SERIES

From Generative AI to AI Agents: Why the Next Five Years Will Change Cybersecurity

The AI revolution did not start with autonomous agents. It started with generative AI. But the journey from generating information to taking action is changing what businesses need from cybersecurity.

In 2023, generative AI became a mainstream technology conversation.

People were asking AI to write emails, summarize documents, generate code, create images, analyze information, and answer questions.

The interaction was relatively simple:

Human → AI → Response

The human remained in the middle.

Today, that model is changing.

AI systems can increasingly reason through multi-step tasks, use external tools, access applications, work with files and data, browse the web, execute code, and perform actions on behalf of users. OpenAI's 2025 ChatGPT agent system, for example, combined research capabilities with browser interaction, a terminal, and access to external data sources and applications (OpenAI Deployment Safety Hub).

The model is becoming:

Human → AI → Tools → Data → Actions

And the next stage is potentially:

Human → AI Agents → Other Agents → Business Systems → Actions

That evolution has a major cybersecurity implication.

The question is no longer only:

How do we secure our computers and applications?

It increasingly becomes:

How do we secure the machines, people, applications, identities, data, and AI agents that can act inside our digital environment?

This article begins a five-year series exploring how we arrived here, where AI is going, and why cybersecurity platforms will become increasingly important as AI moves from generating content to performing work.

The Beginning: 2023 and the Generative AI Explosion

2023 represented a major shift in how ordinary businesses interacted with artificial intelligence.

Generative AI moved from being primarily a research and specialist technology into something that employees could directly use.

People began using AI for:

  • Writing

  • Research

  • Programming

  • Marketing

  • Customer communication

  • Data analysis

  • Documentation

  • Content creation

  • Translation

  • Business planning

  • Knowledge retrieval

The important change was accessibility.

AI no longer required a specialized machine-learning team.

An employee could open a browser, enter a prompt, and immediately use a powerful AI system.

That created enormous productivity opportunities.

It also created a new security question:

What happens when employees start sending business information to AI systems?

Documents, customer information, source code, internal processes, credentials, business strategies, contracts, and other sensitive information could potentially become part of AI workflows.

The first AI security conversation therefore focused heavily on data exposure and information governance.

But this was only the beginning.

2024: AI Moves Into Business Workflows

The next stage was not simply better AI models.

AI started becoming integrated into the tools people were already using.

Instead of asking an AI system a question and copying the answer somewhere else, AI could increasingly become part of a workflow.

Consider a simple example.

Earlier model

An employee asks:

"Summarize these customer complaints."

AI produces a summary.

The employee reads it and decides what to do.

Emerging model

An AI system can:

  1. Read customer complaints.

  2. Classify them.

  3. Identify recurring issues.

  4. Create tasks.

  5. Draft responses.

  6. Update business systems.

  7. Notify employees.

The AI is no longer merely producing information.

It is participating in a process.

That distinction is extremely important for cybersecurity.

When AI only produces text, the primary security concern may be the information it receives and produces.

When AI starts interacting with business systems, the security question expands:

What is the AI allowed to access?

And:

What is the AI allowed to do?

2025: From AI Assistants to AI Agents

2025 brought the concept of agentic AI much closer to practical business systems.

An AI agent is different from a traditional chatbot because it can be designed to pursue a goal through multiple steps, using tools and external systems along the way.

Instead of:

Prompt → Answer

the workflow becomes:

Goal → Planning → Tool usage → Actions → Evaluation → Next action

This creates an entirely different security model.

OWASP's work on agentic AI specifically identifies attack surfaces involving reasoning, memory, tools, identity, human oversight, and interactions between multiple agents (OWASP Gen AI Security Project — Agentic Threats Navigator).

This is the point where cybersecurity begins to intersect directly with AI architecture.

An agent may have:

  • An identity

  • Credentials

  • Access tokens

  • Memory

  • Instructions

  • Tools

  • APIs

  • Data sources

  • Business permissions

  • External integrations

  • The ability to initiate actions

Every one of those becomes relevant to security.

2026: The Agent Becomes an Operational Actor

We are now entering a different phase.

AI agents are increasingly being designed to perform tasks rather than simply answer questions.

An agent can potentially:

  • Research information

  • Browse websites

  • Read documents

  • Analyze data

  • Write code

  • Execute code

  • Interact with APIs

  • Work with business applications

  • Create or modify information

  • Coordinate multiple steps

  • Communicate with other systems

This is why the security conversation around agents has become much more serious.

OWASP's Agentic AI work describes risks including goal hijacking, tool misuse, identity and privilege abuse, agentic supply-chain vulnerabilities, unexpected code execution, memory poisoning, insecure inter-agent communication, cascading failures, human-agent trust exploitation, and rogue-agent behavior (OWASP Top 10 for Agentic Applications).

These risks are fundamentally different from the security model of a simple chatbot.

The Fundamental Change: AI Can Now Act

This may be the most important idea in the entire series.

For years, businesses primarily secured systems that stored, processed, and transmitted information.

Now they increasingly need to secure systems that can make decisions and take actions.

That changes the attack surface.

Consider a traditional employee workstation.

It may have:

  • An operating system

  • Applications

  • Files

  • Browser sessions

  • Credentials

  • Network access

  • Business data

Now imagine an AI agent operating through that environment.

The agent may have access to some or all of those resources.

The agent itself becomes another security-relevant entity.

And unlike a conventional application, its behavior can depend on:

  • Instructions

  • Context

  • Retrieved information

  • Memory

  • Tool results

  • External content

  • Other agents

  • Human requests

This creates a much more dynamic security environment.

The New Security Model

The traditional security model often looks something like:

Users → Devices → Applications → Data

The emerging AI environment looks more like:

Users → Devices → AI Agents → Tools → Applications → APIs → Data

And increasingly:

Agent → Agent → Agent → Business Systems → Data

This introduces additional questions.

Who is the agent?

Does it have its own identity?

What can it access?

Does it have access to customer information?

What can it change?

Can it create records, modify data, execute code, or send communications?

What credentials does it possess?

Are those credentials limited?

What tools can it use?

Can an agent invoke any available tool, or only approved tools?

What does it remember?

Can malicious information enter its memory and influence future actions?

Who authorized the action?

Was the action explicitly approved by a human, or did the agent initiate it autonomously?

What happened?

Can security teams reconstruct the sequence of events?

These are cybersecurity questions.

2027: The Rise of AI-Managed Workflows

The next phase is likely to involve deeper integration of agents into ordinary business processes.

This should be treated as a forward-looking scenario rather than a guaranteed prediction.

Businesses may increasingly have specialized agents for:

  • Sales

  • Customer support

  • Finance

  • Software development

  • IT operations

  • Research

  • Marketing

  • Procurement

  • Data analysis

  • Security operations

Instead of one AI assistant, an organization could have many specialized agents.

One agent might research a problem.

Another might analyze the results.

Another might execute an approved workflow.

Another might monitor the outcome.

This is where multi-agent systems become important.

OWASP has already published specific threat-modeling guidance for multi-agent systems because coordination between autonomous agents introduces additional attack surfaces and complexity (Multi-Agentic System Threat Modeling Guide).

The security problem therefore becomes larger than securing an individual AI model.

The organization must understand the relationships between agents.

2028: The Digital Workforce Becomes More Autonomous

Looking further ahead, another possible stage is the emergence of organizations where AI agents perform substantial portions of routine digital work.

Again, this is a scenario for the series, not a certainty.

A business might have:

Human employees

working alongside:

AI agents

that operate across:

  • CRM systems

  • Accounting systems

  • Communication platforms

  • Development environments

  • Cloud infrastructure

  • Customer databases

  • Analytics systems

  • Internal knowledge systems

At that point, cybersecurity cannot simply focus on whether a laptop is protected.

It must understand the entire digital operating environment.

Why Cybersecurity Platforms Become More Important

This is where the importance of a proper cybersecurity platform becomes clear.

