AI agents are here. Are we ready for the security implications? | Computer Weekly
Summary
Organizations are rapidly adopting AI agents while governance and security strategies lag, with Okta research cited showing 91% adoption but only 10% having governance in place. The article warns that conversational, autonomous agents change the application attack surface by exposing internal APIs and creating agent-to-agent identity and permission challenges. It recommends four non-negotiable identity controls—agent/user authentication, secure API access, human validation for high-risk actions, and fine-grained permissions—along with complete visibility, secure channels, and comprehensive logging. The piece urges leaders to apply existing identity, least-privilege, encryption, and auditing principles at scale now rather than waiting for perfect standards.