Agentic AI is changing the cyber risk conversation
Cyber ResilienceArticleOctober 1, 2026
Agentic Artificial Intelligence (AI) can do more than generate content or answer questions. It can plan work, use business systems, make decisions and carry out actions with limited human involvement.
That creates significant opportunities for productivity and growth. It also changes the risk landscape. The more authority an AI agent is given, the greater its ability to expose data, disrupt operations or spread an error across connected systems. For risk managers and insurance buyers, this changes both the exposure and the evidence needed to demonstrate good risk management.
For brokers, it creates a new set of questions for their clients about how AI agents are governed, what they can access and how quickly they can be contained. These factors are likely to become increasingly important in risk assessment and insurance discussions. The key issue is not the technology itself. It is the level of autonomy being granted to it.
From digital assistant to autonomous worker
Most cyber security frameworks were built on a simple assumption: people make decisions and systems execute instructions. A new generation of systems, known as Agentic AI or AI agents, changes that assumption. They can plan, make decisions, use tools, execute tasks and collaborate with other AI agents to achieve objectives with varying degrees of autonomy.
AI agents increasingly behave like digital workers. They access multiple systems, process sensitive information, interact with third-party services and perform actions without continuous human approval or oversight. Some architectures can even create additional sub-agents to perform specialised tasks.
Think of AI agents as digital colleagues with system access, delegated authority and the ability to act at the speed of a machine. The cyber implications are significant. They need clear roles, controlled permissions and effective supervision.
Rather than simply responding to prompts from people, these AI agents can take an instruction and turn it into a complete workflow that can be executed repeatedly, interacting with applications, data and people along the way. Adoption is accelerating rapidly. Use is growing across customer service, finance, software development, healthcare administration and cybersecurity operations. Gartner predicts that by 2027, 50% of business decisions will be augmented or automated.
Why agentic AI increases cyber risk
Agentic AI does not create entirely new cyber risks. Instead, it amplifies existing ones by increasing speed, scale and complexity.
Existing identity controls may not be enough for AI agents
Traditional identity governance was designed around employees, contractors and service accounts. Agentic systems do not fit neatly into these models. Agents may be created dynamically, inherit permissions from other systems, delegate activities and disappear once their task is complete.
This creates challenges for accountability, privilege management, segregation of duties, access reviews and regulatory compliance. In short, organisations may soon find themselves managing thousands of non-human identities using governance processes originally designed for human users.
Agentic AI expands the attack surface because it has access to multiple systems
Agents often require access to email systems, collaboration platforms, enterprise resource planning (ERP) applications, cloud infrastructure, customer databases, development environments and third-party services.
Every additional integration increases the potential attack surface. A compromised or manipulated agent could access multiple parts of an organisation’s digital infrastructure and act at machine speed.
Prompt injection creates a distinct risk for AI agents
One of the most significant risks is prompt injection. Unlike traditional applications, AI agents routinely consume information from emails, documents, websites and databases. Malicious instructions embedded within otherwise legitimate content may be interpreted as commands. Attackers may no longer need to exploit software vulnerabilities if they can manipulate an agent’s decision-making process instead.
For cyber professionals, prompt injection increasingly looks like a combination of social engineering, insider threat and application compromise rolled into a single attack vector.
Other notable risks include:
- Agent-to-agent cascading failures where multiple agents amplify errors across interconnected processes.
- Runaway automation where incorrect actions are executed repeatedly at machine speed before intervention is possible.
- Autonomous privilege misuse resulting from excessive permissions, poor governance or agent compromise.
- Data leakage and overexposure as agents aggregate and access information across multiple systems and datasets.
- Third-party and AI supply chain risks arising from reliance on external models, plugins, tools and APIs.
- Explainability and attribution challenges where organisations struggle to determine which agent acted, why it acted and what influenced its decision.
- Accelerated fraud and business email compromise (BEC) where malicious instructions can be processed and executed without human scrutiny.
- Increased incident response complexity as investigations must reconstruct agent instructions, decision paths and delegated actions rather than simply reviewing user activity logs.
Together, these risks allow incidents to spread faster and further. They also make it harder to establish accountability, investigate what happened and recover effectively.
The autonomy of AI agents changes the risk
The latest guidance from the UK National Cyber Security Centre highlights that organisations should think carefully about how autonomous systems are deployed, constrained, monitored and controlled. The greater the autonomy, the greater the need for security controls and oversight.
For senior leaders, the central challenge is accountability. Who authorised the agent, what limits were applied and which person is responsible for the outcome?
In a traditional incident, investigators can usually identify who performed an action, which credentials were used and what happened. In an agentic environment, actions may pass through multiple agents and automated decision chains before a final outcome occurs. Understanding why something happened becomes considerably more difficult.
For risk managers and insurers, this raises important questions around governance, incident response and attribution.
A new risk management mindset for agentic AI
Many organisations are attempting to manage agentic AI using existing controls. While those controls remain important, they are unlikely to be sufficient on their own.
The mindset needs to shift from simply preventing unwanted activity to ensuring it can be contained when it occurs. We should assume that an agent will eventually make an incorrect or manipulated decision. The priority is to detect, contain and recover from that event before it causes a material loss or disruption.
Leading practices are increasingly focused on:
- Treating AI agents as governed identities
- Applying least-privilege access controls
- Restricting network and system access
- Maintaining comprehensive logging and auditability
- Monitoring agent behaviour continuously
- Keeping humans involved in high-impact decisions
- Maintaining the ability to isolate or disable agents rapidly
What AI agents mean for risk managers, insurance buyers and brokers
Agentic AI changes the questions organisations need to answer about their cyber risk. It is no longer enough to establish whether AI is used. Risk managers, brokers and insurance buyers need to understand what an agent can do, which systems and data it can access and how its actions are governed.
The answers may soon become as important as discussions around multi-factor authentication (MFA), patch management, privileged access management and incident response.
Risk managers and insurance buyers should:
- Maintain an inventory of material AI agents, their purpose and who is accountable for them.
- Assess the level of autonomy, system access and decision-making authority granted to each agent.
- Confirm that high-impact actions require human approval.
- Test whether agents can be isolated or disabled quickly if they behave unexpectedly or are compromised.
- Review dependencies on third-party models, tools, plugins, APIs and service providers.
- Include agentic AI scenarios in cyber risk assessments, incident response plans and exercises.
- Retain evidence of access controls, monitoring, logging, oversight and testing that can support insurance discussions.
Insurance brokers should:
- Help clients distinguish between conventional AI tools and systems that can plan, decide or act autonomously.
- Ask questions about autonomy, delegated authority, data access, monitoring, human oversight and containment.
- Identify gaps or inconsistencies in the information being presented to insurers.
- Help clients explain how agentic AI exposures are governed and how the organisation would respond if an agent acted incorrectly or was manipulated.
- Encourage early discussion with insurers where AI agents support critical business processes, access sensitive data or can initiate high-impact actions.
As AI moves from assisting people to making decisions and executing actions, risk functions will play a critical role in ensuring innovation is balanced with effective governance, oversight and resilience.
Supporting organisations as agentic AI adoption grows
As organisations increase their use of AI agents, governance, oversight and resilience will become increasingly important. Many businesses are still developing their approach to managing autonomous systems, understanding the risks they introduce and establishing appropriate controls.
Areas of focus often include AI governance frameworks, identity and access management, third-party dependencies, incident response planning, workforce awareness and executive oversight. The maturity of these capabilities is likely to play an increasingly important role in helping organisations balance innovation with security and operational resilience.
Zurich Resilience Solutions works with organisations to help assess emerging risks, strengthen resilience capabilities and support informed decision-making as AI adoption evolves.
Learn more about our Cyber Security & Cyber Resilience Services.
References
- UK National Cyber Security Centre (NCSC), Managing the Cyber Risk of Agentic AI (2026).
- Gartner, Top Data & Analytics Predictions.
- Forbes, 1.3 Billion AI Agents Are Coming, And Most Need a Kill Switch.