The more systems an organization operates, the harder it becomes to understand what is happening.

Add AI agents to the environment and the number of possible interactions increases significantly.

A modern security platform therefore needs to help organizations answer fundamental questions.

1. What devices exist?

Organizations need visibility into their endpoints.

Without knowing what devices are connected to the business environment, security visibility is incomplete.

This is the foundation of endpoint inventory.

2. What is happening on those devices?

Inventory tells you what exists.

Monitoring helps you understand what is happening over time.

This becomes increasingly important when employees use AI tools, browser-based AI applications, development tools, and other services from business endpoints.

3. What security concerns are appearing?

Security monitoring can surface information that may require attention.

An alert does not necessarily mean that a confirmed security incident has occurred.

It means that something may require investigation.

That distinction becomes especially important as the volume of automated activity increases.

4. Which vulnerabilities exist?

AI does not eliminate traditional cybersecurity problems.

Operating systems, applications, configurations, credentials, networks, and endpoints still have vulnerabilities.

In fact, more automation can increase the importance of managing those weaknesses.

NIST's work on adversarial machine learning and AI security reflects the broader recognition that AI systems themselves introduce security and resilience considerations (NIST Adversarial Machine Learning report).

See Vulnerability Management for how DotlyGuard approaches this layer.

5. Which activities may represent threats?

Threat detection becomes another layer.

The goal is not simply collecting enormous amounts of information.

The goal is identifying potential security threats or suspicious activity that deserves investigation.

6. Who or what is performing an action?

This question will become increasingly important.

Historically, security teams have primarily asked:

Which user performed this action?

In an AI-enabled environment, they may also need to ask:

Which agent performed this action?

And:

On whose authority?

That introduces the concept of machine identity and agent identity into everyday security operations.

The Endpoint Is Still Important

There is a temptation to think that AI will make endpoint security less important.

The opposite may happen.

Employees will continue to use:

  • Laptops

  • Desktops

  • Mobile devices

  • Browsers

  • Development environments

  • Business applications

AI agents will interact with many of those environments.

That means the endpoint can remain an important observation point.

A security platform that provides endpoint inventory, visibility, monitoring, protection, vulnerability information, alerts, and threat detection can become part of the broader security architecture.

The endpoint does not disappear because AI becomes more intelligent.

It becomes one of the places where AI-enabled work actually happens.

Explore Endpoint Security →

The Security Platform Becomes the Source of Context

This may ultimately be one of the most important changes.

A security platform should not simply generate alerts.

It should help organizations understand their environment.

For example:

Device

→ Who uses it?

→ What is running on it?

→ What security information exists?

→ Are vulnerabilities present?

→ Are there suspicious activities?

→ What alerts have occurred?

→ What happened before and after the event?

That context becomes increasingly valuable as automation increases.

Because when AI can perform actions rapidly, humans need better visibility into those actions.

AI Does Not Replace Cybersecurity

Another important point is often missed.

AI can improve cybersecurity.

It can help with:

  • Analysis

  • Classification

  • Investigation

  • Correlation

  • Summarization

  • Detection

  • Security workflows

  • Response assistance

But AI also creates new attack surfaces.

OWASP's agentic security guidance explicitly treats autonomous agents as a new security domain rather than simply another version of traditional software (Securing Agentic Applications Guide).

NIST is likewise working on security controls covering generative AI, single-agent systems, and multi-agent systems (Control Overlays for Securing AI Systems).

The future therefore is not:

AI instead of cybersecurity.

It is:

AI + cybersecurity.

And increasingly:

AI secured by cybersecurity.

The Five-Year Question

The most interesting question is not:

How powerful will AI become?

A more important business question is:

How much authority will businesses give AI?

There is a major difference between an AI that can suggest an action and an AI that can execute it.

There is another difference between one agent and hundreds of agents.

And another between an agent with limited access and an agent with access to sensitive business systems.

The more authority AI receives, the more important security controls become.

