The security industry has long struggled with ambiguous definitions (zero-trust, anyone?) that leave too much open to interpretation. The term agent is no different. But in a weird twist, the term isn't being viewed too broadly, as is typical in security. Quite the opposite. Too many people are viewing the term agent too narrowly.

Over the last month of conversations with tech leaders, a clear pattern emerged. When they heard “agent,” they thought of something they build: an enterprise agent, typically custom-built or configured to automate end-to-end business workflows. Those conversations kept coming back to two types:

  1. Custom Agents: Coded by engineering teams, these typically live in hosted services like AWS Bedrock AgentCore, Microsoft Foundry Agent Service, or Google’s Gemini Enterprise Agent Platform (formerly Vertex AI).

  2. Low-code Agents: Assembled by any employee, they're more drag-and-drop or prompt-based, allowing you to build an agent that can automate specific tasks or workflows. Microsoft Copilot Studio was the most cited example.

While top of mind, enterprise agents are also the smallest agent population in environments today.

The agents you didn’t build

Most agents in use today are productivity agents. These are the copilots and assistants that help automate individual tasks or workflows. Things like Microsoft Copilot, Claude Code and Cowork, OpenAI Codex, and other coding harnesses like Cursor and Antigravity.

It’s no surprise they’re the majority. First, they’re actually useful. That’s why coding agents are now the de facto standard for writing code. Second, Microsoft is jamming Copilot down every user’s gullet. Note that I didn’t say Copilot is useful, but that’s an argument for another day.

So, why the confusion?

First, marketing teams are agent-washing everything. Every third word in every product pitch is “agent,” which muddies what an agent actually is.

Second, many people still equate productivity agents with chatbots. Generating documents or images doesn’t feel very risky. But chatbots aren’t just chatting anymore. They’re full-fledged agents that call tools, read data, and act on your employees’ behalf.

Just look at Anthropic’s latest move: “Claude Cowork and chat are now one Claude.” By definition, Claude is an agent. It’s given a task. It comes up with a plan to accomplish that task. It calls tools, reads company data, and writes code to do it. That “chatbot” has tools and acts independently.

The irony is that while most concern centers on enterprise agents and the damage they could do, those agents also get the most security scrutiny and are the most locked down as a result.

Meanwhile, employees are granting productivity agents more access and autonomy. Every productivity agent has become a one-stop shop for a threat actor. Compromise an agent, and you have a highway to all the applications and data that user connected to it. This isn’t science fiction. Researchers compromised an OpenAI employee’s account, took over their Codex agent, and used it to open a pull request to an internal repo.

We’re worrying about an asteroid strike while leaving all our doors and windows unlocked, with big neon signs telling thieves we have all our valuables inside.

Which brings me to my favorite commentary around the risk of productivity agents: “the frontier labs are accountable for security.”

You know, the frontier labs, like OpenAI…

And Anthropic…

If you’re a security leader who runs Microsoft products (e.g., Windows and Azure) in your environment and feels confident they’re best suited to keep you safe and secure, please raise your hand. I’ll take a vote…no one? Exactly.

An agent is software that acts

My definition of an agent: a product or code that, given an assigned goal and access to data and tools, operates independently in a loop to complete it. It’s quite literally a digital employee.

Enterprise agents act as a service, automating business tasks. Productivity agents act as an extension of humans, completing tasks on their behalf. Both are agents. Both bring new challenges that security teams must solve at a scale we’re not comfortable with.

The real challenge is securing many agent instances running in parallel across the business without taking the business offline. And like the employees they work for, agents cross identity, endpoint, data, cloud, and SaaS all at once. That’s why existing security tooling, built to secure one domain at a time, falls short. We have to think differently about visibility, governance, runtime controls, and detecting agent misuse or rogue behavior.

The asteroid may never hit, but while we’re distracted, threat actors are already checking which doors are unlocked. The first step in security is visibility. Start by understanding what every agent in your environment is doing today, both productivity and enterprise agents.

If you’re worried about employees misusing agents or about rogue behavior, let’s chat.

Reply

Avatar

or to participate