did not simply become better at generating text.
The relationship between AI and the surrounding computing environment changed.
The system around the model became increasingly important.
A modern agent can potentially interact with:
Business applications
APIs
Databases
Documents
Email
Calendars
Browsers
Development environments
Cloud services
Internal systems
External services
Other AI agents
Enterprise data
The model is only one component.
The security problem exists across the entire system.
From AI Assistant to Digital Actor
A traditional AI assistant follows a relatively simple pattern:
Human → AI → Response
The human asks a question.
The AI generates an answer.
The human decides what to do next.
An agentic workflow is different:
Human → AI Agent → Tool → Business System → Data → Action
The agent may retrieve information, call an API, update a record, create a document, send a message, execute code, or perform another operation.
That means the AI system is no longer simply generating information.
It is participating in the execution of work.
This distinction matters enormously for cybersecurity.
A wrong answer can be inconvenient.
An unauthorized action can create a security incident.
For example, imagine an agent responsible for processing customer requests.
It might have access to:
Customer records
Internal documentation
CRM systems
Email
Billing information
Support tickets
If the agent only produces suggested responses, the security implications are relatively limited.
If it can independently modify customer records, send emails, issue refunds, change account information, or invoke administrative APIs, the security requirements become substantially different.
The question changes from:
Is the AI answer accurate?
to:
Was the action authorized?
The New Enterprise Architecture
The traditional enterprise security model often looks something like this:
People → Devices → Applications → Data
The emerging agentic model adds another layer:
People → Devices → Identity → Applications → AI Agents → Tools → APIs → Data → Actions
Sometimes the agent may sit between a user and an application.
Sometimes it may operate independently.
Sometimes one agent may invoke another.
This produces a much more complex environment.
Consider a software development organization.
A developer might use a laptop to access a code repository.
An AI coding agent may then:
Read the repository
Analyze the code
Search documentation
Install dependencies
Modify files
Execute tests
Open a pull request
Interact with development tools
The endpoint is still important.
The developer identity is still important.
The repository is still important.
But now the organization also needs to understand the identity and authority of the AI system performing those actions.
This is one reason NIST began work specifically around AI agent identity and authorization in 2026. Its work examines how agents can be identified, authenticated, authorized, audited, and controlled (NIST concept paper on software and AI agent identity and authorization).
Identity Becomes More Complicated
Traditional identity management asks:
Who is the user?
Agentic systems introduce additional questions:
Which agent is acting?
On whose behalf is it acting?
What credentials is it using?
What permissions were delegated to it?
Which actions are permitted?
How long should that authority remain valid?
Consider a simple example.
An employee has permission to access a CRM.
The employee asks an AI agent to update customer information.
The agent now needs some form of authority to interact with the CRM.
Should it use:
The employee's identity?
A dedicated agent identity?
A service account?
A delegated token?
Temporary authorization?
A combination of these?
Each model has different security implications.
This is why identity and authorization are becoming central topics in agent security.
NIST's 2026 work explicitly identifies identification, authorization, auditing, and non-repudiation as areas that require attention for software and AI agents (NIST CSRC).
The important principle is simple:
Capability is not authorization.
An agent may technically be capable of performing an operation without being authorized to perform it.
Security architecture must enforce the difference.
The Principle of Least Privilege Applies to Agents
Least privilege has been a fundamental cybersecurity principle for decades.
Users should receive only the permissions they need.
Applications should receive only the permissions they need.
Services should receive only the permissions they need.
The same principle becomes increasingly important for AI agents.
Suppose an agent needs to read customer support tickets.
It may not need permission to:
Delete customers
Change billing
Create administrators
Modify security settings
Access unrelated databases
Giving the agent all available permissions simply because it might need them someday creates unnecessary risk.
The broader the authority, the larger the potential blast radius if the agent is manipulated, compromised, misconfigured, or given malicious input.
The security objective should therefore be:
Give the agent enough authority to complete its task, but not enough authority to create unnecessary damage.
Tools Become Part of the Attack Surface
An AI model by itself has limited ability to affect the external environment.
Tools change that.
A tool might allow an agent to:
Search the web
Read files
Send email
Query a database
Execute code
Modify a CRM
Create cloud resources
Access an API
Update a ticket
Change configuration
Every tool creates another security boundary.
OWASP's agent security guidance identifies risks including prompt injection, tool abuse, privilege escalation, data exfiltration, and memory poisoning (OWASP AI Agent Security Cheat Sheet).
This means security cannot stop at the model.
Organizations need to examine the complete execution chain:
Input → Model → Context → Decision → Tool → Identity → Permission → Action
Any one of those stages can become relevant to security.
Context Is Becoming a Security Boundary
Agents do not operate only from the user's original prompt.
They may receive information from:
Documents
Websites
Emails
Databases
Search results
APIs
Files
Previous conversations
Persistent memory
Other agents
Some of this information may be untrusted.
That creates an important security problem.
An agent may encounter information that looks like an instruction even though it is actually attacker-controlled content.
This is one reason prompt injection becomes more significant when AI systems can take actions.
A malicious instruction inside a document is one thing when an AI merely summarizes the document.
It becomes much more serious when the same AI can act on the information.
The security question becomes:
Can untrusted information influence a trusted action?
That is fundamentally a security architecture question.
Memory Creates Another Security Layer
Memory makes AI systems more useful.
An agent can remember preferences, previous tasks, project information, or context from earlier interactions.
But persistent memory also creates another place where malicious or incorrect information can influence future behavior.
OWASP has specifically identified memory and context poisoning as agentic security concerns. Its 2026 guidance describes memory as a security-relevant state because information retained by an agent can influence future sessions and actions (OWASP Gen AI Security Project).
This produces a new security requirement:
Organizations need to understand what information an agent remembers, where it is stored, who can modify it, and how it influences future decisions.
Memory should not automatically be treated as trusted simply because it was created by an AI system.
The Endpoint Is Still Part of the AI Security Story
It may be tempting to assume that AI security is primarily a cloud or application problem.
It is not.
Employees still use:
Laptops
Desktops
Browsers
Terminals
Development environments
Mobile devices
Business applications
AI agents may be accessed from these endpoints.
Developers may run AI coding tools locally.
Employees may use browser-based agents.
Administrators may operate AI-enabled management systems.
Business users may interact with AI applications through their normal workstations.
That means the endpoint remains part of the overall security chain.
An organization cannot fully understand its security environment if it knows what AI systems exist but has poor visibility into the devices from which employees access those systems.
This is where foundational cybersecurity capabilities remain important.
Endpoint inventory
Organizations need to know what devices exist. See Endpoint Inventory Management.
Endpoint visibility
Organizations need to understand what is happening across those devices. See Endpoint Visibility.
Endpoint monitoring
Organizations need ongoing visibility rather than a one-time inventory. See Endpoint Monitoring.
Vulnerability management
Organizations need to identify weaknesses that could be exploited through endpoints or applications. See Vulnerability Management.
Threat detection
Organizations need to identify potentially suspicious activity. See Threat Detection.
Security monitoring
Organizations need the ability to observe security-relevant activity across the environment. See Security Monitoring.
Security alerts
Organizations need a way to identify events that require investigation. See Endpoint Security Alerts.
AI does not eliminate these requirements.
In many cases, AI makes them more important because AI-enabled workflows still depend on the underlying computing environment.
The Security Boundary Now Follows the Action
This may be the most important security lesson of the agentic era.
Traditional security architecture often focuses on protecting systems.
Agentic security increasingly requires protecting actions across systems.
Consider this sequence:
Employee → Endpoint → Identity → AI Agent → Tool → API → Business Application → Data → Action
Every transition represents a possible control point.
If a security team only monitors the AI model, it may miss what happened at the endpoint.
If it only monitors the endpoint, it may not understand which agent performed an API operation.
If it only monitors the API, it may not know which agent or user initiated the action.
If it only monitors the database, it may see the final change without understanding the reasoning or authorization path that produced it.
This creates the need for stronger correlation across systems.
Security Needs an Activity Trail
When an AI agent performs an action, organizations increasingly need to answer:
Who initiated the task?
Which agent performed it?
What identity did the agent use?
What data did it access?
Which tools did it invoke?
What permissions did it have?
What action did it perform?
What system was changed?
When did it happen?
Was human approval required?
What happened afterward?
This is not simply an AI question.
It is an auditability question.
It is also an incident investigation question.
If an unexpected change occurs in a business system, security teams need enough evidence to reconstruct the sequence.
That is why visibility and monitoring become increasingly important as AI becomes more autonomous.
Human Oversight Does Not Disappear
The rise of agentic AI does not necessarily mean that humans disappear from workflows.
Instead, organizations may use different levels of human involvement.
Human approval
The agent prepares an action.
A person approves it.
The system executes it.
Human supervision
The agent performs routine work.
A person monitors the process and intervenes when necessary.
Bounded autonomy
The agent can act independently within clearly defined limits.
Actions outside those limits require approval.
Automated execution
The agent performs predefined tasks without human intervention.
The appropriate model depends on the risk of the action.
A low-risk operation may be automated.
A high-impact operation may require explicit approval.
For cybersecurity, this distinction is important because not every action should have the same authorization requirements.
Agent Inventory May Become as Important as Application Inventory
Organizations already maintain inventories of:
Devices
Applications
Users
Cloud resources
Services
Assets
As agentic systems become more common, organizations may also need to understand their AI agents.
