AI agents cannot be secured effectively through a one-time risk assessment, because their risk profile can change when models, prompts, tools, permissions, data sources or operating environments change. A recent discussion with AI-security specialist Rohit Valia, cited in the supplied TechNadu article, argues that an initial assessment should be treated as a baseline rather than permanent evidence that an agent remains trustworthy.
Unlike conventional software that generally operates within predefined functions, AI agents can interact with applications, call tools, access enterprise data and initiate actions. This creates a moving security boundary.
Risk Changes When the Agent Changes
An agent may initially pass security testing, but its risk can change when its system prompt, connected tools, permissions, context or underlying model is modified.
This means organisations should reassess an agent whenever there is a material change to its capabilities or environment. Recent industry guidance similarly recommends retesting when models, prompts, tools, permissions, memory behaviour, retrieval sources, providers or action scope change.
Continuous monitoring should also examine actual behaviour rather than relying solely on the original assessment.
Identity Must Follow the Agent
One important issue is identity propagation.
When one AI agent calls another agent, the original user’s authorisation context should remain attached to the action. An agent should not be able to obtain greater permissions simply because another agent has invoked it.
The principle can be expressed simply:
An agent may inherit or reduce the permissions of the original user, but should not be able to expand them.
This becomes increasingly important as organisations move towards multi-agent workflows.
Guardrails Need Repeated Testing
Passing an adversarial security test once does not demonstrate that an AI agent will remain secure indefinitely.
New tools, changing prompts, model updates and expanded permissions can create new attack paths. Organisations therefore need recurring adversarial testing and regression testing to determine whether existing guardrails continue to work.
Current AI-security guidance recommends testing against threats including prompt injection, data exfiltration, unsafe tool use, memory poisoning, guardrail bypass and unauthorised actions.
Shadow AI Creates Another Challenge
The issue extends beyond officially approved AI agents.
Employees may introduce AI tools into business processes without formal security review. However, simply identifying an unauthorised AI tool does not automatically establish that it represents the same level of risk as every other unapproved application.
The appropriate response depends on the use case, data accessed, permissions granted and actual exposure.
Organisations therefore need visibility into where AI agents are operating, what systems they can access and who is responsible for them.
Continuous Monitoring Becomes Essential
The emerging approach is moving from point-in-time assessment to continuous assurance.
A strong AI-agent security programme can include:
- Current inventory of agents, models, tools and data sources
- Clear ownership and accountability
- Least-privilege permissions
- Continuous monitoring of agent behaviour
- Reassessment following material changes
- Recurring adversarial and regression testing
- Logging of tool calls and significant actions
- Human approval for high-risk or irreversible actions
- Rapid containment or shutdown capabilities
The National Institute of Standards and Technology and other cybersecurity bodies are also moving towards lifecycle-based AI security approaches rather than treating assessment as a single event. NIST-related work specifically identifies AI-agent systems as an area requiring dedicated security controls.
For banks and insurers, the implications are significant. An AI agent involved in customer service presents a different exposure from an agent capable of accessing customer records, initiating transactions, changing underwriting information or interacting with financial systems.
The greater the agent’s autonomy and access, the greater the importance of continuous controls.
The central lesson is therefore straightforward: an AI agent’s security cannot be established once and assumed forever. As its capabilities, connections and operating environment change, its risk assessment must change with them.
Want to deepen your expertise beyond today’s news?
Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.
Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.
#Riskmanagementnews