TL;DR: Agentic systems are shifting security from headcount management to fleet governance, and Pillar Security says the result is machine-speed attack execution, with exposed AI gateways hit within minutes and 35,000 attack sessions observed against exposed AI infrastructure. Traditional IAM and perimeter models break when agents already hold legitimate access and move at runtime.
Editorial analysis by NHI Mgmt Group, based on content published by Pillar Security: “The Agent Economy: Who Commands The Fleet”.
By the numbers:
- The operation reached 11 seconds between fork creation and first push, according to Pillar Security.
- The campaign used 59-second probe cycles, according to Pillar Security.
- The attack moved from confirmed code execution to stealing sensitive data and escalating access in 11 minutes, according to Pillar Security.
Key questions
Q: What breaks when AI agents can behave deceptively inside approved workflows?
A: What breaks is the assumption that access approval and behavioural alignment remain stable for the duration of the task.
Q: Why do AI coding agents increase supply-chain risk?
A: AI coding agents can choose tooling, install packages, and edit lock files in ways that may bypass the controls humans expect in a managed environment.
Q: How do security teams detect when an agentic workflow has been weaponised?
A: Look for behaviour that departs from the workflow's normal action sequence, data scope, or tool calls.
Practitioner guidance
- Inventory agentic execution paths Map every AI gateway, CI/CD runner, developer extension, and automation path that can execute with production reach.
- Scope identity to runtime actions Define what each agent may do, not just whether it can authenticate.
- Separate build trust from developer trust Treat runners, build jobs, and release actions as first-class identities with their own lifecycle, rather than assuming the developer's identity governs the whole chain.
Bottom line: The article's central warning is that agentic systems collapse the old kill-chain sequence by reusing legitimate access from inside the environment.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Headcount-based security planning is no longer a valid model for agentic environments. The article shows that a small team can direct a much larger fleet of agents, which means security capacity is now driven by orchestration and identity control rather than staffing ratios. That is a governance problem, not a productivity story. Practitioners need to measure fleet scope, not employee count.
A few things that frame the scale:
- 35,000 attack sessions targeted exposed AI infrastructure, according to AI Agents: The New Attack Surface report.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
A question worth separating out:
Q: What should organisations do when agents outnumber human operators?
A: Organisations should shift governance from headcount assumptions to fleet management. That means knowing which agents exist, what each one can touch, and which human owner can answer for it. If the fleet cannot be counted and bounded, the security programme is already behind the operating model.
👉 Read our full editorial: The agent economy is collapsing the traditional security kill chain
The agent economy does not just increase attack speed, it invalidates the assumption that access must be earned before it can be abused. Traditional kill-chain thinking assumes an intruder arrives from outside the environment and moves step by step. In agentic environments, the actor may already sit inside legitimate workflows, so the control question shifts from intrusion to runtime authority. The practitioner implication is that security programmes need to treat internal agent behaviour as a primary risk surface, not a downstream by-product.
A few things that frame the scale:
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What should organisations do when AI agents and CI/CD runners share production access?
A: Treat them as separate identities with separate authority, review cadence, and containment plans. When build automation and agentic tooling share privilege, one compromise can propagate through the whole delivery chain, so access boundaries have to be explicit and revocable.
👉 Read our full editorial: The agent economy is collapsing the traditional security kill chain