SERIES · PART 4

2026: The Agentic Enterprise and the New Cybersecurity Boundary

The more important question is no longer simply what an individual AI agent can do. What happens when AI agents become part of the operating structure of an organization?

This article is Part 4 of From Generative AI to AI Agents: Why the Next Five Years Will Change Cybersecurity.

The story of artificial intelligence changed significantly between 2023 and 2025.

In 2023, generative AI made it possible for ordinary users to interact with powerful AI systems through natural language.

In 2024, AI became increasingly embedded into business applications and workflows.

By 2025, the conversation had moved toward AI agents that could use tools, retrieve information, execute tasks, and take actions with varying degrees of autonomy.

In 2026, the more important question is no longer simply what an individual AI agent can do.

The question is:

What happens when AI agents become part of the operating structure of an organization?

That is the beginning of the agentic enterprise.

An agentic enterprise is not necessarily a company where every employee has an autonomous AI assistant. It is better understood as an emerging architecture in which AI systems can participate directly in business workflows, interact with applications and data, use tools, and perform tasks on behalf of people or organizations.

This changes cybersecurity because the security boundary is no longer limited to people, devices, applications, servers, and networks.

It increasingly includes AI agents as participants in the environment.

And that means organizations need to understand not only who their users are and what devices they have, but also which software systems are acting, what authority they have, what they can access, and what they actually did.

The Evolution Continues

The progression from 2023 to 2026 can be simplified into four stages.

| Year | AI evolution | Central security question | | --- | --- | --- | | 2023 | AI generates | What information are we giving AI? | | 2024 | AI integrates | What systems can AI access? | | 2025 | AI acts | What can AI do? | | 2026 | AI operates across workflows | How do we secure an organization where AI can act? |

This progression is important.

The technology did not simply become better at generating text.

The relationship between AI and the surrounding computing environment changed.

The system around the model became increasingly important.

A modern agent can potentially interact with:

  • Business applications

  • APIs

  • Databases

  • Documents

  • Email

  • Calendars

  • Browsers

  • Development environments

  • Cloud services

  • Internal systems

  • External services

  • Other AI agents

  • Enterprise data

The model is only one component.

The security problem exists across the entire system.

From AI Assistant to Digital Actor

A traditional AI assistant follows a relatively simple pattern:

Human → AI → Response

The human asks a question.

The AI generates an answer.

The human decides what to do next.

An agentic workflow is different:

Human → AI Agent → Tool → Business System → Data → Action

The agent may retrieve information, call an API, update a record, create a document, send a message, execute code, or perform another operation.

That means the AI system is no longer simply generating information.

It is participating in the execution of work.

This distinction matters enormously for cybersecurity.

A wrong answer can be inconvenient.

An unauthorized action can create a security incident.

For example, imagine an agent responsible for processing customer requests.

It might have access to:

  • Customer records

  • Internal documentation

  • CRM systems

  • Email

  • Billing information

  • Support tickets

If the agent only produces suggested responses, the security implications are relatively limited.

If it can independently modify customer records, send emails, issue refunds, change account information, or invoke administrative APIs, the security requirements become substantially different.

The question changes from:

Is the AI answer accurate?

to:

Was the action authorized?

The New Enterprise Architecture

The traditional enterprise security model often looks something like this:

People → Devices → Applications → Data

The emerging agentic model adds another layer:

People → Devices → Identity → Applications → AI Agents → Tools → APIs → Data → Actions

Sometimes the agent may sit between a user and an application.

Sometimes it may operate independently.

Sometimes one agent may invoke another.

This produces a much more complex environment.

Consider a software development organization.

A developer might use a laptop to access a code repository.

An AI coding agent may then:

  1. Read the repository

  2. Analyze the code

  3. Search documentation

  4. Install dependencies

  5. Modify files

  6. Execute tests

  7. Open a pull request

  8. Interact with development tools

The endpoint is still important.

The developer identity is still important.

The repository is still important.

But now the organization also needs to understand the identity and authority of the AI system performing those actions.

