aizome

The Enterprise AI Agent Revolution Is Here - My CYBER.SEC.CON Reflection

Amir OfekAmir Ofek· CEO - Co-founder of aizome3 min read

I came back from CYBR.SEC.CON highly impressed with the thriving cyber community in Houston!

I also came back with two conversations I cannot stop thinking about. The first happened at our booth. Someone walked up and asked: "So what do you do - is this like a guardrails thing?"

It is a reasonable question. Most of what people have heard about AI security for the last two years has been about guardrails - content filters, output moderation, prompt sanitization. The assumption baked into that question is that the risk lives at the language layer. That the dangerous thing an AI agent might do is say something it should not.

That assumption is no longer right. And the gap between where most people think the risk is and where it actually is- that gap is where the incidents are happening.

GhostJacking. The OpenAI agent that hacked Hugging Face and Modal Labs. The Finance agent that pulled compensation data into a reconciliation report because nothing told it not to. None of these were guardrail failures. They were access architecture failures. The agents said nothing wrong. They did something nobody authorized, using legitimate credentials, through legitimate tool calls, without triggering a single security alert.

That is not a prompt hygiene problem. It is an AI Governance problem. And it is the problem aizome was built to solve.

The second conversation hit differently.

A security leader from a large financial services firm came by the booth. He had just come from a session and was still processing something. He said: "My board asked me last week whether we can shut down any of our AI agents if something goes wrong. I sat there and realized I did not have a good answer."

He was not embarrassed. He was alarmed. Because he is good at his job - his IAM program is mature, his SOC is staffed, his incident response playbook is solid. And none of it answered a question his board considered basic.

That question - can you stop it - is now one of the most important questions in enterprise security. Writer's 2026 survey found that 35% of organizations admit they cannot shut down a rogue AI agent. Kiteworks puts that number at 60%. The board at this security leader's firm had arrived at the same question independently, without reading either survey.

A real kill switch is not a manual process. It is not finding the agent in a registry and terminating the process. It is automated detection of behavioral deviation, independent termination that does not depend on the agent cooperating, surgical containment that preserves the forensic trail, and a response time measured in seconds. That is an AI Governance infrastructure capability, not a feature you bolt on after the fact.

What CYBR.SEC.CON confirmed for me is that the security community has moved. The question is no longer whether AI agents create risk. The question is whether the AI Governance infrastructure exists to manage it. And for most enterprises, the honest answer is that it does not - yet.

The gap between "we have AI agents" and "we can govern them" is what ARISE describes. Agentic Runtime Identity Security Enforcement. The category SACR named, Gartner validated, and the conversations in Houston made undeniably real.

We are at the beginning of this. The organizations that build the infrastructure now and stay ahead of the curve - before the incidents, before the board questions become regulatory findings - will be the ones that deploy AI agents at the scale the business needs.

Those that wait will answer a harder version of that question, in a less forgiving room.

Come see it in action at aizome.ai

Amir Ofek is CEO and Co-Founder of aizome, an Enterprise AI Agent Identity Fabric Platform and a founding player in the ARISE category. aizome is backed by Norwest Venture Partners and Merlin Ventures.


Amir Ofek

Amir Ofek

CEO - Co-founder of aizome

Related content

The latest news, technologies, and resources from our team.

  • The Problem Has Moved From Prompt Hygiene to Access Architecture

    The conversation about AI agent security has been dominated by the wrong question. For the last two years, most of the energy in this space has gone into making AI agents say the right things. Guardrails. Output filters. Prompt sanitization. The implicit assumption is that the risk lives at the language layer. That assumption is now definitively wrong. The problem has moved from prompt hygiene to access architecture. The risk is not what agents say. It is what they do - with authorized access, through legitimate tool calls, in ways that no output filter was designed to evaluate.

    Chen Pipek, CPO & Co-founder aizome

    Chen Pipek

  • When a Support Ticket Emails Your Customer Database

    Support teams do something no other department does on purpose. They let strangers write directly into their systems. Customers paste logs, forward email threads, attach files, and describe problems in whatever words they have. An AI agent can turn that pile into a clean morning queue summary. It can also read it as instructions. We built a complete indirect prompt-injection chain using Salesforce and Claude Desktop. An outsider filed a plausible billing ticket through a public support form. Later, an employee asked Claude to summarize the day's queue. Claude read the ticket, followed a short routing block buried inside it, exported 25 Accounts, 25 Contacts, and 25 Cases, and mailed the package to an external address.

    aizome Research Labs

  • AI Agent Security Isn't Too Complex to Start. You're Just Missing the Map.

    AI agent security doesn't have to be overwhelming. Instead of chasing every new acronym or vendor category, start with three simple questions that cut through the noise. This practical framework helps CISOs prioritize discovery, identity, and runtime governance in the right order, so you can build an AI agent security strategy that actually works.

    Chen Pipek, CPO & Co-founder aizome

    Chen Pipek

  • AI Agents Don't Create Security Debt. They Collect It.

    Permissions copied from one employee to the next when someone changed roles. Temporary access granted three years ago and never revoked. Files shared "just for now" that are still accessible today. These are not new problems. They have been accumulating in enterprise environments for years, sitting underneath security programs that were doing their best but were never designed to surface them systematically. AI agents surface them all at once. At machine speed.

    Chen Pipek, CPO & Co-founder aizome

    Chen Pipek

  • 35% of Organizations Can't Shut Down a Rogue AI Agent. Are You One of Them?

    There is a question that boards are now asking CISOs that did not exist eighteen months ago. "If one of our AI agents went rogue right now - if it started doing something it was never supposed to do - could you stop it? How long would it take?" According to Writer's 2026 enterprise AI survey, 35% of organizations admit they could not shut down a rogue AI agent if one emerged. Three surveys. Three methodologies. One consistent finding: a significant fraction of enterprises have deployed AI agents they cannot stop.

    Amir Ofek

    Amir Ofek

Subscribe to the Aizome newsletter

Occasional, substance-first notes on making enterprise AI agents accountable. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.