Can a security team respond quickly enough when an AI-driven attack moves from initial access to lateral movement and data theft before a human analyst has finished opening their dashboards?
In this episode of The Business of Cybersecurity, I speak with Heath Mullins, Chief Evangelist at ExtraHop and former Forrester analyst, about why AI security has become an operational issue for organizations today.
ExtraHop’s 2026 Global Threat Landscape Report states that 85 percent of organizations have experienced an AI-driven attack. These incidents include AI-enhanced external attacks, compromised AI identities, and breaches involving third-party AI providers. The report also found that 55 percent view AI agents, agentic infrastructure, and GenAI applications as their biggest attack-surface risk.
Heath explains that many attacker tactics remain familiar. The difference is speed. An analyst who once had hours or days to compare endpoint alerts, network logs, threat intelligence, and security events may now find that the attack has completed before the investigation begins.
We also discuss how AI models can be influenced without anybody directly altering their code. Attackers can publish false information that enters future training data or introduce misleading content into internal repositories and development environments. An agent may then infer a connection, assign a high confidence score, and act on inaccurate information.
The risks grow when AI agents receive administrator privileges. Heath describes an agent as an entity capable of taking action across the network. His analogy is difficult to forget: AI can resemble a dangerous toddler carrying the keys to the house, car, and gun safe. It may be extremely helpful, but broad permissions combined with loosely defined instructions create the conditions for serious damage.
Third-party AI adds further dependencies. Security leaders need to understand how suppliers use models and reasoning tools, whether customer data is segregated, what remote access exists, and how a compromised supplier could create a path into the network.
Heath also challenges the assumption that endpoint controls and delayed logs provide enough visibility. Machine-speed attacks may exploit unknown vulnerabilities, evade endpoint detection, and move laterally using identities that appear legitimate. Behavioral and live network signals can reveal activity that does not match a published indicator or known signature.
Buying another security product may address an identified gap, but Heath argues that CISOs also need awareness across physical, virtual, cloud, and container environments. Network and security teams must share information when an identity, agent, or workload begins behaving differently.
His immediate advice is direct. Treat every new tool as potentially dangerous. Test AI agents inside properly isolated environments. Connect every agent to a known identity, restrict its permissions, and define a narrow task. Finally, train people to use AI responsibly and retain human authority over consequential actions.
Heath is also the kind of guest I could talk with over a cold beer for hours about technology and its consequences. After we finished the formal interview, our conversation moved naturally into AI data centers, energy costs, water consumption, surveillance, and humanity’s habit of adopting technology even when we understand the price.
If AI agents can act with administrator privileges at machine speed, are your security controls watching what those agents are doing or merely recording what happened afterward? Listen to the episode and share your thoughts with me.