This is one reason NIST began work specifically around AI agent identity and authorization in 2026. Its work examines how agents can be identified, authenticated, authorized, audited, and controlled (NIST concept paper on software and AI agent identity and authorization).

Identity Becomes More Complicated

Traditional identity management asks:

Who is the user?

Agentic systems introduce additional questions:

Which agent is acting?

On whose behalf is it acting?

What credentials is it using?

What permissions were delegated to it?

Which actions are permitted?

How long should that authority remain valid?

Consider a simple example.

An employee has permission to access a CRM.

The employee asks an AI agent to update customer information.

The agent now needs some form of authority to interact with the CRM.

Should it use:

  • The employee's identity?

  • A dedicated agent identity?

  • A service account?

  • A delegated token?

  • Temporary authorization?

  • A combination of these?

Each model has different security implications.

This is why identity and authorization are becoming central topics in agent security.

NIST's 2026 work explicitly identifies identification, authorization, auditing, and non-repudiation as areas that require attention for software and AI agents (NIST CSRC).

The important principle is simple:

Capability is not authorization.

An agent may technically be capable of performing an operation without being authorized to perform it.

Security architecture must enforce the difference.

The Principle of Least Privilege Applies to Agents

Least privilege has been a fundamental cybersecurity principle for decades.

Users should receive only the permissions they need.

Applications should receive only the permissions they need.

Services should receive only the permissions they need.

The same principle becomes increasingly important for AI agents.

Suppose an agent needs to read customer support tickets.

It may not need permission to:

  • Delete customers

  • Change billing

  • Create administrators

  • Modify security settings

  • Access unrelated databases

Giving the agent all available permissions simply because it might need them someday creates unnecessary risk.

The broader the authority, the larger the potential blast radius if the agent is manipulated, compromised, misconfigured, or given malicious input.

The security objective should therefore be:

Give the agent enough authority to complete its task, but not enough authority to create unnecessary damage.

Tools Become Part of the Attack Surface

An AI model by itself has limited ability to affect the external environment.

Tools change that.

A tool might allow an agent to:

  • Search the web

  • Read files

  • Send email

  • Query a database

  • Execute code

  • Modify a CRM

  • Create cloud resources

  • Access an API

  • Update a ticket

  • Change configuration

Every tool creates another security boundary.

OWASP's agent security guidance identifies risks including prompt injection, tool abuse, privilege escalation, data exfiltration, and memory poisoning (OWASP AI Agent Security Cheat Sheet).

This means security cannot stop at the model.

Organizations need to examine the complete execution chain:

Input → Model → Context → Decision → Tool → Identity → Permission → Action

Any one of those stages can become relevant to security.

Context Is Becoming a Security Boundary

Agents do not operate only from the user's original prompt.

They may receive information from:

  • Documents

  • Websites

  • Emails

  • Databases

  • Search results

  • APIs

  • Files

  • Previous conversations

  • Persistent memory

  • Other agents

Some of this information may be untrusted.

That creates an important security problem.

An agent may encounter information that looks like an instruction even though it is actually attacker-controlled content.

This is one reason prompt injection becomes more significant when AI systems can take actions.

A malicious instruction inside a document is one thing when an AI merely summarizes the document.

It becomes much more serious when the same AI can act on the information.

The security question becomes:

Can untrusted information influence a trusted action?

That is fundamentally a security architecture question.

Memory Creates Another Security Layer

Memory makes AI systems more useful.

An agent can remember preferences, previous tasks, project information, or context from earlier interactions.

But persistent memory also creates another place where malicious or incorrect information can influence future behavior.

OWASP has specifically identified memory and context poisoning as agentic security concerns. Its 2026 guidance describes memory as a security-relevant state because information retained by an agent can influence future sessions and actions (OWASP Gen AI Security Project).

This produces a new security requirement:

Organizations need to understand what information an agent remembers, where it is stored, who can modify it, and how it influences future decisions.

Memory should not automatically be treated as trusted simply because it was created by an AI system.

The Endpoint Is Still Part of the AI Security Story

It may be tempting to assume that AI security is primarily a cloud or application problem.

It is not.

