AI agents are moving from a productivity story into a security-operations problem. The Register reports that agents have already appeared in real-life attacks in recent weeks, while also creating new defensive questions for organizations that are beginning to connect them to sensitive systems and data. The central issue is agency. Earlier generative AI tools mostly produced text, code or analysis for a human to use. Agentic systems can be given goals and connected to tools, data sources and workflows. According to The Register, that shift introduces new data-integration channels attackers can abuse and adds a growing class of non-human identities that may not fit neatly into traditional access-control models. Matt Hartman, former acting head of cyber at the US Cybersecurity and Infrastructure Security Agency and now chief strategy officer at Merlin Group, told The Register that “tremendous risk” comes with agentic AI and machine identities. His view is that as AI systems begin taking actions rather than merely generating content, organizations will increasingly give agents access to sensitive systems and sensitive data. That means, he said, companies will need to treat every agent as a privileged identity. The external threat model is also changing. Hartman told The Register that AI-enabled or AI-amplified identity and social-engineering attacks are rising, citing highly personalized phishing, impersonation and automated reconnaissance. His recommendation was not a wholly new security doctrine, but a stricter application of existing controls: strong identity, phishing-resistant authentication, behavioral signals and zero-trust principles. The same capabilities that make agents useful to attackers can also be used by defenders. The Register frames agentic red teaming as an emerging defensive use case: using AI systems to continuously probe an organization’s own environment, identify weaknesses and surface likely attack paths before outside actors do. That argument was echoed by former NSA cyber leader Rob Joyce in remarks at RSAC, according to The Register. Joyce’s warning was blunt: organizations will be red-teamed whether they choose to pay for it or not; the difference is who receives the findings. Hartman similarly described a growing market for continuous, AI-native or AI-enabled automated red-teaming and penetration-testing capabilities. The story is still early and the provided evidence comes from one outlet, but the direction is clear enough for security teams to track. If agents are being granted tool access, data access or workflow authority, they become part of the identity and access-management estate—not just another software feature. Who benefits: Security vendors building around machine identity, phishing-resistant authentication, behavioral monitoring, zero-trust controls and automated red teaming could benefit if this concern becomes a budget priority. Internal security teams may also gain leverage from tools that test environments continuously. Who's exposed: Organizations connecting agents to sensitive systems or data without treating them as privileged identities are the most exposed. Traditional policies built around static users and predictable access patterns may be weaker against agent-driven workflows and AI-amplified social engineering.