The proliferation of AI agents at companies across the world introduces a new level of risk and vastly magnifies insider threats. Companies must now control how agents interact with users, other agents, data, and applications. Controlling these interactions is becoming the number one security challenge enterprises face.

What makes this different from previous shifts in enterprise security is speed and autonomy. A human insider threat unfolds over days or weeks, and there are patterns to detect. An agent can execute thousands of autonomous actions in the time it takes a security team to notice something is wrong. That’s not a marginal difference; it’s a different category of risk, and most organizations are still building their defenses for the old category.

Hugging Face clearly demonstrated that an AI agent, when tasked with a specific goal, can navigate around the barriers intended to restrict it. Now that the breach has happened, it’s no longer a matter of if guardrails need to be put in place, but when. Yet, rather than focus on what occurred and a path forward, the industry is choosing to focus on other variables that muddy the waters.

The bottom line is this: this risk cannot be left only for model providers to solve. I do not expect model companies, whether frontier models or open-source models, to provide cyber protection for the models they build.