Autonomous agents force a shift from user-centric controls to machine-centric governance. The architectural problem is not simply more automation; it is that agents can act continuously, cross systems quickly and make decisions without the friction that human workflows naturally impose. For teams that built around logins, sessions and manual approvals, that means identity, authorization and monitoring have to be reconsidered for nonhuman actors that do not behave like employees.
The main implementation trade-off is where to enforce trust. If inspection happens too late in the stack, the agent may already have executed a harmful action. That is why browser-level or interaction-level enforcement is attractive: it can observe both rendered content and underlying page structure before the agent acts. But this also raises integration complexity, because security controls must align with application flows, policy engines and response automation without creating latency or breaking legitimate agent behavior.
Operationally, the bigger challenge is scale and change management. Traditional allowlists, dashboards and point-in-time reviews age poorly when agent activity is dynamic and distributed across many applications. Enterprises will need control planes that can define policy at agent creation, update permissions continuously and support real-time response. For platform teams, the key question becomes how to preserve auditability, least privilege and recovery paths while still allowing autonomous systems to run at machine speed.
Autonomous agents are rapidly redefining how enterprise systems operate, exposing new security gaps as machine-driven activity begins to outpace the infrastructure designed for human users.
Systems built around human identity and predictable workflows are struggling to keep up as autonomous agents operate continuously and move across environments with little friction. That shift is forcing enterprises to rethink architecture andย security models to handle a faster, less predictable risk landscape, according toย Ramin Farassat (pictured), chief product and strategy officer of Menlo Security Inc.
โCompanies are still building and theyโre securing their environment for human employees,โ Farassat said. โThey need to desperately re-architect their environment because thereโs going to be this big army of AI agents that are going to be coming up. Of course, we all want this massive speed and the scale that these agents are bringing to the table. The reality is that these agents, unfortunately, lack human intuition. If a hacker throws a zero-day exploit or if they want to do prompt injection to an AI agent, it doesnโt have that gut feeling that we as humans have to know that itโs being tricked. What happens is that it would just basically execute what itโs being told.โ
Farassat spoke with theCUBEโsย John Furrier for theย Google Cloud AI Agents in Action Series on theCUBE, SiliconANGLE Mediaโs livestreaming studio. They discussed how autonomous agents are transforming enterprise security, infrastructure design and real-time threat management. (* Disclosure below.)
Autonomous agents reshaping enterprise security models
As autonomous agents scale, security is shifting from reactive controls toย real-time analysis of behavior and intent. Traditional defenses built around known threats are no longer sufficient when agents operate at machine speed and interact with dynamic content, Farassat explained. This forces organizations to adopt architectures that can interpret context rather than rely on static rules.
โThe only way that we could build this architecture such that it can be resilient and be able to scale was that we couldnโt just react to known threats. We had to actually analyze the intent behind the website content in real time,โ Farassat said. โThat lets us be able to instantly block things like zero-day exploits, social engineering attacks and things that no one has seen before.โ
The operational model is also changing as security becomes embedded directly into agent workflows. However, the true shift isnโt just about implementing AI into the enterprise workflow, but integrating it directly into your security stack, which is exactly the philosophy behind HEAT Shield AI. Solutions leading the AI era focus on bringing AI to the initial point of defense: the browser. This allows AI to visually โseeโ what the user sees while simultaneously โreadingโ the underlying HTML and DOM to identify highly evasive threats. Instead of relying on manual intervention, systems are increasingly designed to allow agents to communicate, enforce policies and respond to threats autonomously. This introduces a new layer of automation that extends beyond detection into coordinated response, Farassat added.
โItโs machine-to-machine defense, itโs in real time and itโs completely automated, without a human ever having to click a button,โ he added. โThen on top of all of that automation and the defense, the agentโs still continuously running in the background and it can provide additional information to the human team.โ
Platforms evolve to meet agent-driven deployment
The rise of autonomous agents is also reshaping how security tools are delivered and adopted. Instead of long deployment cycles, organizations are looking for immediate integration within the environments where AI is already being built. This is pushing vendors toward platform-based distribution models that reduce friction and accelerate adoption, Farassat emphasized.
โAs we move into this new fast-paced agentic era, the way that we deploy security has to evolve,โ he said. โIt has to be instant, and it cannot require long integration projects. Thatโs exactly why we put our HEAT Shield agent on Google [Cloud] Original Postroduct/menlo-security-public/a2a-agent-v1-49b2?pli=1">Agent Marketplace. It completely removes the friction.โ
This shift extends into how organizations operationalize security at scale. AI interfaces are replacing traditional dashboards, enabling administrators to interact with systems through natural language and automated workflows. The result is a more fluid model where policies can be updated and enforced in real time without manual configuration, Farassat pointed out.
โUsing this AI technology, the security admin can now just interact directly with the Menlo agent and ask it things like, โShow me the current blocklist,โ or they can go and actually change a policy,โ he said. โThey say, โSwitch this threat response from logging to blocking,โ and AI just handles it for you.โย
Managing risk in a world of unseen AI activity
The proliferation of autonomous agents is also amplifying challenges around visibility and control. Shadow AI is no longer limited to isolated tools but is embedded across nearly every digital surface, making traditional tracking methods ineffective. This forces organizations to rethink how they identify and manage unseen AI activity.
โEvery site that you go to has AI. Every site is shadow AI, and every application is potentially a shadow AI,โ Farassat said. โThe lists almost become obsolete the second they come up. Using a list is really not the way, in our opinion, to be able to discover and deal with shadow AI.โ
Rather than attempting to contain agents at the perimeter, the emerging approach is to embed governance directly into their lifecycle. This includes defining policies at creation and continuously monitoring behavior as agents execute tasks. It reflects a broader move toward dynamic control models that scale with the agents themselves, according to Farassat.
โInstead, what we believe needs to be done is to start from the beginning,โ he said. โAs the agents are being built, set up specific policies within the agents. Make sure that you have control rights. But then, as the agents perform the task that theyโre performing and going to our platform, weโre still making sure that weโre providing the means for being able to look for things like prompt poisoning, be able to address different types of rights and access controls and set different policies that manage those agents at the scale of the agents themselves.โ
Hereโs the complete video interview, part of SiliconANGLEโs and theCUBEโs coverage of the Google Cloud AI Agents in Action Series:
(* Disclosure: TheCUBE is a paid media partner for the Google Cloud AI Agents in Action Series. Neither Google Cloud, the sponsor of theCUBEโs event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Image: SiliconANGLE
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBEโs Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni โ Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios โ with flagship locations in Silicon Valley and the New York Stock Exchange โ SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

