Amidst rising temperatures and bustling conversations in Riyadh, the focus of discussions for Chief Information Security Officers (CISOs) remains squarely on AI strategy. Every leader should be grappling with two critical questions:
- Are we actively developing, testing, and scaling AI agents to counter an anticipated surge in AI-driven adversarial threats?
- Do we possess the necessary intelligence to act with the speed of machines?
Why Focus on Agents Right Now?
Timing plays a pivotal role in the cybersecurity arena—so why the urgency to invest in agents for defensive purposes? We can break this down into two key aspects.
First, we need to address the risk posed by financially motivated adversaries, particularly those not tied to government entities. While state-sponsored actors may operate with more resources, the true concern lies in the autonomous offensive capabilities that could leverage frontier AI models for malicious purposes. Agencies like the Five Eyes have issued warnings regarding the misuse of advanced AI, signaling a looming threat. However, despite the anticipation, the widespread use of automated attack agents hasn’t manifested fully. So, what’s holding them back?
Although frontier models could theoretically enable sophisticated operations, they currently have limitations that prevent large-scale automated attacks. The challenge lies in balancing operational security with the adoption of third-party APIs—risking exposure—against the investment of resources to develop localized open-source models. The latter, despite their potential, demand substantial time, effort, and capital for effective use.
An experiment involving LibreChat and Dolphin-llama3:14b, conducted on a $3,000 local server equipped with suitable Nvidia graphics hardware, revealed that even seemingly simple tasks, such as creating a web shell, remain challenging. However, the barriers to entry in terms of both technical capabilities and costs are expected to decline rapidly over time, leading to increased opportunities for adversaries.
This brings light to a specific concept that should be on the radar of every defender: quantization. This involves simplifying AI models to use less memory, which can significantly lower the hardware requirements needed to run effective models. While this approach might slightly reduce performance, it makes AI capabilities more accessible. As the threshold for deploying functional models lowers, more opportunistic actors can mount attacks.
Ultimately, the primary threat isn’t the advanced frontier models, but rather the ability of adversaries to deploy competent local models on economical hardware. Given the pace of advancements in open-source models witnessed over the past eighteen months, the upcoming period could see further improvements that will empower financially motivated actors to orchestrate attacks at scale.
Thus, it's imperative for organizations to act decisively in developing defensive AI agents now rather than sitting idle. Just as we wouldn’t embrace autonomous vehicles without confidence in their performance, we can’t afford to ignore the learning process involved in refining agent workflows. Smart CISOs are establishing an AI control framework that promotes transparency in AI use, project ROI tracking, and code security, acknowledging that building and testing agents is an integral element of this larger initiative.
Prioritizing the Deployment of Agents
Now, regarding the practical aspect: where should organizations focus their agent efforts first? The effectiveness of agents is directly correlated with the quality of data they access and their ability to operate quickly. While there are numerous opportunities available, addressing the following three areas could yield significant benefits.
1. Continuous Threat Exposure Management (CTEM): Each stage of CTEM is ripe for agent involvement. Particularly, AI-driven vulnerability identification is seeing accelerated development, but reliable patches may not always be readily available. The game is defined by KEVs (Known Exploited Vulnerabilities), and establishing agent-based detection signatures must take precedence amidst a sea of often irrelevant CVSS scores. When combined with a thorough asset inventory and enumerated services, a compelling agentic workflow emerges, significantly enhancing CTEM outcomes.
2. Breach & Attack Simulation (BAS): This represents a shift towards ongoing adversarial assessments. Existing controls often fail to detect or prevent threats effectively. Given that an adversary’s AI can analyze and dismantle defenses in mere moments, validating coverage and identifying gaps ahead of an attack is crucial. The intelligence powering BAS should start with an understanding of adversary TTPs (Tools, Tactics, and Procedures), integrating ‘living-off-the-land’ tools and novel procedural adaptations. In the short term, agents can facilitate smoother interactions with BAS platforms, while in the long run, they may take over many of the platform-specific tasks.
3. Security Operations: There’s been notable activity among startups in the AI security vendor space focused on rapidly triaging alerts and incident response investigations. Harnessing deep intelligence sourced from indicators and artifacts gives agents a decision-making advantage in escalating, remediating, or closing incidents. Yet, organizations must balance the levels of automation against potential consequences; swift actions on minor issues should differ from decisions involving significant security implications, necessitating human oversight on critical matters.
Embracing Early Adoption of Agent Technology

The full realization of production-quality security agents may still be on the horizon, but organizations that invest in research and development now will foster greater resilience against evolving threats. The urgency to defend against rapidly developing capabilities is just heating up. By combining vendor expertise with internal AI and security knowledge, organizations can enhance their adaptability. Keeping humans in the decision loop where nuance matters while allowing agents to manage routine tasks is critical. The time to begin building and iterating on these agents is now.