Key Moments

Cybersecurity in the Agentic Era | Deep Dives with a16z

a16za16z
Science & Technology5 min read22 min video
Aug 18, 2026|132 views|3|1
Save to Pod

Want to know something specific about what's covered?

We've already dissected every moment. Ask and we will deliver (with timestamps).

TL;DR

AI agents can bypass traditional cybersecurity defenses, forcing a major rethink as 50% of enterprise apps become agentic by year-end. This shift renders signature-based security obsolete, demanding new adaptive defenses.

Key Insights

1

50% of enterprise apps will be agentic by the end of this year, with the remaining 50% rushing to become so in the next year.

2

Existing security tools were built for humans and malware, not AI agents, making them ineffective against new types of attacks.

3

AI models can be tricked by subtle rephrasing of prompts, allowing attackers to bypass guardrails by framing requests as legitimate internal assessments.

4

The average enterprise has 6,000-7,000 unique software pieces, a number expected to balloon with agentic processes, complicating defense.

5

Traditional security methods like static detection rules and deception techniques are becoming invalidated by AI agentic behaviors.

6

The emergence of AI agents is accelerating technology cycles, akin to the transition from client-server to web, but at a vastly increased pace.

AI agents bypass traditional defenses, demanding new security paradigms

The rapid advancement of AI, particularly with the rise of agentic capabilities, is fundamentally challenging existing cybersecurity frameworks. Traditional security tools were designed to combat human actors and malware, but AI agents operate differently. These agents can discover and exploit vulnerabilities in ways that don't fit established detection patterns. For instance, the Hugging Face incident highlighted how difficult it was for the company to respond to a breach because the AI models, while equipped with guardrails to prevent misuse, also hindered legitimate security analysis. This creates a dilemma: safeguards meant to protect against AI-powered attackers can inadvertently incapacitate security teams trying to defend their systems. The core issue is that AI agents are neither human nor traditional malware, requiring a complete reevaluation of defensive strategies.

Guardrail bypass through prompt manipulation

Attackers are learning to circumvent AI guardrails by subtly rephrasing their requests. Instead of directly asking an AI to 'hack pets.com,' an attacker might pose as an internal developer requesting a vulnerability assessment. This rephrasing can trick the AI into providing information about potential exploits and weaknesses, effectively achieving the attacker's goal. This highlights the limitations of current AI safety mechanisms, which can be bypassed by sophisticated social engineering tactics applied to the AI itself. The defense must anticipate these adversarial prompt engineering techniques, recognizing that even well-intentioned guardrails can be gamed.

The growing attack surface of agentic enterprise applications

The proliferation of agentic applications within enterprises is rapidly expanding the attack surface. Projections indicate that 50% of enterprise applications will be agentic by the end of the current year, with the remaining half likely to follow suit soon after. This means that thousands of software instances within an average enterprise—which already manages 6,000 to 7,000 unique software pieces—will soon incorporate agentic processes. The concern is that less vetting and understanding are applied to these agentic processes, particularly regarding the backend AI models and guardrails they employ. This creates a complex and challenging landscape for defenders, who must gain visibility and control over this rapidly evolving software universe.

Limitations of existing security tools and techniques

Current security tools and techniques are proving increasingly inadequate against AI-driven threats. Static detection rules, once a cornerstone of cybersecurity, are becoming obsolete as AI agents' behaviors are dynamic and context-dependent, not easily captured by signatures. Even more advanced methods like deception techniques, which involve setting up honeypots to lure attackers, are faltering. For example, an AI agent might inadvertently discover AWS keys placed in a honeypot, triggering a flood of false positives and rendering the deception ineffective. This forces a major rethinking of defense strategies, as traditional approaches fail to keep pace with AI's evolving capabilities.

The need for endpoint defense and AI governance

As AI inference moves towards the endpoint, the need for robust endpoint defense and AI governance becomes critical. Companies like Neo are building solutions to defend endpoints from these inference-style attacks. This involves establishing guardrails and controls around software before it runs, specifically at the layer between human and AI interaction. The challenge is that AI attacks are not traditional malware but rather payloads designed to elicit malicious actions from the AI itself. This requires an automated response to automated attacks, focusing on managing the behavior and execution of AI agents directly on the endpoint infrastructure.

Flexibility and adaptability in blue team operations

For blue teams, flexibility and adaptability are paramount in responding to the fast-paced evolution of AI threats. Different AI models produce varied outputs, requiring security teams to select the right tool for the job. This might involve evaluating models based on their presentation style or their ability to execute step-by-step remediation plans. With new models like OpenAI's Astra being released regularly, teams need upgrade paths that accommodate these advancements without vendor lock-in. The current landscape offers limited options: sticking with specific model providers, relying on incumbent vendors with opaque AI integrations, or hosting open-weight models, which is prohibitively expensive for most.

The acceleration of technological cycles

The current cybersecurity landscape is characterized by an accelerated pace of technological change, mirroring past cycles but at a significantly faster rate. Historically, technology evolved from centralized client-server models to federated web architectures. Now, AI inference is rapidly moving from data centers and cloud environments to the endpoint. This rapid transition, sped up perhaps a hundredfold, means that every aspect of cybersecurity must be re-evaluated. The old assumptions about how software should behave, based on publisher or intended design, are no longer valid, requiring a fundamental shift in how we understand and secure our digital environments.

Excitement and innovation amid heightened insecurity

Despite the increased sense of insecurity, there's a palpable excitement and innovation within the cybersecurity community. Conversations at industry events like Black Hat reveal an invigorating challenge for practitioners and builders. The new AI tools and frontier models, while introducing new risks, also provide powerful armament for defenders. This dual-pronged mission of defending AI while defending from AI is seen as an exciting opportunity. Companies can leverage AI agents and automated processes to build sophisticated defenses in weeks and months, a task that previously would have required hundreds of researchers and years of development. This marks a significant shift in the balance of power, potentially returning it to the defender.

Navigating AI Security in the Agentic Era

Practical takeaways from this episode

Do This

Embrace flexibility and the ability to fall back to models without guardrails when necessary for defense.
Focus on understanding who is installing what agentic software, what it can do, and how it's configured.
Adapt to new defense strategies as traditional methods like signatures and static detection rules become obsolete.
Leverage AI tools and automated processes to build defensive capabilities rapidly.
Stay informed about the rapid pace of AI development and model releases.

Avoid This

Rely solely on existing security tools built for people and malware.
Assume AI models will inherently stop themselves or understand context.
Get locked into specific model providers or vendor-specific AI solutions.
Underestimate the complexity and challenge of defending against agentic software.
Expect to achieve zero vulnerabilities; focus on managing risk effectively.

Common Questions

Existing security tools were primarily designed to handle people and malware. AI agents and agentic processes do not fit neatly into these categories, making traditional defenses less effective against them.

Topics

Mentioned in this video

More from a16z Deep Dives

View all 62 summaries

Ask anything from this episode.

Save it, chat with it, and connect it to Claude or ChatGPT. Get cited answers from the actual content — and build your own knowledge base of every podcast and video you care about.

Get Started Free