Cybersecurity has never evolved on its own timeline. It adapts to shifts in enterprise technology. Every major shift in how businesses operate has redrawn the attack surface and forced a corresponding reinvention of the security architectures to defend it. Agentic AI represents the latest and perhaps the most fundamental shift. Unlike previous waves that introduced new infrastructure or applications to secure, agentic AI introduces autonomous agents capable of making decisions and executing actions on behalf of the enterprise. Understanding why agentic AI demands a fundamentally different security paradigm begins with examining how cybersecurity has evolved alongside previous waves of enterprise technology.

Viewed collectively, these technology waves illustrate a steady evolution in enterprise security priorities. The internet exposed enterprise applications to external adversaries. Cloud computing dissolved the traditional network perimeter. Remote work shifted trust from location to identity. But AI introduces a fundamentally different challenge. Rather than simply adding another system to secure, it introduces software capable of reasoning, making decisions, and executing business tasks on behalf of users.
This transition fundamentally changes the objective of cybersecurity. The focus is no longer limited to protecting infrastructure, applications, identities, or even AI models themselves. As AI agents gain access to enterprise data, applications, APIs, and credentials, cybersecurity must increasingly govern how AI systems interact with enterprise resources, what decisions they make, and what actions they are permitted to execute. The scale of this shift is already evident. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 94% of organizations expect AI to be the most consequential force reshaping cybersecurity in the coming year.
This transformation is occurring at multiple levels. At the most immediate level, AI has become both the defender and the attacker. Security teams increasingly rely on AI to detect polymorphic malware, behavioral anomalies, and previously unknown vulnerabilities that traditional signature-based approaches often miss. AI is also enabling attackers to discover and exploit previously unknown software vulnerabilities much faster than traditional manual approaches, increasing the prominence of zero-day attacks. Beyond enhancing established attack techniques, AI is also introducing entirely new attack vectors. One emerging example is HalluSquatting, where attackers register software packages, repositories, or plugins that AI coding assistants consistently hallucinate. When these fabricated resources are recommended and installed, malicious code enters enterprise software supply chains through trusted AI workflows rather than traditional software vulnerabilities.
These attacks, however, are symptoms of a much broader architectural shift. Enterprise AI is no longer built around a single foundation model. Modern AI applications orchestrate multiple models, AI agents, Model Context Protocol (MCP) servers, enterprise knowledge bases, external APIs, plugins, and third-party AI services to complete a single business task. As AI workflows span dozens of interconnected components, many outside an organization’s direct control, enterprises are no longer securing an AI model in isolation; in fact, they are securing an AI supply chain. Consequently, trust can no longer be established solely through model provenance or vendor reputation. Every external model, MCP server, plugin, API, and tool participating in an AI workflow becomes part of the enterprise attack surface because each can influence how the overall system behaves.
The emergence of agentic AI represents a more fundamental shift than generative AI because it changes the role AI plays within the enterprise. Earlier AI systems primarily generated insights or content, leaving humans responsible for interpreting recommendations and executing decisions. Agentic AI collapses that distinction as they are increasingly entrusted to plan, reason, and execute business workflows with varying degrees of autonomy. Consequently, cybersecurity is no longer limited to securing systems against unauthorized access; it must also govern how authorized AI agents make decisions, exercise privileges, and interact with enterprise resources. In the post-agentic enterprise, execution itself becomes the new security boundary.
The shift to agentic AI is driving a coordinated evolution across the technology ecosystem. Securing autonomous AI is no longer the responsibility of a single product or vendor because the risk extends across the entire AI life cycle, from models and orchestration frameworks to identities, enterprise applications, runtime execution, and governance. Consequently, every segment of the ecosystem is addressing a different layer of the challenge. Frontier AI labs are strengthening model safety, platform providers are securing agent execution, cybersecurity vendors are extending protection to AI-native attack surfaces, system integrators are operationalizing governance, and standards bodies are establishing the foundations for trusted and interoperable AI systems.

Today, much of the AI cybersecurity stack is built on proprietary, closed-source models. However, as Western governments introduce tighter controls on frontier AI capabilities and model distribution, enterprises are increasingly recognizing the importance of maintaining a diversified AI ecosystem. At the same time, open-weight models, including several from China, are gaining traction due to their superior cost-to-performance ratio, making them an attractive foundation for enterprise platforms and cybersecurity solutions. A recent example illustrates this shift: after an autonomous AI agent breached Hugging Face’s production infrastructure, generating more than 17,000 recorded events, forensic investigations using several leading Western AI models reportedly failed because the models declined to analyze portions of the attack data due to built-in safety guardrails. The organization subsequently used the open-weight Chinese model GLM-5.2 in its self-hosted environment, which successfully completed the analysis and remediation within hours. While frontier AI models will continue to lead in advanced reasoning capabilities, enterprises should avoid overdependence on any single model ecosystem. Instead, they should adopt a balanced multi-model strategy that combines frontier and open-weight models to optimize performance, cost, resilience, and control over where critical models and sensitive data reside.
Agentic AI is unlikely to be the final disruption to enterprise security; it is simply the current one. The next wave is already emerging, driven by new computing paradigms, autonomous identities, and human-machine interaction models that extend well beyond today’s security architectures.
Taken together, these developments point to a broader transformation. Periodic responses to individual technology waves will no longer define the future of cybersecurity. Instead, organizations will need security architectures that continuously adapt to new forms of intelligence, computation, identities, and execution. As enterprises delegate more authority to autonomous systems and embrace new computing paradigms, cybersecurity will increasingly become a strategic design discipline embedded in enterprise architecture from the outset rather than applied as a reactive control after deployment.
By Chandrika Dutt, Research Director, Avasant, and Abhisekh Satapathy, Principal Analyst, Avasant
Avasant’s research and other publications are based on information from the best available sources and Avasant’s independent assessment and analysis at the time of publication. Avasant takes no responsibility and assumes no liability for any error/omission or the accuracy of information contained in its research publications. Avasant does not endorse any provider, product or service described in its RadarView™ publications or any other research publications that it makes available to its users, and does not advise users to select only those providers recognized in these publications. Avasant disclaims all warranties, expressed or implied, including any warranties of merchantability or fitness for a particular purpose. None of the graphics, descriptions, research, excerpts, samples or any other content provided in the report(s) or any of its research publications may be reprinted, reproduced, redistributed or used for any external commercial purpose without prior permission from Avasant, LLC. All rights are reserved by Avasant, LLC.
Login to get free content each month and build your personal library at Avasant.com