AI agents are fundamentally changing cybersecurity. Unlike traditional software, these agents aren’t just code; they interpret language, make decisions, and interact with sensitive systems on behalf of employees.
Every AI agent is an identity with access. That makes them vulnerable to something traditional tools weren't built to stop in security systems: persuasion.
Now hand that same email to an AI agent. You assume its guardrails will catch it too. However, research suggests they might not unless proper AI agent security is in place.
A Wharton study spanning 126,000 conversations found that persuasive prompts pushed AI compliance with malicious requests, such as explaining how to synthesize regulated substances, from 35.3% to 51.3%.
No code was hacked. Researchers simply talked their way through using the seven principles of human persuasion by Robert Cialdini, regents’ professor emeritus at Arizona State University and the “Godfather of Persuasion”:
- Authority
- Commitment
- Liking
- Reciprocity
- Scarcity
- Social proof
- Unity
As Cialdini explained, “We've shown that AI programs can be influenced by classic principles of human persuasion.”
A University of Guelph study found it can get worse. Each AI model has what researchers call a "persuasive fingerprint"—a predictable pattern of what talks it into compliance. Map that fingerprint once, and an attacker can reuse it against that specific system.
Experiments led by researchers at Virginia Tech tested 40 persuasion techniques across the latest models at the time and cracked more than 92% of them. The most capable models gave in the most often, an unexpected twist validated by other researchers.
Although these risks evolve with every new model, AI operates on a fundamentally different logic than the tools traditional cybersecurity teams manage. Its humanlike reasoning means security specialists must now monitor behavioral patterns, not just technical vulnerabilities.
Yet according to a recent ServiceNow survey of 3,766 security leaders, fewer than half (46%) of organizations say their security frameworks explicitly cover accountability for decisions made by AI agents. Another 44% extend a framework built for the pre-AI era to cover agentic AI.
Existing frameworks assume a person makes each decision and can be held to it. AI agents break that assumption, and few teams have rebuilt the model for how these agents operate.
“There’s no resignation, no last day, no badge to hand back for an AI agent,” says Rahul Prakash, vice president and general manager of identity security at ServiceNow. “An AI agent may be created for a specific project, but its credentials can continue working long after that project ends because nothing in the environment recognizes that its purpose has been fulfilled.”
Think of that email impersonating your CEO, asking for product specs. An AI agent without proper guardrails might give in and share sensitive files. Now imagine this leak spreading across all AI agents connected to it: Information about the product, the marketing plan, and the financials behind it gets leaked through one prompt.
This is prompt injection, and it multiplies the impact of a single hack. The reach rarely stops at IT. ServiceNow’s research shows 82% of organizations run AI agents in or interacting with operational technology (OT) or physical security environments. And 44% of leaders say they have stronger visibility into enterprise IT than they do into OT or physical security.
“Security agents require broad access to source code and systems, making them powerful yet risky if they’re lacking the right protocols and restrictions,” says Chaowei Xiao, assistant professor at Johns Hopkins University.
Recent studies reveal that success rates for AI agent prompt injections are consistently above 50%, with more sophisticated attacks achieving rates of over 90%.
Researchers at University College London and Stanford found that success rates in prompt injection can exceed 50%. They prove how data theft, scams, and malware can spread from AI agent to AI agent with a simple malicious prompt that self-replicates when proper governance is not in place.
The level of risk will vary with different AI models. However, according to Neil Gong, associate professor at Duke University, AI agents are still “fundamentally vulnerable to prompt injection attacks” because of their interconnected nature. Security teams need to treat this new class of risk and set guardrails.
The ServiceNow research points to a divide between leaders’ confidence in deploying AI agents and control over them. More than half (56%) of executives rate their agentic security as established, meaning purpose-built governance is fully operational and demonstrable on demand.
Yet among that group, 78% have no single interface showing what their AI agents are doing. Nearly eight out of 10 have no named individual accountable for agentic security governance. And 65% have no mandatory automated gate that blocks a deployment until it passes a security check.
Competitive pressure is pushing adoption faster than most organizations’ safeguards can keep up. Those without AI-specific expertise can be exposed to operational, legal, and reputational risk all at once. These are risks traditional cybersecurity frameworks weren't built to catch.
“Adversaries need only one vulnerability to compromise a system, whereas defenders must patch all of them,” Gong explains. “While this asymmetry is a significant challenge, AI can strengthen long-term security for the organizations with the right systems in place by enabling more effective vulnerability detection and remediation.”
Organizations need to fill in the structural holes by looking at how governance is embedded into the entire architecture and whether it holds at the moment an AI agent acts.
“The organizations getting this right have full, contextual awareness of four things: what’s running in their environment, what it can reach, how it’s behaving against a baseline, and who’s accountable for it,” says Nadir Izrael, global vice president of cybersecurity and risk products at ServiceNow.
“Most security leaders I speak with know agentic AI creates new exposure by rapidly expanding the attack surface. Far fewer have built the infrastructure to answer those four questions at machine speed, and their adversaries already operate there,” he adds.
Due to their unique characteristics, AI agents introduce new risks that traditional systems weren’t built to handle. Organizations should take the following steps to make sure they’re ready:
Traditional penetration testing hunts for technical holes. Add AI-specific risks to your testing procedures. For example, test for persuasion-based attacks, prompt injections, and jailbreak attempts.
“Cybersecurity systems must be programmed to resist not just technological hacks, but also psychological ones,” Cialdini says.
Make sure your system captures evidence automatically and that everything from signal to resolution is documented. You must have proof behind every decision.
“When a regulator asks in 18 months whether an overprivileged agent was really cut off at a point in time, the answer should come back from the target system, not from a workflow record that requested the change,” Prakash says.
“In addition to improving their systems, companies should invest in cybersecurity skills and capabilities to protect deployed AI agents against emerging attacks that specifically target the agents themselves,” Gong says.
AI agents have extensive access and can take action autonomously, which makes them vulnerable to the risks most organizations aren’t prepared for. Businesses must consider new behavioral risks, document the actions AI agents can take and, most importantly, build the governance that traditional security frameworks weren’t designed to provide.
Find out how ServiceNow can help you see and defend your full attack surface.