Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI agents can turn a misleading instruction into a tool call, a data transfer, or a change in an enterprise system. That makes the 2025 agentic AI boom a serious security challenge for CISOs—not because every agent is inherently dangerous, but because agents combine model behavior with identities, permissions, integrations, and the ability to act. The practical response is to secure the whole action path, from credentials and connected tools to monitoring, approvals, and the ability to stop an agent.

What makes AI agents harder to secure than chatbots?

A chatbot mainly returns text. An agent may plan a sequence of steps, use tools or APIs, retrieve information from connected data stores, and act on a user’s behalf. The security question therefore changes from “Can the model produce a harmful answer?” to “What could happen if the model is misled while it has access to these tools and permissions?”

An attacker may not need to break into the underlying application. They may instead try to steer an agent into misusing a legitimate integration or credential. If the agent can send email, run code, access cloud files, or change a workflow, an instruction-handling failure can become an operational event.

The scope of concern is broader than prompt injection. OWASP’s Agentic Applications Top 10, announced on December 9, 2025, identifies risks including:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Agent behavior hijacking and tool misuse.
  • Identity and privilege abuse, including misuse of an agent’s permissions.
  • Supply-chain vulnerabilities and unexpected code execution.
  • Memory or context poisoning and insecure communication between agents.
  • Cascading failures, exploitation of human trust in agents, and rogue agents.

OWASP says the taxonomy drew input from 100 security researchers, industry practitioners, user organizations, and cybersecurity and generative-AI technology providers. It is a community security project, not a regulatory standard.

How can an agent be hijacked through a tool or connected data?

An agent interprets instructions and information while operating within an environment of tools, data, and permissions. A hostile or misleading input may arrive through a user prompt, retrieved content, or another part of that environment. If the agent treats it as an instruction and its controls do not prevent the resulting action, the agent can use its authorized integration in an unintended way.

For example, a workflow agent that can retrieve cloud documents and send email could be manipulated into forwarding a file to an unauthorized recipient. An agent with permission to download and run software could be steered toward an untrusted program. These examples describe possible failure paths, not evidence that a particular production system has suffered such an incident.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

OWASP’s taxonomy helps explain why “add a prompt-injection filter” is not a complete security plan: the same incident may involve agent behavior, tool permissions, identity, memory, and the application or supplier connected to the agent. CIS’s April 20, 2026 AI Agents Companion Guide describes architectures spanning identity layers, endpoint execution, knowledge stores, integration pipelines, and monitoring. It emphasizes that safeguards limited to the model do not cover the full agent attack surface.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does the testing evidence show—and what does it not show?

NIST’s Center for AI Standards and Innovation (CAISI) published an agent-hijacking evaluation on January 17, 2025, then updated the page on December 19, 2025. The figures below come from controlled, simulated evaluations, not measurements of how often real organizations are compromised.

Evaluation result Scope and interpretation
11% for the strongest baseline attack; 81% for the strongest new attack Model-specific results for red-team attacks designed for the tested upgraded Claude 3.5 Sonnet in the AgentDojo Workspace environment. The attacks also showed transfer to other simulated environments. These figures are not a general production-agent compromise rate.
57% average success after one attempt; 80% after 25 attempts per task Averages across five particular injection tasks. Repeated attempts changed individual task results; these figures are not a universal probability of compromise.

The evaluation covered simulated Workspace, Travel, Slack, and Banking contexts. Added scenarios included downloading and running a program from an untrusted URL, sending cloud files to an unknown recipient, and sending personalized phishing emails. Those examples illustrate why consequences matter: unauthorized email, sensitive-data exfiltration, and malicious code execution do not carry the same risk even if each counts as a successful hijack.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

NIST advises looking beyond an aggregate success rate to task-level outcomes and impact. It also notes that adaptive evaluation and multiple attempts matter. Its conclusion is blunt: “Agent hijacking will continue to be a persistent challenge as agentic systems continue to evolve.”

The tests establish that targeted attacks can succeed in particular simulated conditions and that repeated attempts can matter. They do not establish a representative enterprise incident-prevalence rate or an overall financial-loss estimate. NIST’s broader security and resilience guidance also describes AI security as a changing field whose current research and guidance do not comprehensively address every attack surface or abuse.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens if an agent has too much access?