Employees still use:

  • Laptops

  • Desktops

  • Browsers

  • Terminals

  • Development environments

  • Mobile devices

  • Business applications

AI agents may be accessed from these endpoints.

Developers may run AI coding tools locally.

Employees may use browser-based agents.

Administrators may operate AI-enabled management systems.

Business users may interact with AI applications through their normal workstations.

That means the endpoint remains part of the overall security chain.

An organization cannot fully understand its security environment if it knows what AI systems exist but has poor visibility into the devices from which employees access those systems.

This is where foundational cybersecurity capabilities remain important.

Endpoint inventory

Organizations need to know what devices exist. See Endpoint Inventory Management.

Endpoint visibility

Organizations need to understand what is happening across those devices. See Endpoint Visibility.

Endpoint monitoring

Organizations need ongoing visibility rather than a one-time inventory. See Endpoint Monitoring.

Vulnerability management

Organizations need to identify weaknesses that could be exploited through endpoints or applications. See Vulnerability Management.

Threat detection

Organizations need to identify potentially suspicious activity. See Threat Detection.

Security monitoring

Organizations need the ability to observe security-relevant activity across the environment. See Security Monitoring.

Security alerts

Organizations need a way to identify events that require investigation. See Endpoint Security Alerts.

AI does not eliminate these requirements.

In many cases, AI makes them more important because AI-enabled workflows still depend on the underlying computing environment.

Explore Endpoint Security →

The Security Boundary Now Follows the Action

This may be the most important security lesson of the agentic era.

Traditional security architecture often focuses on protecting systems.

Agentic security increasingly requires protecting actions across systems.

Consider this sequence:

Employee → Endpoint → Identity → AI Agent → Tool → API → Business Application → Data → Action

Every transition represents a possible control point.

If a security team only monitors the AI model, it may miss what happened at the endpoint.

If it only monitors the endpoint, it may not understand which agent performed an API operation.

If it only monitors the API, it may not know which agent or user initiated the action.

If it only monitors the database, it may see the final change without understanding the reasoning or authorization path that produced it.

This creates the need for stronger correlation across systems.

Security Needs an Activity Trail

When an AI agent performs an action, organizations increasingly need to answer:

Who initiated the task?

Which agent performed it?

What identity did the agent use?

What data did it access?

Which tools did it invoke?

What permissions did it have?

What action did it perform?

What system was changed?

When did it happen?

Was human approval required?

What happened afterward?

This is not simply an AI question.

It is an auditability question.

It is also an incident investigation question.

If an unexpected change occurs in a business system, security teams need enough evidence to reconstruct the sequence.

That is why visibility and monitoring become increasingly important as AI becomes more autonomous.

Human Oversight Does Not Disappear

The rise of agentic AI does not necessarily mean that humans disappear from workflows.

Instead, organizations may use different levels of human involvement.

Human approval

The agent prepares an action.

A person approves it.

The system executes it.

Human supervision

The agent performs routine work.

A person monitors the process and intervenes when necessary.

Bounded autonomy

The agent can act independently within clearly defined limits.

Actions outside those limits require approval.

Automated execution

The agent performs predefined tasks without human intervention.

The appropriate model depends on the risk of the action.

A low-risk operation may be automated.

A high-impact operation may require explicit approval.

For cybersecurity, this distinction is important because not every action should have the same authorization requirements.

Agent Inventory May Become as Important as Application Inventory

Organizations already maintain inventories of:

  • Devices

  • Applications

  • Users

  • Cloud resources

  • Services

  • Assets

As agentic systems become more common, organizations may also need to understand their AI agents.

For each agent, an organization could need to know:

| Agent information | Security question | | --- | --- | | Agent identity | What system is acting? | | Owner | Who is responsible for it? | | Purpose | Why does it exist? | | Data access | What information can it retrieve? | | Tools | What can it invoke? | | Permissions | What can it change? | | Credentials | How does it authenticate? | | Memory | What persistent state does it maintain? | | Environment | Where does it operate? | | Activity | What has it done? | | Approval model | When must humans intervene? |

This does not mean every organization already has a mature agent inventory.

