Companies deploying artificial intelligence agents face a cybersecurity challenge that extends beyond protecting their own systems. A compromised agent could become a vehicle for attacking customers, suppliers and other business partners, exposing its operator to broader legal and financial consequences.
An analysis published Monday (Oct. 5) by the International Association of Privacy Professionals (IAPP) argues that businesses need to evaluate agentic AI through both cybersecurity and liability frameworks. Regulation could play a constructive role by establishing security standards that help prevent incidents and give compliant companies grounds to defend their conduct when safeguards fail.
The analysis builds on a Forbes article by technology executive Emil Sayegh, who says companies should treat AI agents as privileged identities. An agent connected to financial software, internal databases or collaboration platforms may possess credentials and authority comparable to those of an employee with sensitive access.
That requires companies to answer five foundational questions: Which AI agents are operating, and who owns them? What systems and data can they access? Which actions require human approval? Are their activities monitored? Can their access be revoked immediately?
For IAPP, however, identifying those controls is only the starting point. Businesses must account for the speed at which attackers could exploit an agent authorized to execute code, call application programming interfaces or change system configurations.
A compromised artificial intelligence agent could enable credential theft, privilege escalation or movement across connected systems before a human reviewer has time to intervene. That makes the design of defensive controls as consequential as the boundaries placed on an agent’s authority.
“Companies should be thinking about automated monitoring as well as automated containment,” the IAPP analysis states, including revoking access when specified conditions arise.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
Automation comes with its own trade-offs, however. An erroneous shutdown could interrupt legitimate operations, so companies must weigh containment triggers against business disruption. Nevertheless, IAPP warns that a posture dependent on human intervention may prove unworkable against rapidly progressing attacks.
On the flip side, AI agents themselves have no privacy rights, giving companies greater latitude to scrutinize their activities, although IAPP notes that different status does not eliminate a company’s obligations regarding personal information processed through an agent’s work.
If an incident does occur, the potential fallout is familiar. Companies could face operational disruption, customer and privacy notifications, public company disclosure obligations, regulatory enforcement and litigation, including class actions. An agent’s access and capabilities could increase the scope or severity of the damage.
The more difficult scenario involves harm outside the deploying company. IAPP describes an agent becoming a “pivot point” for attacks on business partners, potentially inserting malicious links or malware into routinely exchanged files. A trusted commercial workflow could thereby become an AI-enabled supply chain compromise.
For legal and compliance teams, that possibility makes contractual risk allocation particularly important. Liability limits and indemnity provisions could influence exposure, alongside negligence claims, the foreseeability of harm and the impact on affected partners. Public companies would also need to consider materiality.
IAPP’s regulatory argument follows from that uncertainty. Legislation establishing security duties could raise the standard of protection while giving companies a clearer benchmark against which to demonstrate reasonable conduct.
A company able to show that it met legislated standards of care could argue that it fulfilled duties owed to injured parties. The analysis presents that as a potential defense, rather than an automatic exemption from liability.
For businesses, the immediate task is to connect technical permissions, monitoring and containment with contractual obligations and incident planning. The regulatory debate is therefore also about defining what responsible deployment requires, and what evidence companies will need when an agent causes harm.