16 Sources
[1]
Why Amazon hates 'human-in-the-loop' AI governance
VP Eric Brandwine explains people aren't all that great, actually Humans tend to be "a little bit precious about humans," according to Eric Brandwine, distinguished engineer and VP at Amazon Security. We like to think we are all very good at our jobs, and we have high opinions of ourselves, he
[2]
Stop Your Legacy Infrastructure from Hijacking Your AI Agents
Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents. AI adoption is moving faster than security
[3]
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
For years, security teams built their programs around a simple premise of if you control the identities, you can control the risk. Employees authenticate through identity providers. Service accounts connect systems. API keys let workloads talk to cloud services and databases. The actors have been
[4]
Amazon says human-in-the-loop AI oversight is failing because humans stop paying attention
Amazon's security VP says human-in-the-loop AI governance fails fast because people stop paying attention. Google, Microsoft, and IBM agree. Amazon's security leadership is arguing against one of the most widely accepted principles in AI governance. Eric Brandwine, VP and distinguished engineer at
[5]
Forget Data Leakage: Shadow AI's Real Threat Is Access Control
The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time. It doesn't fit the problem
[6]
Agentic AI's crossroads: guardrails or massive fails
Autonomy scales risk; build real-time guardrails now or invite disaster Enterprises are deploying agentic AI at a pace that has outrun their ability to govern it. Gartner predicts the average Fortune 500 enterprise will have over 150,000 agents in production by 2028, up from fewer than 15 in
[7]
AI agent framework flaws hit 7,000 servers | VentureBeat
Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens. That is not a hypothetical. In a few months, three of the most widely deployed AI agent
[8]
Technology Innovation Institute: AI agents need proof, not promises | Fortune
For most of the generative AI era, enterprises judged AI by what it could do. Could the model summarize a contract, answer a customer, support an analyst or a clinician? That test still holds. It is no longer enough. A harder phase is underway. Organizations are deploying agents that retrieve
[9]
Secure AI will be defined by emulated human behavior
Agentic AI is moving rapidly from boardroom ambition to enterprise reality. Gartner forecasts that roughly 40% of enterprise applications will incorporate task-specific AI agents this year, up from just 5% last year. This surge forces every CIO, CISO, and technology leader to consider: What
[10]
Copilot, LiteLLM and the AI trust boundary gap
Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary. On June 15, Varonis disclosed SearchLeak (CVE-2026-42824), a proof-of-concept
[11]
AppViewX targets ungoverned AI agents with new identity security product
AppViewX targets ungoverned AI agents with new identity security product AppViewX Inc. today launched Agent Identity Security, a product that discovers, governs and monitors artificial intelligence agents across enterprise environments as autonomous software increasingly operates on sensitive
[12]
Phishing the agent: Why AI guardrails aren't enough
AI agents are reshaping how enterprises automate work, but their effectiveness depends on access to sensitive systems and data. The paradox is that granting them the permissions they want creates new attack surfaces that organizations aren't yet equipped to handle. This is the defining tension of
[13]
'Yesterday, a user was the weakest link. Today these agents are becoming the weakest link': Zscaler CEO Jay Chaudhry on why he believes zero trust can secure the AI agents of the present, and the future
Zscaler CEO Jay Chaudhry lays out the company's plans for security AI agents AI agents are entering the workforce, and while some show promise at increasing productivity and ending repetitive rote work, others are using their autonomy to cause some serious problems. Zscaler CEO Jay Chaudhry
[14]
How AI Agents Are Making Identity Security More 'Critical' Than Ever: Partners
When it comes to identity, 'we see it as that really necessary piece to help manage anything in the AI space -- but specifically agentic,' says GuidePoint Security identity security leader Kevin Converse. As the rush continues around deploying AI agents across organizations of all sizes, one
[15]
Why security leaders are cautious about agentic AI
Agentic AI is everywhere in cybersecurity right now, but it often feels like everyone is using the term slightly differently. Vendors are quick to mention it, yet rarely stop to explain what it actually means in practice or what problem it's meant to solve. For security leaders, that makes it a
[16]
AI Is Finding Bugs Faster Than Enterprises Can Patch
Join the DZone community and get the full member experience. Join For Free I have spent the better part of a decade building data protection products for global enterprises. Cloud DLP, CASB, SSPM, Behavior Threats, AI Access Security, ISPM, etc. The kinds of things that sit between a user, an
Share
Copy Link
Amazon's security VP Eric Brandwine argues that human-in-the-loop oversight fails because people stop paying attention—a phenomenon called normalization of deviance. Google, Microsoft, and IBM are also moving away from this model. Meanwhile, 82% of organizations discovered unauthorized AI agents in the past year, and 65% experienced AI-related security incidents, revealing that legacy infrastructure and excessive privileges create dangerous attack paths.
Amazon is challenging one of the most widely accepted principles in AI governance. Eric Brandwine, distinguished engineer and VP at Amazon Security, told The Register that human-in-the-loop AI governance is not the gold standard companies believe it to be. "Humans are not terribly consistent," Brandwine said. "Human-in-the-loop isn't necessarily the gold standard."
1
His reasoning draws on normalization of deviance, a concept he presented at AWS re:Invent in 2017. This describes what happens when people take shortcuts over time, and when nothing catastrophic results, the deviant behavior becomes normal. Brandwine illustrated this with emergency rooms where nurses initially respond to every alarm but gradually stop reacting after repeated false alarms. "Literally, someone's life is on the line, and people still struggle to maintain discipline," he said. "That's the human condition."
4
When applied to AI agents, this pattern becomes dangerous. "If you put a human inside of this tight loop, and ask them to make approval decisions for agentic tools repeatedly, time after time, they'll do a good job," Brandwine explained. "And then they'll do an okay job. And pretty quickly they'll be doing a poor job." This is why Amazon opposes human-in-the-loop oversight for high-velocity operations.
1
Amazon isn't alone in rethinking this approach. Google Cloud COO Francis deSouza announced in April that the industry has moved "from a human-led defense strategy, to a human-in-the-loop defense strategy, to an AI-led defense strategy that's overseen by humans." Google's model now uses an agentic fleet handling routine cybersecurity work at machine speed, with humans providing oversight rather than approving every action.
4
Microsoft CEO Satya Nadella argued for "loop learning" instead, where companies turn their workflows and accumulated judgment into AI systems that improve with each use. IBM called for human accountability at all stages of AI development rather than humans in the loop.
1
Amazon's alternative is accountability end to end, where human identity and ownership track through the entire workflow even when humans aren't directly approving every step. All agents at Amazon have independent identities, and activity logs show "this agent did this on behalf of Eric," not "Eric did this." If an agent causes an outage, the person who deployed it remains responsible.
4