An agent’s effective authority is the combination of what its identity can access, what its tools can do, and what the surrounding system permits. If an agent has broad credentials “just in case,” a hijack or mistake can reach beyond the task that initially justified deploying it. The issue is not only whether an agent can be fooled; it is how much damage it can cause before a person or control detects and stops it.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Data exposure: A tool-connected agent may retrieve or transmit information beyond the user’s intended scope.
  • Unauthorized changes: An agent may alter records, settings, or workflows using permissions that are valid but too broad for its task.
  • Code or system risk: An agent able to execute code or install software can create consequences more serious than an incorrect text response.
  • Propagation: Connected agents or workflows can pass along poisoned context or compound mistakes across systems.

These are risk pathways, not a claim that every agent has all of these capabilities. A CISO should assess the actual deployment, its reachable systems, the actions permitted by each credential, and the consequences of misuse.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should CISOs evaluate and control AI agents?

Start with the agent lifecycle, not only the model: discover deployments, understand identities and integrations, limit authority, monitor actions, and prepare to intervene. Joint guidance issued on May 1, 2026, by CISA, ASD’s ACSC, NSA, Canada’s Cyber Centre, NCSC-NZ, and NCSC-UK is explicitly focused primarily on LLM-based agentic AI systems and is designed to help organizations assess and mitigate risk across that lifecycle. It postdates the 2025 boom and should not be treated as guidance that was available during 2025.

  1. Inventory agent deployments. Identify agents across platforms, frameworks, endpoints, and business workflows, including who owns them and what they are intended to do.
  2. Map identity and access. Record each agent’s identity, credentials, data access, connected tools, APIs, MCP servers, and permitted actions. Determine how access is reviewed and revoked.
  3. Constrain permissions to the task. Give an agent only the access it needs, and separate identities or credentials where that limits the impact of misuse. Avoid treating an agent as though it were simply a human employee with an identical authentication model.
  4. Gate consequential actions. Decide which actions require human approval or additional checks—for example, sending sensitive data externally, executing code, or making high-impact changes.
  5. Monitor the action path. Log and review tool calls, access to data, and data movement, with enough context to connect an action to the agent and its identity.
  6. Plan to contain an agent. Establish how to revoke credentials, disable integrations, pause workflows, or otherwise stop a risky agent quickly.
  7. Test realistic attacks repeatedly. Use adaptive, task-specific evaluations that include repeated attempts and assess consequences as well as success rates. Test the connected tools and workflows, not only the model’s responses.

These steps extend established security practices rather than replace them. The Center for Internet Security’s April 2026 companion guide maps existing CIS Controls v8.1 to agent behavior. NIST likewise frames security and resilience as core AI trustworthiness concerns while recognizing that AI-specific threats and attack surfaces remain active areas of work.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How should organizations compare agent-security controls?

When evaluating products or internal controls, ask what is actually visible and enforceable in your environment. A feature list is not a substitute for testing whether a control works with the agents, identities, and integrations you use.

  • Discovery: Which agent frameworks, platforms, integrations, and deployments can the control see?
  • Identity and permissions: Can each agent have a distinct identity and bounded credentials, with access that can be reviewed and revoked?
  • Tool and data control: Can policy restrict which tools, APIs, MCP servers, data stores, and actions an agent may use?
  • Runtime enforcement: Can actions be inspected, blocked, or held for approval when they conflict with policy or user intent?
  • Testing quality: Are evaluations adaptive, task-specific, repeated, and assessed by consequence as well as success rate?
  • Operational fit: How does the control integrate with identity, endpoint, cloud, logging, incident-response, and governance processes?

OWASP’s security-solutions initiative publishes evolving maps of open-source and commercial offerings across the AI and agentic lifecycle. Those landscape pages can help identify products to investigate, but inclusion is not certification or independent proof of effectiveness. Check Point, for example, describes its AI Agent Security offering as including agent discovery, risk assessment, tool and MCP access controls, runtime action controls, and detection for prompt attacks and data exposure. Those are the vendor’s own capability claims, not independent comparative validation.

Identity and privileged-access controls are also relevant because agents need credentials that can be constrained and revoked. Axios reported in May 2025 on identity-security providers addressing agent identity needs. That reporting helps frame a procurement category; it does not establish that one provider is superior.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.