> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# AI Agents Have Changed the Rules of the Game. Detection and Response Haven't Caught Up Yet
- URL: https://www.cybrsecmedia.com/gai-agents-have-changed-the-rules-of-the-game-detection-and-response-havent-caught-up-yet/
- Published: 2026-09-24T15:12:17.000Z
- Updated: 2026-09-24T15:13:59.000Z
- Description: As autonomous agents write code and manage infrastructure with scant oversight, the security frameworks built for predictable systems can’t keep pace.
- Author: George V. Hulme
- Tags: Agentic AI, Detection and Response, Article

Security teams that think they have visibility into their production environments may want to ask a different question: visibility into what, exactly? New Relic's 2026 Observability Forecast found that a quarter of organizations have deployed AI agents: systems that autonomously write code, change configurations, and manage with no monitoring in place. Those agents are operating in the shadows.

Nic Benders, chief New Relic technical strategist, warns enterprises are fundamentally misclassifying the nature, and therefore the risks, of their agents. "Organizations have given themselves a false sense of security by treating AI agents like other tools in their software and infrastructure stack," Benders said. "An AI agent isn't the same as a deterministic tool like Kubernetes, CloudFormation, or Autoscaling. As agents are given more autonomy to write code, change configurations, and interact with production systems, organizations need to account for the fact that they can make decisions and take actions that aren't entirely predictable," Benders added.

When an AI agent makes rapid, autonomous changes to software and production environments and detection, diagnosis, and response remain manual, the potential for damage grows faster than teams can contain it.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

New Relic's [2026 Observability Forecast](https://newrelic.com/press-release/20260922?ref=cybrsecmedia.com), based on a survey of 2,575 IT and engineering leaders and practitioners across 24 countries and 12 industries, found that 25% of organizations have deployed AI agents in production without monitoring. These are agents autonomously writing code, changing configurations, and managing infrastructure: the identical actions that would trigger mandatory logging and behavioral oversight under most enterprise security frameworks if they were performed by a human or traditional deterministic system.

That distinction matters more than many realize, because a deterministic system executes instructions in ways that should be anticipated and audited. An AI agent operating in a live environment can produce outcomes that weren't explicitly specified, including unplanned outcomes that result from manipulation, prompt injection, or behavior at the edge of its training. Without monitoring, there's no audit trail, no behavioral baseline to detect anomalies, and no forensics to determine what happened if the agent goes awry.

**Related:**

[AIpocalyptic Decisions - Andy EllisCYBR.SEC.Media is the ultimate hub for cybersecurity professionals and enthusiasts, featuring conference presentations, podcasts, articles, and research.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-8df1ea6d-9891-41da-8a78-253d7fd2771b.jpg)CYBR.SEC.Media, and CYBR.SEC.Media![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/Winn-Shwartau--1--bbf95ea4-9a56-4197-8327-b56ffb3f36bf.png)](https://www.cybrsecmedia.com/aipocalyptic-decisions-andy-ellis/)

[AI Security Failures Start With the Security BasicsAt CYBR.SEC.CON. 2026’s first AI.SEC.CON. track, Elizabeth Wharton argues that headline-grabbing AI disasters keep exposing familiar failures in validation, least privilege, data governance, trust boundaries and change control.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-c56e853c-3b59-4e35-991d-1def56df597f.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/ai.sec.con_1024-e42118a7-a207-4fbb-a8f8-203f4f539502.webp)](https://www.cybrsecmedia.com/ai-failures-arent-new-security-failures-liz-wharton-says-fix-the-basics/)

[AI Security Risks: Cyber Experts Separate Threat From FUDAs AI leaders warn of catastrophic risk, cybersecurity experts separate credible threats from speculation and identify the guardrails needed now.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-df1599ff-ced3-48ce-993e-99a37cebb4cf.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/AI-Core_-Alarm-and-Containment-6e3e707a-6109-4cb0-b62c-05c404cde0c0.png)](https://www.cybrsecmedia.com/ai-could-kill-us-all-cyber-experts-cut-through-the-fud/)

The report's detection and response numbers reinforce why the monitoring gap carries security weight. Engineers already spend 37% of their time addressing disruptions, up from 33% last year. The mean time to detect a high-impact outage is 41 minutes, and the mean resolution time is 54 minutes on top of that. That's roughly 95 minutes of combined exposure per incident, in an environment where agents may be making autonomous changes throughout. When the team building agent monitoring already spends more than a third of its capacity on reactive firefighting, the gap between where monitoring should be and where it is becomes self-reinforcing.

New Relic’s survey found some good news on outage costs. Survey respondents report losing an annualized $74 million to high-impact IT outages, down somewhat from $76 million last year. The top cited causes are third-party and cloud provider failures, followed by network failures and software change deployments. However, that last category is expanding as AI-generated code increases the volume and pace of production.

The research found organizations are deploying AI capabilities faster than they're building the instrumentation necessary to understand what those agentic capabilities are actually doing. However, organizations actively monitoring AI agents in production are twice as likely to report a 3x or greater return on their total observability investment compared to those that aren't (42% vs. 21%).

For security leaders, the takeaway is whether the security program has any visibility into what the organization’s agents are doing once they're in production. AI agents that autonomously modify production systems belong in the same visibility and audit tier as other privileged actors, and the data in this survey suggests the industry hasn't broadly reached that conclusion.

“The industry needs to be able to detect, diagnose, and respond to production issues at the same speed that increasingly autonomous systems can create change. We’ve been through versions of this transition before," Benders said.

In my career, we've gone from releasing software every six to nine weeks to thousands of deployments per week as cloud, microservices, and continuous delivery changed software development. That required the entire software delivery and operations pipeline to evolve. AI represents another step change in speed, and our detection and response practices need to evolve with it,” he concluded.