NewsTradingSentimentEventsCommunityBriefing
Tech

Cognizant: AI Agents Force CISOs to Rethink Trust and Control

By Tech Desk · · 2 min read
A digital shield protecting a network of interconnected nodes
Illustration: Tradingbird, based on a photo published by Cyber Magazine

Autonomous AI agents expand the cyber attack surface, requiring continuous verification of identities and actions rather than static perimeter defenses.

Key points

  • Autonomous AI agents expand the attack surface by allowing actions across multiple systems, increasing the operational blast radius of failures.
  • Context must be treated as a security asset because corrupted data leads to confidently wrong decisions at scale rather than simple data leaks.
  • CISOs are shifting from static policy reviews to continuous, evidence-based governance to ensure traceability and human accountability for AI actions.

The rapid adoption of autonomous AI agents has fundamentally shifted the cybersecurity landscape. These systems can interpret data, make decisions, and execute actions across connected networks with minimal human oversight. This autonomy introduces risks that traditional security controls, designed for static applications, are not equipped to handle.

Vishal Salvi, Global Head of Cybersecurity Service Line at Cognizant, argues that the recent surge in AI capability has altered the threat environment more significantly than the previous decade. The core challenge is no longer just preventing data leakage, but managing the operational consequences of an agent acting on corrupted or manipulated information.

Autonomy Expands the Operational Blast Radius

Traditional software operates within predefined rules, meaning a failure usually results in incorrect output without broader systemic impact. AI agents, however, can trigger unintended actions in other systems, disrupt business processes, or influence decisions with real financial stakes. The blast radius of a single agent failure is no longer confined to one isolated system.

This expansion creates new attack surfaces that legacy defenses ignore. Models, prompts, and data pipelines are now live targets. Since attackers and defenders both utilize AI tools, the advantage shifts to whoever can verify and secure these dynamic interactions first. Static perimeter defenses are insufficient against threats that move through the logic and context of the agent itself.

Context Becomes a Critical Security Asset

Context is both the superpower and the primary vulnerability of AI agents. When an agent relies on internal documents, customer records, or operational procedures, that data becomes part of its decision-making process. If this context is corrupted, the agent does not merely leak information; it makes confidently wrong decisions at scale, potentially causing widespread operational harm.

Organizations must treat context as a first-class security asset. This requires controlling not only what data an agent can access but also the actions it can take based on that data. The trade-off is clear: granting an agent broad access to be useful increases the risk of it being manipulated to act maliciously or erroneously.

CISOs Must Shift From Assumed to Provable Trust

The role of the Chief Information Security Officer is evolving to manage AI trust continuously. As reported by Cyber Magazine, this shift moves away from periodic policy reviews toward governance backed by evidence. CISOs must ensure traceability, auditability, and explainability of autonomous actions, maintaining human accountability even as the agent acts independently.

This requires defining clear ownership and escalation paths, especially where there is significant regulatory or financial risk. The catch is that this level of oversight demands new skills and continuous monitoring infrastructure. Organizations cannot simply deploy agents and rely on existing compliance frameworks; they must build mechanisms that prove trust rather than assuming it.

Based on reporting by Cyber Magazine, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories