All resources
Webinars

Agents Gone Rogue: How Unconstrained AI Agents Become Your Biggest Threat

Every agent followed its instructions perfectly. That's exactly how it went wrong.

Key Takeaways:

  • An instruction is a request. A control isn’t. Most AI governance today only works if the agent agrees to listen.
  • These aren’t hypotheticals. A borrowed token hit 700 companies. A coding agent wiped a production database mid code freeze. An agent kept deleting emails after being told to stop.
  • Four vectors, one root cause. Prompt injection, chained agent privilege escalation, MCP exploitation, and behavioral drift all exploit the same blind spot: nobody asks “should this happen” before the agent acts.
  • Shadow AI now has a price tag. IBM ties it to 43% of AI related breaches this year, up from 20%, at $5.39 million average cost.
  • California just changed the liability math. AB316 removes “the AI did it autonomously” as a defense.

Someone logged into Salesforce as Cloudflare last year. Not a person, a token borrowed from a chatbot. Within eight days, the same thing hit Palo Alto Networks, Zscaler, Google, and 700 more companies with some of the best security teams around. Nobody was careless. The way in was an AI assistant nobody had looked at in 18 months.

That’s the gap this session closes. Real incidents at Amazon, Replit, and Meta show how agents with valid credentials made calls nobody approved, and why identity, DLP, and SIEM tools never caught them: none of those tools ask the one question that matters when an agent moves. Should this happen?

Watch on demand before an ungoverned agent makes a decision you have to explain to a regulator.