The New Mandate for Security: Why I'm Getting My Hands Dirty with Agentic AI
You can’t assess the risk of a system you don’t know how to build.
As cybersecurity leaders, we’re facing an undeniable truth: the rapid, autonomous deployment of agentic AI systems is outpacing our ability to identify and assess the associated risks. We cannot wait for the industry to “catch up.”
That’s why I’ve taken an unconventional but, I’d argue, necessary approach to closing the security gap: I’m learning to be both the builder and the attacker.
Building, not just analyzing
Over the past several months I’ve immersed myself in the popular AI frameworks, actively building solutions rather than only reviewing other people’s. That hands-on work included:
- Designing RAG-based chatbot applications.
- Investigating methods of adversarial machine learning.
- Working through the deployment perspective of LLMs and tool integration.
The payoff is a clearer view of the new delta in the attack surface that agentic AI introduces. I can now map its specific security challenges on top of the traditional application security risks they sit beside, instead of treating “AI risk” as a single undifferentiated blob.
A practical mandate for security professionals
I regularly hear from security engineers, architects, and GRC professionals that they struggle to assess AI risk effectively. The technology moves too fast, and the traditional frameworks feel incomplete.
A builder’s perspective bridges the gap between abstract risk and practical control. It lets us move past generic concern and ask sharper questions:
- How is this model versioned and managed?
- Where are embeddings stored, and how is PHI/PII being secured?
- What’s the performance overhead of our security and safety guardrails?
- How, specifically, is prompt injection being prevented at the ingress layer?
None of those questions can be answered from a policy document. They’re answered by looking at the system.
The window before the frameworks catch up
The AI security landscape will mature. Standards will arrive, tooling will consolidate, and assessment will get more routine. Until then, the most effective security professionals won’t be the ones who wait for perfect frameworks — they’ll be the ones who understand the technology itself.
If you lead security and haven’t yet shifted part of your mindset from pure defense to an active builder’s posture, that’s the move worth making now, while the gap is still wide.