When agents move at machine speed, security teams lose their lag time
SiliconANGLE Valentina Villamil ● Covered by 5 sources
AI agents are pushing into company systems at machine speed. That’s making old security lag time useless, and CrowdStrike is moving defense to the endpoint.
Based on reporting by SiliconANGLE, Valentina Villamil — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
AI didn’t invent a new attack surface so much as it put a turbocharger on the old one. Autonomous software can now read, write and move corporate content faster than a human attacker, which is forcing security teams to rethink how they spot, govern and contain it. The uncomfortable part is that much of this activity lands on the endpoint, where tool calls and model context protocol connections actually run.
CrowdStrike is answering by extending Falcon to watch agents at that endpoint level. The company is treating each agent as an asset with its own identity and data footprint, according to Cristian Rodriguez, CrowdStrike’s field chief technology officer for the Americas. The idea is simple enough: if an agent can reach data, it needs the same kind of scrutiny as the system and identity tied to it.
Box is dealing with the same problem from the content side. The company added controls in July to govern AI agents working with enterprise files, and it uses CrowdStrike’s device posture score to decide whether a request for that content gets approved, according to chief information security officer Heather Ceylan. Her takeaway was blunt: the attack surface hasn’t changed, but the speed has. Humans are no longer the only attackers, and detections, visibility and responses all have to keep up in real time.
And the rush to adopt is creating its own cleanup job. Rodriguez said companies that moved early are coming back six months to a year later asking for visibility and data controls across SaaS apps, endpoints and cloud instances. They know the sprawl is real, and they want help getting governance under control after biting off more than they can chew.
There still isn’t a settled architecture for securing agentic AI, and there’s no cloud-style shared responsibility model to make it neat. Ceylan expects the next couple of years to be uncomfortable for CISOs, with security for AI changing by the day until the industry settles on a more standard way to control it.
My take — AI-written commentary, not fact-checked reporting
This is what happens when every vendor calls the same mess an innovation wave. The real product here is control, not magic: if an agent can act like a user and move like software, then treating it like harmless automation is just laziness in a nicer font. The people selling “AI transformation” now get to sell the mop too.
Read more about this at: SiliconANGLE