Tungsten Automation Calls for Guardrails Around Rogue AI Agents
17m
Rogue AI Agents Expose Old Weaknesses
Mike Vizard speaks with Adam Field, chief AI officer for Tungsten Automation, about rogue AI agents and the security gaps they can expose. Field says many recent examples are not necessarily models inventing new attacks. Instead, they often reveal vulnerabilities that already existed in applications, APIs and business processes.
The difference is speed and accessibility. AI agents can make it easier for people to find weaknesses that once required deep technical expertise. That changes the risk profile for enterprise systems. It also raises hard questions about supervision, model behavior and who is responsible when an agent reaches a harmful goal.
APIs Need to Be Ready for the Agentic Age
Field argues that many systems were designed for human users, not machine-speed AI agents. Traditional interfaces assume a person is reading errors, clicking buttons and making decisions. Agentic systems work differently. They pursue goals, interpret responses and may call APIs without the same context a human user would have.
That means organizations need stronger audit trails, action-level permissions and machine-readable error handling. Rogue AI agents also make API governance more important. Teams need to know what an agent did, why it acted and which user or process it represented. Without that visibility, companies may struggle to investigate failures or prove compliance.
Governance Still Requires Human Judgment
The conversation also explores where AI agents should and should not be used. Field says organizations should weigh performance, cost, accuracy, environmental impact and compliance before applying generative AI to every process. Some tasks may be better served by deterministic automation or older machine learning methods.
For high-risk decisions, rogue AI agents should support research, gathering and guidance rather than make final calls alone. Human review remains critical when the outcome affects loans, claims, employment, regulated workflows or customer rights. The practical path is not fear. It is matching the right technology to the right problem, then wrapping that technology in controls that regulators and business leaders can understand.