For each agent, an organization could need to know:
| Agent information | Security question | | --- | --- | | Agent identity | What system is acting? | | Owner | Who is responsible for it? | | Purpose | Why does it exist? | | Data access | What information can it retrieve? | | Tools | What can it invoke? | | Permissions | What can it change? | | Credentials | How does it authenticate? | | Memory | What persistent state does it maintain? | | Environment | Where does it operate? | | Activity | What has it done? | | Approval model | When must humans intervene? |
This does not mean every organization already has a mature agent inventory.
It means the concept is becoming increasingly relevant as agents move from experimentation into operational workflows.
NIST's 2026 AI Agent Standards Initiative specifically identifies agent security and identity as areas requiring standards and research as the ecosystem develops (NIST AI Agent Standards Initiative).
What Happens When Something Goes Wrong?
Imagine an employee asks an AI agent to process a customer request.
The agent reads an external document.
The document contains malicious instructions.
The agent interprets them as relevant context.
It calls a tool.
The tool uses an overly broad permission.
A business record is modified.
The security team receives an alert.
What happens next?
A mature security environment should make it possible to investigate the chain.
User → Endpoint → Agent → Context → Tool → Identity → API → Action
Without visibility across the environment, investigators may only see the final event.
They may know that a record changed.
They may not know why.
That is why cybersecurity in the agentic era increasingly becomes a problem of contextual visibility.
Security Must Extend Beyond the AI Model
One of the easiest mistakes is to think of AI security as a model problem.
The model is certainly important.
But the security boundary extends beyond it.
A practical architecture looks more like this:
| Layer | Example | Security question | | --- | --- | --- | | People | Employees | Who initiated the task? | | Endpoints | Laptops, desktops | Is the device secure? | | Identity | User or agent identity | Who is acting? | | Agent | AI system | What is its purpose? | | Context | Documents, email, data | Can untrusted information influence it? | | Memory | Persistent state | What does it retain? | | Tools | APIs, browser, database | What can it invoke? | | Permissions | Tokens, roles | What is it allowed to do? | | Applications | CRM, ERP, cloud systems | What can be changed? | | Data | Customer or business information | What can be accessed? | | Actions | Create, modify, delete, send | What actually happened? | | Monitoring | Logs and security signals | Can the event be reconstructed? |
This is why agentic security cannot be solved by a single control.
It requires layers.
The Cybersecurity Platform Becomes More Important
As organizations add AI systems, the number of components they need to understand increases.
The security platform therefore becomes the layer that connects visibility across the environment.
At the endpoint level, organizations need to know what devices exist and what is happening on them.
At the application level, they need to understand vulnerabilities and suspicious activity.
At the identity level, they need to understand who or what is accessing systems.
At the AI level, they need to understand which agents exist and what authority they have.
At the monitoring level, they need to connect security-relevant events.
This does not mean a single product must perform every security function.
It means the security architecture needs to work as a system.
The more autonomous the environment becomes, the more dangerous fragmented visibility can become.
A New Security Equation
The evolution can be summarized with three dimensions:
Capability + Connectivity + Authority
Capability describes what the AI can do.
Connectivity describes what systems and information it can reach.
Authority describes what actions it is permitted to perform.
Consider the progression:
Low capability
The AI generates text.
Higher capability
The AI plans a workflow.
Higher connectivity
The AI can access business systems.
Higher authority
The AI can change those systems.
The security requirements increase as these dimensions increase.
The important point is not that autonomous AI is inherently unsafe.
The important point is that autonomy without appropriate boundaries creates a larger security problem.
The Future Security Model
The traditional enterprise security model was largely designed around human users and software systems.
The emerging model needs to account for humans and software agents operating together.
That produces a new relationship:
Human + Endpoint + Identity + AI Agent + Tools + Applications + Data
Security needs to understand the relationships between these components.
For example:
A human may authorize an agent.
The agent may invoke a tool.
The tool may access an API.
The API may modify a database.
The database may contain sensitive information.
A security platform that sees only one part of that chain may not provide enough context.
The goal should therefore be broader visibility and stronger control across the action path.
What Organizations Should Start Thinking About Now
Organizations do not need to wait until every business process becomes agentic.
The security architecture can begin with practical questions.
1. Identify AI usage
Where are employees already using AI?
2. Identify connected AI systems
Which AI applications can access company information?
3. Understand permissions
What can those systems access?
4. Identify endpoints
Which devices are being used to access AI systems?
5. Review credentials
How are AI tools authenticated?
6. Review tool access
Which AI systems can invoke APIs, databases, browsers, or other tools?
7. Monitor activity
What security-relevant activity can be observed?
