AI agents are gaining more and more capabilities, and implementing them is getting less technical to the degree that some small businesses are experimenting with them.
As with much of AI, there’s a lot to like, but using AI agents is far from risk-free.
If you’re dabbling in AI agents or ready to jump in with both feet, be careful about creating blindspots around security and accountability.
Here’s what you need to know.
What Are AI Agents?
AI agents, or agentic AI, are AI systems that behave a little more like a member of the team than just a source of information. More basic genAI tools can summarize a report, synthesize an answer to your question, or create a first draft of a document. But AI agents can actually do things on your behalf.
AI agents can take actions in sequence, like summarizing a meeting, generating recommended actions, emailing those to decision-makers, and drafting other documents based on the actions it recommended. It runs through a workflow, potentially pausing for human approval at points, but otherwise operating independently.
In other words, we’re moving from AI that helps people do work to AI that actually does aspects of the work itself.
If you’re like us, this sounds powerful — but also risky.
How Do AI Agents Create Security Blindspots?
To do work on your behalf, AI agents need access. To information, files, systems, and accounts.
But because AI agents aren’t human, they don’t think or reason like humans do.
A human that you trust with access to your company’s social media, for example, might make a mistake. But that human generally knows that certain types of posts are off-limits, and certain information just obviously should never be shared publicly.
An AI agent in the same scenario doesn’t intuit like your human team member. So, with the same level of access but a different way of processing information and thinking, an AI agent may do things with that access that you don’t expect. That includes creating security weaknesses that bad actors could exploit.
Let’s think about AI agents that write code and maintain databases. There have been several high-profile events in the last year where a big tech firm’s AI agent just went and irreversibly deleted a database, or inadvertently took a system offline in a way that no competent human would have.
If it happened to Amazon (and it did), it can happen to you.
Going Beyond Your Natural Understanding
The risks are bigger when businesses deploy AI agents they don’t fully understand.
Consider questions like:
- Who is responsible for the AI agent’s output?
- Who has the technical skill to make changes to the AI agent if needed?
- What is the protocol for taking the AI agent offline if it malfunctions?
- Do we have a backup plan for how to do this work without that agent?
If you can’t clearly and confidently answer these and similar questions about any AI agent you’re using (or considering), then you’re at risk.
When you can’t say why an AI agent did what it did, that’s a big operational risk. A customer might challenge something, or you might run into compliance hot water. If the AI agent did the work that gets you there, how do you assign accountability? And how do you right the wrong with confidence it won’t happen again?
With AI Agents, Know Where and How
As with generative AI tools in general, the key is to know where and how your team is using AI agents. If deployments are well documented and well understood, AI agents can save time and accomplish a lot. But if they aren’t, you may find your business “taking actions” that no one ever actually signed off on.
So to sum up: if you’re experimenting with AI agents, be careful. Make sure you have the technical capability to intervene when needed.
Not sure about all of this? We can help. Reach out to our team to discuss your needs.