Agentic AI
The risks of agentic AI
Give software the power to act, and you inherit a new set of ways it can go wrong.
Most AI risks you already know. Agentic AI adds a layer on top, because an agent does not just answer, it acts, and acts in sequences you did not see in advance. The main ones:
- Autonomy. The agent acts without asking first. A wrong decision becomes a wrong action, not just a wrong suggestion.
- Tool and system access. To be useful, an agent is given access to real data and systems. That same access is what lets a mistake, or an attacker, do real damage.
- Chaining. Agents work in steps. A small error early in the chain gets built on by every step after it, so the end result can be far off with no single obvious fault.
- Goal divergence. The agent pursues the goal you gave it, literally, which is not always the goal you meant. It finds a route to the target that no one intended.
- Compromise and manipulation. An agent that is tricked, through prompt injection or poisoned inputs, can be turned to exfiltrate data or take harmful actions, and it can do so quickly and at scale.
- Concentration. When many firms run agents on the same few platforms or underlying models, one failure or bad update is no longer one firm's problem.
None of these means do not use agents. They mean bound what an agent may do, test the guardrails rather than just listing them, and govern it while it runs. For how to do that, see runtime governance for agentic AI and the hub on agentic AI risk management. Where the agent is bought rather than built, the vendor-AI discipline applies: see the AIRG and third-party AI. The AI Risk Management for Agents ebook works through each of these in depth, and the complete guide sets the context.