AI agents are inside the enterprise – are your security foundations ready for them?

AI agents expose the limits of software-only security

by · TechRadar

Opinion By Camellia Chan Published 14 August 2026

(Image credit: Getty Images)

Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter

The recent release of Anthropic Mythos is a wake-up call for the tech industry – and the fact that Anthropic themselves chose not to release it publicly speaks volumes about the level of risk we have now reached. AI agents have evolved from chatbots with upgraded capabilities to effective employees with database access, API keys, and system privileges.

Camellia Chan

CEO and Founder of X-PHY, a Flexxon brand.

However, the security protecting them is built on the same strategy that failed to stop ChatGPT jailbreaks in 2023. And this time, there’s no human to review an agent’s output, just an autonomous agent carrying out commands in a silo.

AI agents are reshaping enterprise systems and the way work gets done. Securing them requires an equally fundamental shift in thinking. Ultimately, now that agents act independently, resilience must be rooted in foundational controls, including hardware-level and lower-stack security, to be ready when the higher-level safeguards fail.

Latest Videos FromTechRadarWatch full video here:

How AI agents expand the attack surface

Before agentic AI, the biggest AI risks were bad recommendations, inappropriate responses, and conversational data exposure. Human oversight acted as a safeguard for every action, and AI systems operated without direct access to sensitive information. The primary concern was reputational damage rather than risks to underlying infrastructure.

When Anthropic released the Model Context Protocol (MCP) in November 2024, it established a standardized framework that allows AI agents to connect to databases, file systems, and enterprise tools. But within eight months, a critical vulnerability emerged (CVE-2025-49596, CVSS9.4), triggering emergency security responses across the industry.

The risk came from four factors working together. Autonomy means agents can decide and act without human review. Privileged access gives them credentials, tokens and file system permissions. Machine-speed execution leaves little time for human intervention. And cross-system reach means one compromised agent can move across connected environments.

Together, these factors expanded the attack surface far beyond what traditional security controls – even AI-enabled ones – were built to manage.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors