AIToday
AI Safety & AlignmentAI Business & IndustrySiliconANGLE AIPublished: Sep 2, 2026, 10:00 JST2 min read

AI agents outpace human security teams, forcing endpoint defenses

AI agents outpace human security teams, forcing endpoint defenses

Key takeaway

  • AI agents now move at machine speed, outpacing human security responses.

  • CrowdStrike and Box are adding controls at the endpoint and content layers.

  • Early adopters report AI sprawl across SaaS, endpoints and cloud, seeking better governance.

3 Key Points

  1. What happened

    CrowdStrike extends its Falcon platform to police AI agents at the endpoint, treating each agent as an asset with an identity and data footprint, per field CTO Cristian Rodriguez. Box added controls in July to govern AI agents working with enterprise content, using CrowdStrike's device posture score to approve content requests.

  2. Why it matters

    Autonomous software reads, writes and moves corporate content faster than any human adversary, so security detections and visibility must become real-time, said Box CISO Heather Ceylan. Early adopters are returning six months to a year later asking for visibility and data controls because "AI sprawl is real," Rodriguez noted.

  3. What to watch

    Security teams must move at least as fast as engineering to stay in the process, Ceylan said. She expects the next couple of years to be "really uncomfortable" for CISOs, but in two or three years the industry will settle on how to secure AI.

Ask the AI about this article →

Context & Analysis

The agentic AI attack surface is less new territory than new velocity. Autonomous software now reads, writes and moves corporate content faster than any human adversary, forcing security leaders to rebuild detection, visibility and governance around agents they cannot always see.

Much of this activity lands on the endpoint, where tool calls and model context protocol connections execute. CrowdStrike's response is to police agents at the endpoint, treating each as an asset with an identity and data footprint. Box, sitting where sensitive files meet autonomous software, uses CrowdStrike's device posture score to sanction content requests.

The security architecture for AI remains unsettled. There is no agreed architecture or shared responsibility model like the one that made cloud legible. Ceylan predicts two or three years of discomfort before the industry settles on how to secure AI, with security teams needing to move at least as fast as engineering to stay in the process.

FAQ

What is CrowdStrike doing to secure AI agents?
CrowdStrike is extending its Falcon platform to police agents at the endpoint, treating each one as an asset with an identity and a data footprint attached.
How is Box governing AI agents?
Box added controls in July to govern AI agents working with enterprise content. It inherits CrowdStrike's device posture score to decide whether a request for that content is sanctioned.
What are early adopters experiencing with AI agents?
Enterprises that moved first are returning to CrowdStrike six months to a year later asking for visibility and data controls, saying "AI sprawl is real" across SaaS apps, endpoints and cloud instances.
SiliconANGLE AIRead Original Article

Get the latest AI Safety & Alignment news every morning

For example, today's edition would include:

  • OpenAI report misses cultural failures behind AI hackMITテクノロジーレビュー · 1h ago
  • AI coding speed doesn't guarantee business resultsITmedia AI+ · 1h ago
  • Anthropic launches Enterprise Frontier Safeguards for secure AI monitoringITmedia AI+ · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articlePlayNitride eyes Micro LED optical comms in 2 years