It means the concept is becoming increasingly relevant as agents move from experimentation into operational workflows.

NIST's 2026 AI Agent Standards Initiative specifically identifies agent security and identity as areas requiring standards and research as the ecosystem develops (NIST AI Agent Standards Initiative).

What Happens When Something Goes Wrong?

Imagine an employee asks an AI agent to process a customer request.

The agent reads an external document.

The document contains malicious instructions.

The agent interprets them as relevant context.

It calls a tool.

The tool uses an overly broad permission.

A business record is modified.

The security team receives an alert.

What happens next?

A mature security environment should make it possible to investigate the chain.

User → Endpoint → Agent → Context → Tool → Identity → API → Action

Without visibility across the environment, investigators may only see the final event.

They may know that a record changed.

They may not know why.

That is why cybersecurity in the agentic era increasingly becomes a problem of contextual visibility.

Security Must Extend Beyond the AI Model

One of the easiest mistakes is to think of AI security as a model problem.

The model is certainly important.

But the security boundary extends beyond it.

A practical architecture looks more like this:

| Layer | Example | Security question | | --- | --- | --- | | People | Employees | Who initiated the task? | | Endpoints | Laptops, desktops | Is the device secure? | | Identity | User or agent identity | Who is acting? | | Agent | AI system | What is its purpose? | | Context | Documents, email, data | Can untrusted information influence it? | | Memory | Persistent state | What does it retain? | | Tools | APIs, browser, database | What can it invoke? | | Permissions | Tokens, roles | What is it allowed to do? | | Applications | CRM, ERP, cloud systems | What can be changed? | | Data | Customer or business information | What can be accessed? | | Actions | Create, modify, delete, send | What actually happened? | | Monitoring | Logs and security signals | Can the event be reconstructed? |

This is why agentic security cannot be solved by a single control.

It requires layers.

The Cybersecurity Platform Becomes More Important

As organizations add AI systems, the number of components they need to understand increases.

The security platform therefore becomes the layer that connects visibility across the environment.

At the endpoint level, organizations need to know what devices exist and what is happening on them.

At the application level, they need to understand vulnerabilities and suspicious activity.

At the identity level, they need to understand who or what is accessing systems.

At the AI level, they need to understand which agents exist and what authority they have.

At the monitoring level, they need to connect security-relevant events.

This does not mean a single product must perform every security function.

It means the security architecture needs to work as a system.

The more autonomous the environment becomes, the more dangerous fragmented visibility can become.

A New Security Equation

The evolution can be summarized with three dimensions:

Capability + Connectivity + Authority

Capability describes what the AI can do.

Connectivity describes what systems and information it can reach.

Authority describes what actions it is permitted to perform.

Consider the progression:

Low capability

The AI generates text.

Higher capability

The AI plans a workflow.

Higher connectivity

The AI can access business systems.

Higher authority

The AI can change those systems.

The security requirements increase as these dimensions increase.

The important point is not that autonomous AI is inherently unsafe.

The important point is that autonomy without appropriate boundaries creates a larger security problem.

The Future Security Model

The traditional enterprise security model was largely designed around human users and software systems.

The emerging model needs to account for humans and software agents operating together.

That produces a new relationship:

Human + Endpoint + Identity + AI Agent + Tools + Applications + Data

Security needs to understand the relationships between these components.

For example:

A human may authorize an agent.

The agent may invoke a tool.

The tool may access an API.

The API may modify a database.

The database may contain sensitive information.

A security platform that sees only one part of that chain may not provide enough context.

The goal should therefore be broader visibility and stronger control across the action path.

What Organizations Should Start Thinking About Now

Organizations do not need to wait until every business process becomes agentic.

The security architecture can begin with practical questions.

1. Identify AI usage

Where are employees already using AI?

2. Identify connected AI systems

Which AI applications can access company information?

3. Understand permissions

What can those systems access?

4. Identify endpoints

Which devices are being used to access AI systems?

5. Review credentials

How are AI tools authenticated?

6. Review tool access

Which AI systems can invoke APIs, databases, browsers, or other tools?

