Enterprises have spent decades building cybersecurity programs around an uncomfortable reality: People make mistakes.
Employees click malicious links. They misunderstand instructions. They misuse privileges. They expose sensitive information. Sometimes they do something perfectly well-intentioned that creates an opening for an attacker.
Security teams don't expect to eliminate those mistakes. They build controls designed to detect them, limit the damage and intervene when behavior becomes dangerous.
Nadav Cornberg, founder and CEO of Eve Security, believes organizations need to start thinking about AI agents the same way.
"We expect people to make mistakes," Cornberg told Michael Farnum and Sam Van Ryder during the latest episode of CYBR.SEC.CAST. Yet when organizations deploy AI agents, he said, many still operate under the assumption that those systems can somehow be made "100% secure."
That assumption becomes increasingly dangerous as agents gain access to business applications, data and critical infrastructure.
Full episode and related article:


Agentic AI turns mistakes into operational risk
The problem isn't simply that an AI agent might produce an incorrect answer. Agents increasingly have the ability to act. They can access applications, call APIs, manipulate data and interact with other enterprise systems. Model Context Protocol (MCP) and similar technologies make those connections easier, while natural-language instructions introduce ambiguity and AI models remain probabilistic.
Cornberg described the combination as a troubling trifecta: Agents can connect to systems, their behavior is probabilistic and their instructions are expressed through language that can be ambiguous by design.
That turns an AI mistake into something potentially much larger than a bad chatbot response.
An agent trying aggressively to complete its assigned task might delete information, expose data, consume enormous amounts of resources or interact with systems in ways its operators never anticipated.
"The agent got a task to complete," Cornberg said while discussing recent examples of unexpected agent behavior. "Its nature is to complete the task."
The agent doesn't necessarily recognize that its actions have crossed a security boundary. From its perspective, it may simply be doing its job.
Humans do much the same thing. An employee might transfer money after receiving what appears to be an urgent request from an executive. The employee isn't malicious. They're attempting to accomplish a legitimate business task without recognizing that something has gone wrong.
AI agents introduce the same problem — except they can operate much faster and potentially touch far more systems.
Stop asking only what the agent is allowed to do
That changes the security question. Traditional identity and access management focuses heavily on authorization: Who are you, and what are you allowed to access?
Agentic AI requires another question: What are you actually doing with that access? Cornberg illustrated the difference with an analogy:
Imagine a bank employee who has never entered the vault suddenly walking into it. Even if that employee technically has permission, the behavior itself should attract attention. Security teams need similar visibility into AI agents.
If an agent normally reads Jira tickets, updates them and posts comments, those behaviors establish a baseline. But if that same agent suddenly attempts to delete an entire Jira space, something has changed.
The immediate question shouldn't simply be whether its credentials permit the action. It should be: Why is this agent suddenly doing this?
There might be a legitimate explanation. Perhaps a DevOps team is retiring the space as part of an approved migration. Or perhaps an attacker manipulated the agent into ignoring its instructions. The permission alone can't tell security teams which scenario they're seeing. Behavior and context can.
Agentic AI security needs runtime visibility
That distinction becomes increasingly important as organizations deploy agents into environments already riddled with excessive privileges and technical debt.
Enterprise identities routinely accumulate permissions over time. Procedures aren't always followed. Access isn't always revoked. Security teams have spent years trying to clean up those problems.
Agents will inherit that imperfect environment. Worse, Cornberg noted, AI agents can understand exactly what they can and cannot access—and potentially discover different ways to accomplish their objectives.
Trying to eliminate every excessive permission before deploying AI may be unrealistic, particularly inside massive enterprises. That makes runtime monitoring critical.
Security teams need visibility into how agents behave while they're operating, whether their actions match expected patterns and whether the context surrounding a sensitive action makes sense.
The goal isn't to assume every deviation is malicious. It's to recognize that an unusual action deserves scrutiny before it becomes an incident.
That means agentic AI security may increasingly resemble the security controls enterprises already use around humans: establish expected behavior, watch for deviations, investigate unusual activity and intervene when necessary.
The difference is speed.
AI agents can execute sequences of actions far faster than employees, shrinking the window security teams have to recognize that something has gone wrong.
Cornberg's argument ultimately comes down to a deceptively simple shift in thinking. Security teams shouldn't focus solely on who an AI agent is or what permissions it has. They need to understand what the agent is actually doing with those permissions.
Because AI agents will make mistakes. The security challenge isn't pretending organizations can eliminate that possibility. It's making sure those mistakes don't become breaches.


