Bottom line: Generative AI and AI agents require an expansion of security strategy to include new risk controls, as classic IT security measures do not fully cover the dynamic and autonomous nature of these systems.
The widespread deployment of generative AI and, in particular, autonomous AI agents brings significant new risks for enterprises. Security strategies must explicitly address these risks rather than treating AI adoption as a purely IT or business-unit project.
The commentary on Computerweekly.de addresses the fact that the use of generative AI in general, and of AI agents in particular, is associated with considerable risks for enterprises. Unlike classic software rollouts, generative AI systems and AI agents intervene deeply in business processes, increasingly make decisions autonomously, and in doing so often process sensitive corporate data.
For CISOs, this means expanding the existing security strategy to cover these new risk dimensions. Classic controls for access management, data classification and monitoring only partially apply to generative AI and agent-based systems, since these systems act dynamically and do not always produce predictable outputs. Responsibility for securing these systems therefore cannot rest solely with the business units or IT teams introducing AI applications — it must be actively shaped by the security function.
In practice, this means that security officers should be involved early in decision-making processes around AI projects, in order to assess risks such as unauthorized data access, faulty decisions by agents, or misuse of AI interfaces, and to establish appropriate controls before systems go into production.
Source: www.computerweekly.com · Published August 15, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.