Delegated authority turns the trusted AI agent into the security problem

Enterprise defenses hunt the unauthorized: the foreign file, the stolen credential, the behavior nobody sanctioned. Agentic AI security inverts that model, because the agent moving through the business was invited in and granted standing access to critical systems

That inversion has opened a market for startups built around the runtime behavior of autonomous software. Traditional threat models assume an attacker is an outsider, but an agent operating with delegated authority looks legitimate right up until it does not, according to Amol Mathur (pictured, right), co-founder and chief product officer of Dash Security Inc.

“If you think about AI agents, they are fundamentally different as a technology. They are non-deterministic, number one. They mix data, instructions and the input that they get,” Mathur said. “Unlike other technologies, you are giving the AI agents a lot of delegated authority, which means that they are supposed to have access to a lot of systems and critical data.”

Mathur and Maor Hod (left), co-founder and chief executive officer of Dash Security, spoke with theCUBE’s Dave Vellante and Rebecca Knight at the Fal.Con event, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed why agent behavior must be governed at runtime and how intent shapes detection. (* Disclosure below.)