Sunday 11 Oct 2026
main news image

ARTIFICIAL intelligence (AI) has fundamentally shifted from a futuristic concept to a tangible enterprise reality. A new class of autonomous systems, known as Agentic AI, is already at work, capable of independent reasoning, planning and execution.

This evolution demands that organisations fundamentally reassess the landscape, navigating both the transformative opportunities and the inherent risks that these systems introduce.

Unlike traditional generative AI models that respond to prompts, agentic AI goes further. These systems are designed to reason, plan and take action independently. Increasingly, they are integrated into enterprise environments to automate workflows, manage tasks and interface with internal tools, without the need for constant human oversight.

KPMG's latest quarterly pulse survey revealed that 65% of companies are already piloting AI agents, nearly doubling from 37% just three months prior, with 99% planning to deploy agents into production. As these agents are increasingly used to streamline processes and drive productivity, they are also introducing a new class of cyber risks that can no longer be overlooked.

Agentic AI systems differ from previous generations of AI in that they are designed to take action autonomously. They can access APIs, execute code, interact with enterprise software and even store and reference past decisions. In doing so, they function much like digital employees but without the built-in limitations or human intuition that governs responsible action.

This autonomy, while powerful, raises significant security concerns. Agents can inadvertently access sensitive information, interface with insecure systems or be manipulated by external actors, often with minimal visibility from the IT team. In our engagements with organisations across the region, we’ve observed several risks emerge:

1. Prompt injection and goal manipulation

Attackers can exploit poorly scoped instructions to redirect agents from their intended tasks or cause them to leak sensitive data. Even without explicit injections, vague or overly permissive prompts can be manipulated to trigger unintended actions, including disclosing information or abusing integrated tools.

2. Tool misuse and unsafe integrations 

Agentic systems often rely on third-party tools or APIs to execute tasks. If these integrations are misconfigured or lack proper access controls, attackers can exploit the agent's authority to perform unauthorised actions within enterprise systems. With organisations today using an average of 6.6 high-risk generative AI applications, the potential attack surface is already wide.

3. Credential exposure and impersonation

Agents may inadvertently access or expose sensitive credentials like API keys, tokens or login information that creates risks of privilege escalation or unauthorised system access. Identifying spoofing becomes a major concern, especially in multi-agent setups.

4. Remote Code Execution (RCE)

When agents are given access to code interpreters or scripting tools, attackers may inject malicious instructions to run arbitrary code. Without sandboxing and runtime controls, this opens up the host environment to compromise.

Why this matters 

Globally, adoption of generative AI is surging. Our 2025 State of Generative AI study shows that traffic grew by more than 890% in 2024, with organisations using an average of 66 GenAI apps, about 10% of which are considered high risk.

Most activity comes from writing assistants, conversational agents, enterprise search and developer platforms, which together account for nearly 84% of all GenAI transactions. Widely used tools such as Grammarly, ChatGPT and Microsoft Copilot are no longer just productivity aids but are evolving into agentic platforms that allow enterprises to build custom AI agents.

Closer to home, Malaysia’s rapid digitalisation has positioned it as a regional leader in technology adoption.

As Malaysian organisations across industries continue to embed generative AI in their day-to-day operations, agentic systems are following closely behind. The proliferation of these AI agents and apps is significantly changing the way Malaysians work and live, even as it transforms and expands the attack surface.

This widespread adoption necessitates a closer look at how these tools behave behind the scenes. Organisations must examine if these agents are overstepping security boundaries, storing information inappropriately or if the IT and security teams have visibility into their activities as well as the data they handle.

The first step toward securing agentic AI is visibility. Organisations will have to map out where AI agents are being used, what systems they interact with and what data they can access.

This is particularly when organisations are already unknowingly interacting with various GenAI applications and AI agents. Without this foundational understanding, risk mitigation is impossible.

Next, real-time monitoring will have to be implemented to oversee how agents operate. Policies should be defined that limit their access and capabilities based on context and role. Tools should be restricted to those with verified security controls.

And just as we’ve built zero trust networks around people and endpoints, we will have to apply the same discipline to AI. Because these agents are no longer tools, they are extensions of our workforce. They definitely can help us thrive but only if we’re intentional about how they think and act.

Agentic AI represents both a transformative capability and a critical security challenge. Its potential to accelerate innovation must be balanced against the risks of misuse, data exposure and systemic vulnerabilities.

For Malaysia to fully realise the promise of generative and agentic AI, organisations must integrate security considerations from the outset. This means treating resilience and trust as foundational elements, not optional safeguards. Only then can AI adoption drive sustainable growth and maintain confidence in the nation’s digital future.

Allen Chin is senior manager for solutions consulting (Malaysia) at Palo Alto Networks

Edited ByPathma Subramaniam
      Print
      Text Size
      Share