7. Monitor activity

What security-relevant activity can be observed?

8. Protect vulnerable endpoints

Are devices and applications kept sufficiently secure?

9. Define approval boundaries

Which actions require human approval?

10. Prepare for investigation

If something goes wrong, can the organization reconstruct what happened?

These are not futuristic questions.

They are increasingly practical questions for organizations adopting AI agents.

2026 Is About Securing the Organization Around AI

The biggest change in 2026 is not necessarily that AI became autonomous.

It is that organizations increasingly have to think about AI as part of their operational architecture.

The security boundary therefore expands.

It includes:

People → Endpoints → Identity → AI Agents → Tools → Applications → Data → Actions → Monitoring

The model is still important.

But the model is only one component.

The real security challenge is controlling the environment around the model.

NIST's 2026 work reflects this broader direction, with dedicated initiatives around agent security, agent identity, authorization, interoperability, and secure adoption. NIST's analysis of industry responses also concluded that existing cybersecurity practices remain relevant but need adaptation for agent security (NIST AI Agent Standards Initiative).

OWASP's agent security work similarly treats agentic systems as a distinct security problem involving tools, identity, privilege, memory, context, and autonomous actions (OWASP AI Agent Security Cheat Sheet).

The Question for 2027

The next stage may be even more complicated.

An organization may not have one AI agent.

It may have many.

One agent could research information.

Another could analyze it.

Another could interact with a business system.

Another could verify the result.

Another could perform an operational task.

The agents may communicate with one another.

They may delegate work.

They may share information.

They may operate at different permission levels.

This creates a new question:

How do you secure interactions between agents?

That is the next stage of the story — explored in 2027: The Multi-Agent Organization.

The progression becomes:

2023: AI generates

2024: AI integrates

2025: AI acts

2026: AI operates across enterprise workflows

2027: AI agents interact with other AI agents

The security boundary will therefore have to expand again.

The challenge will no longer be only securing an agent.

It will be securing an ecosystem of agents.

And that is where the next chapter begins.

OWASP's material already identifies insecure inter-agent communication and cascading failures among the relevant risks (OWASP Top 10 for Agentic Applications crosswalk).

Conclusion

The agentic enterprise is not defined by how many AI agents a company deploys.

It is defined by how securely those agents can operate within the organization.

As AI gains access to tools, data, applications, identities, memory, and business workflows, cybersecurity has to follow the action path.

The important questions become:

Who is acting?

What is acting?

What can it access?

What is it authorized to do?

What did it actually do?

Can we see it?

Can we investigate it?

Can we control the consequences?

These questions connect AI security with the foundations of cybersecurity.

Endpoint visibility still matters.

Endpoint monitoring still matters.

Vulnerability management still matters.

Threat detection still matters.

Security monitoring still matters.

Security alerts still matter.

Identity still matters.

The difference is that AI agents are becoming another participant in the environment that these security capabilities must help protect.

The future of cybersecurity will therefore not be about protecting humans from AI or protecting AI from humans.

It will be about creating an environment where humans, software, AI agents, devices, applications, and data can operate together with appropriate visibility, authority, and control.

That is the foundation of the agentic enterprise.

And the next challenge is even larger:

What happens when the enterprise is no longer operating one agent, but hundreds or thousands of interacting agents?

That is the question we explore next.

Continue with Part 3: 2025 or return to the series introduction.

DotlyGuard

See the Full Action Path

As agents operate across workflows, endpoint visibility, monitoring, threat detection, and vulnerability management help organizations understand what is happening across the environment.

No credit card required.

Series: From Generative AI to the Agentic Enterprise

Introduction: From Generative AI to AI Agents

Part 1: 2023: The Generative AI Revolution

Part 2: 2024: When AI Entered the Business Workflow

Part 3: 2025: The Rise of Agentic AI

Part 4: 2026: The Agentic Enterprise and the New Cybersecurity Boundary (this article)

Part 5: 2027: The Multi-Agent Organization (forward-looking scenario)

Part 6: 2028: The AI-Native Business (forward-looking scenario)