8. Protect vulnerable endpoints
Are devices and applications kept sufficiently secure?
9. Define approval boundaries
Which actions require human approval?
10. Prepare for investigation
If something goes wrong, can the organization reconstruct what happened?
These are not futuristic questions.
They are increasingly practical questions for organizations adopting AI agents.
2026 Is About Securing the Organization Around AI
The biggest change in 2026 is not necessarily that AI became autonomous.
It is that organizations increasingly have to think about AI as part of their operational architecture.
The security boundary therefore expands.
It includes:
People → Endpoints → Identity → AI Agents → Tools → Applications → Data → Actions → Monitoring
The model is still important.
But the model is only one component.
The real security challenge is controlling the environment around the model.
NIST's 2026 work reflects this broader direction, with dedicated initiatives around agent security, agent identity, authorization, interoperability, and secure adoption. NIST's analysis of industry responses also concluded that existing cybersecurity practices remain relevant but need adaptation for agent security (NIST AI Agent Standards Initiative).
OWASP's agent security work similarly treats agentic systems as a distinct security problem involving tools, identity, privilege, memory, context, and autonomous actions (OWASP AI Agent Security Cheat Sheet).
The Question for 2027
The next stage may be even more complicated.
An organization may not have one AI agent.
It may have many.
One agent could research information.
Another could analyze it.
Another could interact with a business system.
Another could verify the result.
Another could perform an operational task.
The agents may communicate with one another.
They may delegate work.
They may share information.
They may operate at different permission levels.
This creates a new question:
How do you secure interactions between agents?
That is the next stage of the story — explored in 2027: The Multi-Agent Organization.
The progression becomes:
2023: AI generates
2024: AI integrates
2025: AI acts
2026: AI operates across enterprise workflows
2027: AI agents interact with other AI agents
The security boundary will therefore have to expand again.
The challenge will no longer be only securing an agent.
It will be securing an ecosystem of agents.
And that is where the next chapter begins.
OWASP's material already identifies insecure inter-agent communication and cascading failures among the relevant risks (OWASP Top 10 for Agentic Applications crosswalk).
Conclusion
The agentic enterprise is not defined by how many AI agents a company deploys.
It is defined by how securely those agents can operate within the organization.
As AI gains access to tools, data, applications, identities, memory, and business workflows, cybersecurity has to follow the action path.
The important questions become:
Who is acting?
What is acting?
What can it access?
What is it authorized to do?
What did it actually do?
Can we see it?
Can we investigate it?
Can we control the consequences?
These questions connect AI security with the foundations of cybersecurity.
Endpoint visibility still matters.
Endpoint monitoring still matters.
Vulnerability management still matters.
Threat detection still matters.
Security monitoring still matters.
Security alerts still matter.
Identity still matters.
The difference is that AI agents are becoming another participant in the environment that these security capabilities must help protect.
The future of cybersecurity will therefore not be about protecting humans from AI or protecting AI from humans.
It will be about creating an environment where humans, software, AI agents, devices, applications, and data can operate together with appropriate visibility, authority, and control.
That is the foundation of the agentic enterprise.
And the next challenge is even larger:
What happens when the enterprise is no longer operating one agent, but hundreds or thousands of interacting agents?
That is the question we explore next.
Continue with Part 3: 2025 or return to the series introduction.
See the Full Action Path
As agents operate across workflows, endpoint visibility, monitoring, threat detection, and vulnerability management help organizations understand what is happening across the environment.
No credit card required.
Related DotlyGuard topics
Series Introduction
From generative AI to AI agents — why the next five years change cybersecurity.
Part 3: 2025 Rise of Agentic AI
How individual agents gained tools, authority, and a new attack surface.
Part 2: 2024 AI Business Workflow
How AI moved into applications, data, and everyday workflows.
Endpoint Security
Protect devices where people and agents still intersect.
Endpoint Visibility
Understand devices and security-relevant context.
Endpoint Monitoring
Observe endpoint conditions as automated activity increases.
Security Monitoring
Correlate activity across users, endpoints, applications, and agents.
Threat Detection
Identify unusual activity that may require investigation.
Vulnerability Management
Find weaknesses across systems agents and people depend on.
Endpoint Security Alerts
Surface information that may require attention.
Series: From Generative AI to the Agentic Enterprise
Introduction: From Generative AI to AI Agents
Part 1: 2023: The Generative AI Revolution
Part 2: 2024: When AI Entered the Business Workflow
Part 3: 2025: The Rise of Agentic AI
Part 4: 2026: The Agentic Enterprise and the New Cybersecurity Boundary (this article)
Part 5: 2027: The Multi-Agent Organization (forward-looking scenario)
Part 6: 2028: The AI-Native Business (forward-looking scenario)