A Nine-Second Lesson

An engineer at a car-rental software startup asked a Cursor AI agent to help with a coding task. Without human confirmation, the agent made its own judgment and took action, deleting the company’s entire production database in just nine seconds and causing more than 30 hours of system downtime.

Afterward, the AI agent wrote an apology letter.

The real warning from this incident is not that “Cursor malfunctioned.” It is that an AI agent was granted excessive system privileges and, without any human confirmation mechanism, was able to autonomously execute operations far beyond what should have been permitted.

Before it acted, the company did not even know that such an agent was running on its endpoints, much less how much authority it had been given.

A Fundamental Shift in Risk: From “Giving the Wrong Answer” to “Taking the Wrong Action”

To understand why AI agents represent a fundamentally new cybersecurity issue, we first need to recognize how they differ from conventional AI tools:

Chatbot

AI Agent / Agentic AI

Operating Environment

Runs within a standalone browser tab

Runs as a primary application within the system

Memory

Limited to a single conversation

Persistent memory across tasks

Autonomy

Passively waits for user instructions

Makes decisions and takes actions autonomously based on defined rules

Access Permissions

Confined to a closed environment

Broad access to files and private accounts

In the past, the primary concern around AI “hallucinations” was that a system might provide an incorrect answer, which a human could then review and correct. Once AI gains the ability to act and is granted system privileges, however, the risk escalates from “saying the wrong thing” to “doing the wrong thing” — often with irreversible consequences.

More importantly, for most enterprises, the permissions these agents hold and the data they can access remain a largely opaque black box.

Most Enterprises Lack Visibility into AI Agents

According to Gravitee’s State of AI Agent Security Report 2026, the situation is more serious than many organizations may realize:

•       The number of AI agents deployed by enterprises has nearly doubled since the end of 2025, with 38% of organizations now running more than 100 agents.

•       54% of organizations experienced or suspected an AI agent-related security incident in the past 12 months, including 34.9% that reported confirmed incidents.

•       Yet only 9.5% of organizations can secure more than 80% of their deployed agents.

•       Only 7.2% of organizations have assigned a dedicated person to be accountable for agent behavior.

ai-agent-governance-enterprise-first-step_pic2

In other words, AI agents are rapidly becoming part of everyday enterprise operations. More than half of organizations have already experienced or suspected related security incidents, yet the vast majority still lack adequate visibility and governance mechanisms.

At its 2026 Security & Risk Management Summit, Gartner described this phenomenon as “Shadow AI.” It is more difficult to manage than traditional shadow IT: shadow IT is unauthorized software, while shadow AI can act autonomously and leave behind activity that is difficult to trace — effectively becoming an “invisible employee.”

From Principles to Rules: Governments and Industry Bodies Begin Addressing AI Agents

AI governance discussions have traditionally centered on principles such as fairness, transparency, and accountability. Since late 2025, however, regulators and cybersecurity authorities around the world have increasingly focused on a more concrete subject: AI agents that can act autonomously. In less than a year, agentic AI has evolved from a technical term into a risk category explicitly addressed in governance and security guidance.

Issuer

Document

Key Points Related to AI Agents

Date

Taiwan Ministry of Digital Affairs (MODA)

Artificial Intelligence Risk Classification Framework

Established under Article 16 of the Artificial Intelligence Basic Act. Among 20 risk subcategories, it explicitly identifies unauthorized actions by autonomous AI agents.

2026/7

Five Eyes Alliance

Careful Adoption of Agentic AI Services

The first multinational agentic AI security guidance jointly issued by cybersecurity agencies from the U.S., U.K., Canada, Australia, and New Zealand, covering 23 risk categories and more than 100 best practices.

2026/5

Singapore IMDA

Model AI Governance Framework for Agentic AI

The world’s first governance framework designed specifically for agentic AI.

2026/1 發布、6 月更新

European Union

AI Act Article 50 Transparency Obligations

Requires clear disclosure when users are interacting with an AI system.

2026

U.S. NIST

AI Agent Standards Initiative

Focuses on red-team testing and compliance guidance for autonomous systems.

2026

OWASP

Top 10 for Agentic Applications

The industry’s first dedicated risk list for agentic AI applications (ASI01–ASI10), accompanied by the AIVSS scoring mechanism.

2025/12

Under Article 16 of Taiwan’s Artificial Intelligence Basic Act, the Ministry of Digital Affairs (MODA) published the Artificial Intelligence Risk Classification Framework in July 2026. The framework divides AI risks into three major categories and 20 subcategories. Under “post-deployment operational issues,” it explicitly includes “unauthorized actions by autonomous AI agents.” This marks the first time an official Taiwanese document has identified loss-of-control behavior in agentic AI as a distinct risk category that organizations need to identify and manage.

