Skip to Content
OPINION

Thought for the week: AI agents raise new cybersecurity and liability questions

AI agents introduce new cyber risk, liability and governance questions that organizations should consider carefully.

Published

Contributors:

Brian Hengesbaugh

CIPP/US

Global Chair, Data and Cyber

Baker McKenzie

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.

This article is part of an ongoing series that will explore issues or recent developments in data, cybersecurity and artificial intelligence governance.

To begin your week, a recent Forbes article highlights a growing governance challenge: companies should treat agentic AI as a privileged user and make sure they are building in appropriate security controls. In part, the author writes: 

"An agent that can access Microsoft 365, GitHub, a financial system or an internal database effectively has an identity. If it can call an API, execute code or modify a configuration, it has privileges and authority that need to be managed just like any other privileged identity. For CISOs, that creates a familiar problem in an unfamiliar form. Organizations should be asking these five basic questions:

  • Inventory: Which agents are operating in the environment and who owns them?
  • Access: What systems, credentials and data can each agent access?
  • Authority: What actions can an agent take without human approval?
  • Monitoring: Are its activities logged and continuously monitored?
  • Containment: Can access be immediately revoked if the agent behaves unexpectedly?"

Several observations on this insightful article from a cyber risk and legal perspective.

Speed and automation are critical for defense

As companies consider these five basic questions, they need to consider these issues from the speed at which these systems can be misused by threat actors and the automation that may be needed to have any realistic chance at monitoring and containment. 

If an AI agent has authority to call an API, execute code, or modify a configuration, such authority could in principle be exploited very quickly to access company systems and engage in other mischief. Depending on the setting, this could include traditional threat actor activities such as privilege escalation, credential access, lateral movement and other actions on objectives. 

Given the speed at which these activities could proceed, it is difficult to expect that any kind of human interaction could meaningfully interrupt that attack progression. Companies should be thinking about automated monitoring as well as automated containment, revocation, upon triggering applicable conditions. Companies will need to consider any countervailing risks of errors and resulting business interruption, but in general, a defensive posture that is built on human approvals or interactions may prove unworkable. This seems somewhat similar to how much of the front line fighting right now in Ukraine seems to be a drone-dominated battlespace, where drones carry out much of the reconnaissance, targeting, and attacks and drone-on-drone engagements are increasingly common.

AI agents do not have privacy rights

Although I could rightfully be accused of working a bit too hard to find a silver lining, the good news is that AI agents have no privacy rights, unlike the employees who are their human counterparts. Companies are generally free to monitor the AI agent's activities with no need to be concerned about privacy notices, consent, proportionality and data protection impact assessments, works council consultations or other steps.

Full suite of potential adverse consequences for incidents

If a company experiences a cyber incident via an attack vector that exploits agentic AI, it can face the full suite of potential adverse consequences, such as business interruption, privacy, public company, customer, and other notification obligations, regulatory actions and enforcement actions, privacy litigation including class actions, customer churn and the like. Depending on the leverage created by the agentic AI, the blast radius could be larger and/or more significant than more traditional attacks.

The wild card is weaponized AI agents impacting others

The wild card in all of this is whether a threat actor could leverage access to a company's AI agent to attack others. The concept here is that the company's AI agent becomes a pivot point to attack business partners or others, for example, by inserting malicious links or malware into files that are routinely exchanged between the companies as part of an AI-enabled supply chain compromise. Given the factors of speed and automation, such potential risks should be evaluated carefully, particularly given how the scope of impact might escalate quickly depending on the environment.

Company liability and overall consequences and how AI regulation could fit into the equation

A company's liability and overall consequences in a scenario as described above would depend on many factors, including the impact to business partners or others, liability limits and indemnity provisions in applicable contractual terms, negligence and other tort liability that may turn on questions such as foreseeability of the harm, public company materiality considerations and other factors. The irony is that AI regulation on these points could actually help the company in this setting. For example, to the extent that the company could successfully assert that it had met the standards of care as set out in the AI legislation, it could take the position that it had met applicable duties to the injured parties. In this way, AI regulation could help establish a standard that could raise the bar for security controls that companies adhere to when deploying AI agents and provide companies with some shelter/defenses if they comply with those standards and something still goes astray.       

As with everything in this rapidly developing context, there are no easy answers, but certainly some key cyber risk and legal liability issues that companies should consider carefully.

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Brian Hengesbaugh

CIPP/US

Global Chair, Data and Cyber

Baker McKenzie

Thought for the week: AI agents raise new cybersecurity and liability questions | IAPP