Every headline this week wants you worried about attackers wielding AI like a scalpel, faster reconnaissance, smarter phishing, malware that writes itself. That’s the wrong worry. Unit 42’s newly unpacked 2026 Global Incident Response Report found the intrusions still landing are mostly boring: stolen credentials, bespoke remote access trojans, social engineering that would have worked in 2015. Meanwhile the actual disruption happening inside your environment right now is the AI you deployed on purpose. Agentic AI systems with standing permissions, no clear owner, and no audit trail are quietly becoming the biggest gap in your cybersecurity posture, and almost nobody is treating them like the privileged accounts they are.

Illustration representing AI's growing role in cybersecurity incident response
Unit 42’s 2026 findings suggest attackers are still winning with familiar techniques, not exotic AI tradecraft.

Cybersecurity’s AI Panic Is Aimed At The Wrong Target

Ask a room full of security leaders what keeps them up at night and you’ll hear some version of “AI-powered attacks.” It’s a good story. It’s also not what’s actually breaking organizations. Unit 42’s report describes threat actors using AI mostly the way everyone else does: to write better phishing copy, to speed up triage of stolen data, to automate the boring parts of a campaign they were already running. The intrusion vector hasn’t fundamentally changed. What’s changed is the volume and polish, not the sophistication of the initial foothold.

Look at Cisco Talos’s disclosure of UAT-11795, a financially motivated, Russian-speaking crew running a custom Starland RAT and a bespoke WLDR command-and-control implant against targets in the US and Europe. No AI arms race required. Just patient, well-funded humans building tools that work and reusing them until defenders catch up. That’s the actual threat landscape: purpose-built malware, not autonomous AI adversaries.

The Attackers Are Still Winning With Old Tricks

Microsoft’s Defender team also flagged a spike in ACR Stealer activity between late April and mid-June, leaning on ClickFix-style lures to harvest browser credentials, authentication tokens, and sensitive documents. It’s a technique that’s been effective for over a year now because it exploits a gap that has nothing to do with technology: a user who trusts a fake error message enough to paste a command into a Run box. No exploit chain, no zero-day, just a plausible-looking prompt and a moment of inattention.

This matters for how you allocate defensive effort. If your threat detection budget is chasing hypothetical AI-generated exploits while your actual exposure is credential theft through social engineering, you’re solving the wrong problem. Defense in depth means layering controls so that a single bad click doesn’t turn into a domain compromise, not betting everything on catching a sophisticated payload at the perimeter.

Your Own AI Agents Are The New Insider Threat

Here’s where it gets uncomfortable. Dark Reading’s recent piece on agentic AI makes a point that deserves more attention than it’s getting: the real risk from agentic systems isn’t that attackers will out-automate you, it’s that the AI agents you’ve already given tool access, credentials, and decision-making latitude to are operating with a level of autonomy your existing security hardening playbook was never built to govern. These agents can query databases, trigger workflows, send communications, and modify infrastructure, often with permissions scoped by someone who assumed a human would always be in the loop.

Who Owns The Agent When It Goes Wrong?

Ask your team right now who is accountable when an AI agent takes an action that causes harm, deletes the wrong record, approves the wrong transaction, exposes the wrong file. If the answer is vague, you have a governance gap, not a technology gap. Non-human identities already outnumber human accounts in most modern environments, and agentic AI is adding a new category that doesn’t fit neatly into existing identity and access management models. Treating an AI agent’s credentials with less rigor than you’d apply to a contractor’s laptop is how you end up explaining an incident to your board that started with a tool nobody remembered was still connected.

Control Isn’t Accountability, And That Difference Is Costing You

There’s a broader lesson here from an unlikely source. Security researcher Bruce Schneier recently highlighted law professor Daniel Solove’s argument in the Wall Street Journal that giving individuals more “control” over their personal data has failed as a regulatory strategy in the AI era. Solove’s case is that consent boxes and privacy settings put the burden on people who can’t realistically evaluate the risk, while the companies building the systems face little real accountability when things go wrong. His proposed fix, real liability for negligent design, duties of care, and structural accountability, maps almost exactly onto the agentic AI problem inside your own organization.

Giving a business unit “control” over configuring its own AI agent isn’t the same as holding that unit accountable when the agent misfires. If you want agentic AI deployed safely, you need the equivalent of a fiduciary duty applied internally: someone owns the risk, someone reviews the permissions, and someone answers for the outcome. Control without accountability is how shadow IT became shadow AI.

A person selecting an AI agent from a menu of automated options
Agentic AI systems often carry more standing permission than the humans who deployed them.

Hardening Agentic AI Before It Hardens Against You

None of this means abandoning AI tooling. It means governing it with the same discipline you’d apply to any privileged system. A few concrete steps that hold up regardless of vendor:

  1. Inventory every agentic AI system with write access, API keys, or workflow triggers, and assign a named human owner to each one.
  2. Scope agent permissions to the narrowest set of actions required, and revoke standing access the same way you would for a departing employee, on a schedule, not on discovery.
  3. Log every agent action at the same fidelity as privileged human activity, and feed those logs into your existing threat detection pipeline rather than a separate silo nobody watches.
  4. Require human approval for high-consequence actions, financial transactions, credential changes, external communications, regardless of how much the agent has “earned” trust.
  5. Fold AI agent misuse scenarios into your incident response plan explicitly. If your playbook only covers compromised humans and compromised servers, it has a blind spot.
  6. Reassess brute-force and firewall protections around the infrastructure agents touch. An agent with database access is a new lateral movement path even if the initial compromise looks nothing like a traditional intrusion.

None of these steps require exotic tooling. They require treating agentic AI as what it is: a new class of privileged actor in your environment, not a productivity feature you configured once and forgot about.

Frequently Asked Questions

Is agentic AI actually more dangerous than AI-powered attacks?
Not more dangerous in isolation, but far more under-governed. Attackers using AI still rely on known techniques your defenses can catch. Agentic AI systems inside your own environment often have standing permissions nobody is actively monitoring, which makes misuse or compromise harder to detect.
How is this different from standard shadow IT risk?
Shadow IT usually involves a tool a team adopted without approval. Shadow AI agents often have explicit approval but no ongoing ownership, meaning permissions get granted once during setup and never revisited as the agent’s role expands.
What’s the fastest way to start fixing this?
Run an inventory of every AI agent with API access, database access, or the ability to trigger workflows, and assign a named accountable owner to each one this week. You cannot govern what you haven’t listed.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.