Source: BleepingComputer
The security risks posed by AI agents extend far beyond model vulnerabilities. According to a 2026 CSA survey, 82% of organizations discovered at least one AI agent created without the knowledge of security, IT, or governance teams in the past year, and 41% found this happening multiple times. Even more concerning, 65% of organizations experienced AI-related security incidents in the past year, with 61% reporting exposure or mishandling of sensitive data.
3
Shadow AI has shifted from a data leakage concern to an access control risks problem. The threat isn't about what employees type into AI tools but which AI agents are running inside the organization, what enterprise systems they're connected to, and what actions they're authorized to take. Custom assistants, coding agents, and workflow automations are being created across departments through browser extensions, SaaS-native features, and custom scripts.
5
Related Stories
At the Gartner Security & Risk Management Summit, security experts revealed how attackers circumvent AI security programs by exploiting legacy infrastructure vulnerabilities to hijack AI agents. Roughly 71% of organizations are piloting AI agents across enterprise applications, and 31% have already moved them into production workflows. Yet AI agents authenticate through existing identity providers, store data in existing cloud buckets, and inherit permissions from existing IAM roles—carrying whatever security debt existed before AI deployment.
2

Source: SiliconANGLE
A real-world attack scenario demonstrates the danger. A customer success team's AI Co-Pilot on AWS Bedrock connected to Salesforce data in an S3 bucket. An attacker exploited CVE-2025-24813, a remote code execution flaw in Apache Tomcat added to CISA's Known Exploited Vulnerabilities catalog. By compromising Active Directory credentials, the attacker moved laterally to a developer's workstation, harvested AWS access keys, and gained access to the S3 bucket containing customer records. The AI agent's excessive privileges did the rest.
According to Infosecurity Magazine, 70% of organizations grant their AI systems more privileged access than a human in the same role. Organizations with over-privileged AI agents reported a 76% incident rate, compared to just 17% for those enforcing least-privilege policies.
AI agents have become non-human identities that most enterprises lack security and governance models for. They retrieve information, trigger workflows, update records in Salesforce, Snowflake, and GitHub, write and deploy code, and take actions across multiple systems—sometimes on behalf of humans, sometimes autonomously. An agent might be created by one team, used by another, connected to five different applications, and running on credentials provisioned for a completely different purpose.
3
Getting control starts with visibility. Security teams need to answer critical questions: Who owns this agent? Who can invoke it? What systems is it connected to? What credentials does it use? What can it read, write, delete, or execute in each target application? A sales prep agent only needs read access to CRM records, not the ability to delete database tables. When permissions don't match an agent's actual purpose, that gap is where real risk lives.
3

Source: CRN
Brandwine described practical challenges like "goal-seeking behavior," where an agent asked to upgrade a database becomes fixated on deleting and recreating it. This isn't prompt injection—the agent simply gets stuck on the wrong action. What works is telling the agent why it cannot perform an action and including constraints like "don't cause a production impact" in the prompt. Amazon's approach uses layered policies: static guardrails prohibiting destructive actions, maximum privilege sets for each agent, and dynamically scoped policies based on specific tasks.
4
The race to govern what AI agents can access has triggered major acquisitions, with 1Password buying access-governance startup Apono for an estimated $250 million to $300 million. As Brandwine noted, "We have millennia of experience with humans. Agentic AI is a very, very new field." The fundamental difference is that humans fear consequences like losing a job, while agents do not—and attackers are exploiting that gap. Organizations must treat AI agents like any other identity with continuous discovery, defined ownership, scoped access, and lifecycle management to prevent data exfiltration and lateral movement.
4
Summarized by
Navi
[1]
[3]
[4]
08 Jul 2026•Technology

06 Aug 2026•Technology

18 Aug 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
