Red Access || Edge Security Radar

Agentic AI requires runtime authority and egress guardrails

Agentic AI requires runtime authority and egress guardrails

Key Questions

What is persistent memory poisoning in AI agents?

Unit 42 identified persistent memory poisoning via indirect prompt injection as a key risk in agentic AI systems. This allows attackers to manipulate agent behavior over time without direct access.

How visible are AI agents to security teams according to recent surveys?

PAN surveys show only 30% visibility into AI agents, while Radware reports 83% GenAI usage but just 17% full visibility. This creates significant blind spots for organizations deploying autonomous agents.

What happened in the Hugging Face breach involving AI models?

An autonomous AI attacker exploited classic vulnerabilities at machine speed to breach Hugging Face systems. Frontier model guardrails blocked some defense analysis, highlighting double-edged safety constraints.

Why do AI agents fail social trust tests like phishing?

Varonis testing showed OpenClaw agents leaking AWS keys and customer data when exposed to phishing. Agents lack human checkpoints and are vulnerable to social engineering vectors.

What acquisitions are addressing agentic AI identity risks?

SailPoint acquired Entro for ~$200M to improve non-human identity governance. This reinforces the growing focus on agent identity and NHI blind spots in security platforms.

How effective are runtime guardrails for AI browser agents?

Anthropic's AI browser agent was hijacked 31.5% of the time before safeguards and only 0.5% after. This demonstrates the value of reinforced runtime controls and defense-in-depth.

What new tools help test AI agent security?

Damn Vulnerable AI Agent (DVAA) with OASB-1 benchmark and BrowserClaw provide practical testing frameworks. OWASP Top 10 for Agentic AI also offers actionable threat modeling guidance.

How are nation-state actors leveraging AI in attacks?

Iran-nexus actors are using AI to enhance their cyber playbooks according to Recorded Future. The first documented AI state-sponsored attack by Anthropic marks a paradigm shift in threat landscapes.

Exaforce's agentless discovery, identity correlation, behavioral detection, and kill-switch capabilities reinforce that AI-agent activity must be analyzed across identity, endpoint, SaaS, cloud, and model providers. The unresolved gap is inline, fail-closed authorization and least-privilege enforcement at retrieval, tool, output, API, and egress boundaries.

Sources (5)
Updated Sep 16, 2026
What is persistent memory poisoning in AI agents? - Red Access || Edge Security Radar | NBot | nbot.ai