From 2023 to the Next Five Years

The evolution can be summarized as:

| Period | AI Evolution | Security Question | | --- | --- | --- | | 2023 | Generative AI | What information are we giving AI? | | 2024 | AI integrated into workflows | What systems can AI access? | | 2025 | Agentic AI emerges | What can AI do? | | 2026 | AI agents become more operational | Who controls and monitors AI actions? | | 2027 | More specialized and multi-agent workflows | How do we secure interactions between agents? | | 2028 | Greater AI participation in business operations | How do we secure an AI-enabled organization? |

The exact timeline will vary by industry and technology adoption.

But the direction is clear: AI is moving from generating information toward interacting with systems and performing increasingly complex tasks.

The New Cybersecurity Foundation

This is why businesses should not think about cybersecurity as a collection of disconnected tools.

A modern security strategy needs a foundation of visibility and control.

At minimum, organizations need to understand:

Endpoints — What devices exist?

Identity — Who or what can access systems?

Applications — What software and services are being used?

Data — What information is being accessed?

Vulnerabilities — Where are the weaknesses?

Threats — What potentially malicious or suspicious activity is occurring?

Alerts — What requires attention?

Activity — What actually happened?

AI and Agents — Which automated systems can access or act within the environment?

These layers increasingly intersect.

Why Endpoint Security Still Matters in an AI-First World

The cybersecurity industry will continue to evolve.

New AI security platforms will emerge.

New agent security controls will appear.

New identity models will be developed.

New standards will be created.

But organizations will still have physical and virtual endpoints.

People will still use computers.

Applications will still have vulnerabilities.

Credentials will still need protection.

Data will still need protection.

And attackers will continue looking for the weakest path into an organization.

The future of cybersecurity therefore is unlikely to be about choosing between traditional endpoint security and AI security.

It will increasingly be about connecting them.

The Bigger Picture

The journey from generative AI to agentic AI is not simply a story about better models.

It is a story about increasing autonomy.

In 2023, AI primarily generated.

Then AI increasingly assisted.

Then it began participating in workflows.

Now agents can increasingly act.

The next stage is greater coordination between AI systems and business infrastructure.

Every step increases the potential value of AI.

Every step also increases the importance of security.

That leads to a simple principle:

The more authority we give AI, the more important visibility, identity, monitoring, access control, vulnerability management, and security become.

A cybersecurity platform is therefore not just about protecting yesterday's computers.

It is about building the security foundation for tomorrow's digital workforce.

This Is Only the Beginning

This article is the beginning of a five-year series.

The next articles will examine the evolution year by year:

Part 1 — 2023: The Generative AI Revolution

How generative AI moved from research technology into everyday business use.

Part 2 — 2024: When AI Entered the Business Workflow

How AI moved from chat interfaces into applications, productivity tools, development environments, and business processes.

Part 3 — 2025: The Rise of Agentic AI

How AI began moving from answering questions toward planning, using tools, and taking actions.

Part 4 — 2026: The Agentic Enterprise

How AI agents are becoming increasingly integrated into real business environments and why identity, permissions, monitoring, and security matter.

Part 5 — 2027: The Multi-Agent Organization

A forward-looking examination of what happens when multiple AI agents coordinate across business systems.

Part 6 — 2028: The AI-Native Business

A forward-looking scenario examining what cybersecurity could look like when AI becomes an operational layer across much of the digital organization.

The objective is not to predict the future with certainty.

It is to understand the direction of technological change early enough to build the security foundations required for it.

Final Thought

Generative AI changed how humans interact with computers.

Agentic AI may change how computers interact with the world.

That distinction could become one of the defining technology shifts of the next several years.

And when software can increasingly see, reason, access, communicate, and act, security cannot remain an afterthought.

It has to become part of the architecture.

The future of AI depends not only on what AI can do, but on whether we can securely control what it is allowed to do.

DotlyGuard

Build the Security Foundation

As AI gains authority to act, visibility, monitoring, threat detection, and vulnerability management become more important — not less.

No credit card required.