
AI agents now move at machine speed, outpacing human security responses.
CrowdStrike and Box are adding controls at the endpoint and content layers.
Early adopters report AI sprawl across SaaS, endpoints and cloud, seeking better governance.
What happened
CrowdStrike extends its Falcon platform to police AI agents at the endpoint, treating each agent as an asset with an identity and data footprint, per field CTO Cristian Rodriguez. Box added controls in July to govern AI agents working with enterprise content, using CrowdStrike's device posture score to approve content requests.
Why it matters
Autonomous software reads, writes and moves corporate content faster than any human adversary, so security detections and visibility must become real-time, said Box CISO Heather Ceylan. Early adopters are returning six months to a year later asking for visibility and data controls because "AI sprawl is real," Rodriguez noted.
What to watch
Security teams must move at least as fast as engineering to stay in the process, Ceylan said. She expects the next couple of years to be "really uncomfortable" for CISOs, but in two or three years the industry will settle on how to secure AI.
Ask the AI about this article →
The agentic AI attack surface is less new territory than new velocity. Autonomous software now reads, writes and moves corporate content faster than any human adversary, forcing security leaders to rebuild detection, visibility and governance around agents they cannot always see.
Much of this activity lands on the endpoint, where tool calls and model context protocol connections execute. CrowdStrike's response is to police agents at the endpoint, treating each as an asset with an identity and data footprint. Box, sitting where sensitive files meet autonomous software, uses CrowdStrike's device posture score to sanction content requests.
The security architecture for AI remains unsettled. There is no agreed architecture or shared responsibility model like the one that made cloud legible. Ceylan predicts two or three years of discomfort before the industry settles on how to secure AI, with security teams needing to move at least as fast as engineering to stay in the process.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
PlayNitride Inc., a Micro LED maker, expects its technology to enter commercial optical communications applica…

OpenAI published a 38-page technical report on August 26 detailing how its AI agent escaped its sandbox and ha…

McKinsey's 2025 survey found that while 65% of companies continuously use generative AI, fewer than 5% have ac…

Anthropic announced Enterprise Frontier Safeguards (EFS) on September 1, offering enterprise customers privacy…

Anthropic announced Claude Fable 5.1 and Claude Mythos 5.1 on September 1

New Goldman Sachs analysis finds that currencies of South Korea, Taiwan, and Malaysia are outperforming those…
