Source : INDIA TODAY NEWS
Companies are moving beyond using artificial intelligence simply to generate content or answer questions. AI systems are increasingly being connected to enterprise identities, internal data, APIs, databases and other applications, while AI agents are being given the ability to retrieve information, make decisions, call tools and take actions.
That is creating a new challenge for cybersecurity teams. As AI becomes more deeply embedded in enterprise systems, securing the underlying infrastructure may no longer be enough.
advertisement
Companies also need to understand how their AI systems behave, what they can access and what actions they are taking.
“As AI becomes connected to enterprise identities, data and tools, securing the infrastructure around it is no longer enough. Security teams also need to understand how AI systems behave, what they access and what actions they take. AISDR is our approach to bringing that visibility and response capability into cyber defense,” said Hakimuddin Wadlawala, Founder, Aquila I.
The shift is particularly important as businesses move towards more autonomous, agentic AI systems that can interact with enterprise applications and data with limited human intervention.
AI IS CREATING A NEW CYBERSECURITY ATTACK SURFACE
Traditional software testing and cybersecurity systems are generally designed to identify known vulnerabilities, unauthorised access or clearly malicious activity.
AI systems introduce another layer of complexity because their behaviour can change depending on the data, instructions, tools and systems they interact with.
An AI agent, for example, may use a valid identity and legitimate credentials to access a database. On its own, that activity may not appear suspicious.
But if the same identity suddenly gains additional privileges, accesses an unfamiliar resource and makes an unusual sequence of tool calls, the combination could indicate that something is wrong. This means security teams need to look beyond individual events and understand the context surrounding AI behaviour.
“As AI systems become more autonomous, the question is not simply whether an action is technically permitted. Security teams need to understand whether the action is consistent with the system’s expected behaviour and intent,” said Wadlawala.
The risks can include identity misuse, excessive access, sensitive-data exposure, manipulation of tools or MCP integrations and what Wadlawala describes as goal or intent drift.
AGENTIC AI MAKES THE SECURITY CHALLENGE MORE COMPLEX
The growing use of agentic AI could make this problem even more difficult. Unlike conventional chatbots, AI agents can perform sequences of tasks, interact with tools and applications and make decisions along the way.
An agent could access a data source it has never used before, make an unusual series of tool calls, communicate differently with another agent or move beyond its normal scope.
While none of these actions may independently indicate an attack, the pattern could signal that something has gone wrong.
“Security teams need visibility across the AI environment, including AI systems, agents, model APIs, RAG pipelines, MCP integrations, identities and tokens, infrastructure and connected data systems,” said Wadlawala.
This becomes particularly important because a single AI workflow can span multiple parts of an enterprise environment.
THE CONCERN AROUND AI IS GROWING
The cybersecurity challenge comes at a time when concerns about increasingly capable AI systems are becoming more prominent among technology leaders.
Microsoft co-founder Bill Gates, in an essay published this week, warned that the world is entering a turbulent AI era and called for stronger institutions and international cooperation to manage the risks associated with advanced AI.
Gates has also highlighted concerns around AI-enabled cyberattacks.
The developments around Anthropic’s Claude Mythos show why cybersecurity is becoming such an important part of that conversation. Anthropic describes Claude Mythos 5 as a highly capable model for cybersecurity and biology research.
Because of its capabilities, access has been restricted to a limited group of vetted partners through a trusted-access programme.
Anthropic’s Project Glasswing, meanwhile, used Claude Mythos Preview with around 50 partners to identify more than 10,000 high- or critical-severity vulnerabilities across important software, according to the company.
The same capabilities that help cybersecurity researchers find vulnerabilities can also create risks if powerful AI systems are misused. This makes the cybersecurity challenge increasingly two-sided: AI can help defend systems while also becoming a powerful tool for attackers.
SECURING AI MEANS LOOKING AT MORE THAN THE MODEL
For companies, securing the AI model alone may not be enough. An AI agent could use an enterprise identity, call an application API, access a cloud workload and retrieve information from a database as part of a single task.
“AI security cannot be treated as an isolated layer. You need to understand the relationships between the AI system, its identity, the tools it can use, the data it can access and the infrastructure around it,” said Wadlawala.
Security teams therefore need to correlate AI activity with information from identity, endpoint, cloud, network, application and data security systems.
For example, an AI agent accessing a particular database may be entirely legitimate. But if it is simultaneously using a newly privileged identity and making unusual API calls, the combined behaviour could provide a stronger warning. The focus is consequently shifting from simply asking whether an action is allowed to determine whether it makes sense in context.
This is where the concept of AI Systems Detection & Response, or AISDR, comes into the picture. Wadlawala said AISDR is intended to give security teams greater visibility into AI systems and the relationships between models, agents, identities, infrastructure, tools and data.
“The objective is not just to create an inventory of AI systems. Organisations need to understand what those systems can reach, which identities and tokens they are using, what tools they are calling and what happened before and after a particular action,” said Wadlawala.
That visibility becomes increasingly important as organisations give AI systems greater autonomy.
AUTOMATION CANNOT REMOVE HUMAN OVERSIGHT
Greater automation in cybersecurity does not necessarily mean removing humans from decision-making.
Routine responses could potentially be automated, such as restricting an agent’s tool access, revoking a token or terminating a session when suspicious activity is detected.
However, actions with significant operational or business consequences may still require human oversight, said Wadlawala.
The distinction becomes more important as AI systems gain access to critical business infrastructure. The greater the autonomy, the greater the potential impact if an identity is compromised, instructions are manipulated or the system moves beyond its intended boundaries.
NEED TO START MONITORING AI LIKE AN ENTITY INSIDE THE ENTERPRISE
The larger change may be conceptual. AI systems are moving from passive tools that respond to instructions to active participants in business processes.
They can have identities, access permissions, connections to applications and the ability to take actions.
Companies may therefore need to monitor AI systems much like other entities operating inside their digital environments, understanding what they are doing, what is normal for them and what changes in behaviour could indicate a threat.
For businesses giving AI more control, the cybersecurity challenge is no longer limited to protecting the technology itself. It is about ensuring that when an AI system has the ability to act, security teams can see what it is doing, understand the context behind its actions and intervene when it moves beyond what it should be doing.
– Ends
SOURCE :- TIMES OF INDIA




