Salvatore Gariuolo, Senior Threat Researcher at Trend Micro, has spent years delving into the evolving landscape of cyberthreats. He sat down with Intelligent CISO to tell us how autonomous AI agents are changing the game, from the risks of their self-guided actions to the new security models required to keep them in check.

Tell us about the potential threats from an AI Agent that thinks and acts of its own accord? What are the potential consequences of that?
An AI agent that thinks and acts autonomously carries the risk of performing unintended, potentially harmful actions without the user realising it. It might, for example, send emails to the wrong recipients, alter calendar events, or delete important files. What’s more concerning is that users may not notice these actions as they unfold, losing the chance to intervene before damage occurs. This risk is amplified by the agent’s deep integration within digital ecosystems, where it routinely accesses and processes data from multiple services. Because of this integration, attackers don’t need to hack systems directly; they can manipulate the agent’s inputs or environments – such as embedding crafted prompts within the webpages it visits – to subtly steer the agent toward undesired behaviours. And since the assistant is no longer limited to answering questions or providing information, its actions can have real, tangible impacts in the user’s reality.
What’s being done to mitigate this threat? How can the industry ensure that AI agents don’t become a new, silent attack vector across different platforms and services?
Mitigating these risks starts with embedding safeguards that maintain user supervision and limit the agent’s autonomous reach. For example, OpenAI is building in explicit confirmation steps before their agent take sensitive actions – sending emails or making purchases – and blocking high-risk operations outright, like bank transfer. Access should be limited to only what’s truly necessary – not giving the agent full reach across the user’s entire digital ecosystem – striking a careful balance between convenience and control.
What are the key ethical and compliance challenges that need to be addressed at a systemic level?
At the systemic level, ethical and compliance challenges revolve around accountability, privacy, and informed consent. When AI agents act autonomously, it’s critical to define who is responsible if things go wrong – developers, users, or service providers. Privacy becomes complex as agents continuously learn about users and access interconnected services, raising questions about data handling and transparency. Ensuring users understand and consent to what these agents do, especially when decisions can have real-world impacts, is another challenge. Regulatory frameworks need to evolve to keep pace with AI capabilities, enforcing clear guidelines for safe, fair, and ethical AI use.
How can we design user interfaces and experiences that promote mindful, rather than blind, authorisation of critical actions?
Designing for mindful authorisation means creating interfaces that clearly communicate the implications of an agent’s actions and require deliberate user input. Instead of passive approval requests, interfaces should contextualise decisions – explaining what will happen and why user confirmation is needed. Step-by-step workflows, visual warnings for high-risk actions and easy ways to review or revoke permissions can help prevent consent fatigue. Still, this becomes more challenging as digital assistants move away from text-based interfaces toward voice input, and as agentic AI becomes more autonomous – reducing, by design, the number of interactions needed with the user.
Would you agree that with AI agents requiring access to a broad range of systems and data, traditional access control models based on human roles are becoming obsolete? What are your thoughts on this?
Traditional role-based access control models rely on clearly defined human roles and responsibilities, which don’t always translate well to AI. Many current AI tools – especially general-purpose digital assistants like ChatGPT’s new agent – require broad access because they handle a wide variety of tasks across multiple systems. For these tools, traditional role-based models struggle since the AI doesn’t fit neatly into a single role and may need to access many unrelated resources. That said, the future likely lies in more specialised agents optimised for specific tasks, which could better align with targeted access controls. So, while traditional role-based access models might not fit the current reality of AI tools, this challenge may diminish as agentic AI matures and becomes more specialised.
What new models or frameworks, such as a ‘least privilege’ approach for AI agents, are gaining traction across the industry to ensure that these agents have only the necessary permissions to function without creating unacceptable security risks?
The industry is moving toward ‘least privilege’ models for AI agents – granting them only the minimum access needed to perform their specific tasks. OpenAI, for example, applies this approach by restricting what ChatGPT agents can access and do. Crucially, users remain in control of these permissions, making it vital that they clearly understand which systems and data they are granting access to, along with the potential risks involved. Time-bound or task-specific permissions offer promising ways to limit exposure, and easy-to-use mechanisms for users to revoke access when needed are equally important.
Organisations are under immense pressure to leverage AI for a competitive advantage, often at the risk of cutting security corners. What strategies can help prevent this?
The pressure to adopt AI quickly can push companies to bolt new tools onto existing workflows without fully understanding what they’re introducing. That’s not just a security risk – it’s also a strategic one. Using the wrong tool for the job, or deploying it without clear oversight, can lead to inefficiencies, blind spots and a false sense of control. Organisations need to move deliberately: first by understanding what an AI tool is designed to do, what systems it can access, and what could go wrong if it misbehaves or is manipulated. That awareness needs to extend to users too – because even the best tools can be misused if people don’t know how to interact with them safely. Just as important is monitoring how the AI behaves – using real-time monitoring and regular audits to catch issues before they cause real damage.
What does the future of Agentic AI and security look like to you in an ideal world?
In an ideal future, agentic AI seamlessly augments human capabilities without compromising security or privacy. AI agents will operate transparently, with a clear understanding of their scope – escalating when uncertain, explaining their reasoning when asked, and deferring to human judgment where needed. Regulatory frameworks will balance innovation with protection, providing clear guardrails for ethical use. In this world, agentic AI becomes not a liability or a black box, but a secure extension of the user’s intent – trusted not because it asks for trust, but because it earns it.


