Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

AI agents raise new questions about security assurance

Security teams are under growing pressure to show customers and boards that their organizations can be trusted. But point-in-time evidence, such as audit screenshots and vendor questionnaires, may not show whether controls still work as risks change, argues Khushboo Kashyap, identified in the article as a Senior Director of Governance, Risk and Compliance at Vanta.

Kashyap says AI could automate the appearance of security controls as easily as the controls themselves. The article cites industry research indicating that more than half of UK security leaders believe AI-driven threats are advancing faster than their teams can respond, while 80% are already using or planning to use AI agents in security. It also says UK organizations spend around 12 weeks a year on compliance tasks and another nine weeks on vendor reviews.

The article argues that organizations need visibility into AI systems, including model APIs, tools embedded in software-as-a-service products, third-party agents, MCP servers and unsanctioned “shadow AI.” It says each agent should have its own identity and access limited to its assigned role, rather than sharing a broad service account.

Before deployment, teams should set access boundaries, decide when human approval is required and plan how to reverse actions. The article says high-impact actions, including changing user access, deleting data or moving money, should retain meaningful human oversight. It also calls for continuous runtime controls and evidence collection, so teams can detect changes and address control drift as it occurs.

Kashyap’s conclusion is that compliance should follow from effective security, with people, processes and systems coordinated continuously rather than relying on periodic audits.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.