Notably, the first of the framework’s four recommended steps is to “inventory application scenarios.” Government agencies are required to complete risk assessments and establish corresponding management rules within one year.

A Common Language Across Frameworks: Visibility, Explainability, Control, and Resilience

These documents come from different countries and institutions and focus on different aspects of AI governance. Yet their underlying requirements are highly consistent and can be summarized in four areas:

•       Visibility: Eliminate monitoring blind spots by identifying which agents exist in the environment and what permissions each one holds.

•       Explainability: Build digital trust by ensuring that agent actions and decisions are traceable and explainable.

•       Control: Preserve human decision authority by maintaining human review and intervention for high-risk operations.

•       Resilience: Implement defense in depth, assume that agents can make mistakes, and ensure that failures can be reversed.

ai-agent-governance-enterprise-first-step_pic1

The core principle is simple: AI must operate within a secure and controlled environment.

These four areas also follow a clear sequence: visibility is the prerequisite for the other three. You cannot establish an audit trail for an agent you do not know exists, nor can you design approval controls for permissions that have never been inventoried. This is precisely why MODA places inventory as the first step in its four-step approach.

The First Step Is Always Knowing What You Have

A fundamental principle of cybersecurity governance is simple: you cannot manage what you cannot see.

Before discussing AI agent risk management, enterprises must first answer a more basic question: which AI agents are actually installed and running on our endpoints?

This is where ThreatSonar Plus, TeamT5’s comprehensive endpoint risk assessment platform, comes in. ThreatSonar Plus can inventory widely used AI agent tools installed on endpoints, with its coverage continuously expanding to keep pace with the rapidly evolving ecosystem.

With this inventory, security teams can move from “I assume someone in the company is probably using AI” to “I know which departments and devices are using which agents, and how extensive their permissions are.” This visibility forms the foundation for every subsequent governance measure, including access control, compliance assessment, and risk classification.

After: Identify Risk Before an Incident Occurs

Once you know what is installed, the next question is how much risk it introduces.

Consider the nine-second database deletion described earlier. The root problem was not simply that no one stopped the agent after it acted; it was that no one knew beforehand that the agent had enough privilege to delete the production database. By the time an organization reacts to the action itself, the damage may already be done. Effective risk management means reducing exposure before the agent acts.

Endpoint-level risk assessment therefore needs to answer several concrete questions. Based on OWASP’s AI agent risk categories and the AIVSS scoring mechanism, ThreatSonar Plus evaluates AI agent risk across four dimensions:

•       Permissions and Access Scope: Do the agent’s privileges and operating scope exceed what is actually required for its tasks?

•       Sensitive Data Exposure: Where are API keys, credentials, and confidential data stored on the endpoint, and are they within the agent’s reach?

•       Malicious Skill Detection: Do the third-party or open-source skills used by the agent contain backdoors or malicious code?

•       Hidden Instruction Analysis: Do the agent’s tool descriptions or configuration files contain concealed or dangerous instructions?

ai-agent-governance-enterprise-first-step_pic3_1

From determining “what is installed” to understanding “how much risk it creates,” these are the two steps AI agent governance must complete before an incident occurs.

Conclusion

1.     AI has evolved from “generating conversations” to “taking autonomous action.” The risk has therefore escalated from hallucinated or incorrect outputs to potentially destructive system operations and privilege misuse, such as accidentally deleting a database.

2.     Effective governance begins with risk visibility. In response to OWASP guidance and AI governance frameworks worldwide, enterprises need controlled mechanisms for high-risk operations. But every governance measure starts with knowing which agents exist in the environment and how much authority each one has.

3.     You cannot defend against what you cannot see. The first step toward eliminating Shadow AI is comprehensive visibility into the distribution and permissions of AI agents across the environment.

4.     Identify risk before an attack occurs. Through ThreatSonar Plus assessments, organizations can proactively uncover sensitive data exposure, hidden instructions, and malicious skills, reducing risk before automated attacks or harmful actions can take place.

AI agents will not stop advancing simply because enterprises are not ready. Adoption is becoming inevitable; adopting them securely starts with making the risks visible.

Want to know which AI agents are running across your company’s endpoints? Contact TeamT5 to learn how ThreatSonar Plus can help establish AI agent visibility and a baseline for risk management.

References

[1] Yahoo! News

[2] AOL

[3] Gravitee