AI agents: how CISOs should prepare for their deployment

AI agents: how CISOs should prepare for their deployment


To prepare for the arrival of AI agents in organizations, CISOs must modify their information systems security policy and liaise with chief data officers.

CISOs had to learn how to monitor ChatGPT. Now here comes the AI ​​agents. Unlike generative AI which simply creates content on demand, agentic AI is able to execute commands autonomously by interacting with other tools. “Even if an AI agent is not malicious in itself, it has exorbitant privileges and its use can be misused maliciously by an attacker who interacts with it, or by becoming uncontrollable. This is why I suggest that cybersecurity directors consider any AI agent as a potential cyber threat,” states bluntly Raphaël Marichezchief security officer France and Southern Europe at Palo Alto Networks.

Problem: it happens that these AI agents are developed in an anarchic manner in organizations, by well-intentioned employees who do not take into account their security flaws. Because hell is paved with good intentions, and the CISO must therefore regulate their use now, without even waiting for their deployment, advises Odile Duthilformer CISO, cybersecurity director of the Caisse des Dépôts group and president of the French Information Security Club (Clusif). This requires a clear framework and a strengthening of its collaboration with the IT department.

Write a PSSI dedicated to AI agents

“The first thing I did, and that a CISO must do, is to put in place a framework before deploying AI agents. Because if there is no framework, employees will practice shadow AI and launch AI agents from everywhere. Open Claw and Hermes agents can be installed in the snap of a finger! And we give them easy access to emails, the browser, and what not,” warns Nicolas Prud’hommeCTO and CISO of Ekino, a digital transformation consulting company. For him, this framework must be established in an information system security policy (PSSI) specially dedicated to AI agents. “We must be clear about the rules of the game from the start and that they serve the business. Because when an employee develops an agent in his corner, he is in fact expressing a business need which is not covered. The CISO must therefore respond to his need but with the tools and rules consistent with the company’s PSSI,” adds Odile Duthil.

This PSSI includes in particular “the use cases of authorized AI agents, the data to which they may or may not have access, a classification of this data by sensitivity, the level of autonomy of these agents, the use cases requiring human supervision, the rules on their transparency, the authorized models, a method of risk analysis of agents with a classification according to their criticality to know how they must be tested, at what frequency, etc., affirms Nicolas Prud’homme. For example, such an agent will be said to be at risk level 2, and it will therefore be necessary to test it before putting it into production. Another will be level 3, the tests will therefore be more thorough.

The IT charter must also be modified to include rules for the use of these agents enforceable against employees. “For example, it must specify the models that employees can use. In the charter, most of the CISOs that I know very strongly limit the number of models that can be used,” specifies Odile Duthil. This includes certain rules of the PSSI, such as authorized use cases, and must be communicated to all employees as soon as it is revised to be enforceable against them. “These rules make it possible to integrate employees’ ideas into processes that make them operational, efficient and of high quality.”

Towards a new collaboration with the chief data officer

“For us, the first expressed need for an AI agent came from the sales team. The CIO then turned to me to ask me how we were going to do it. We then very quickly worked together to meet this need in accordance with our policy,” recalls Bruno CheryCISO of Nomios, a cybersecurity company. AI agents present such risks that their deployment “even further strengthens collaboration”, specifies Odile Duthil. “We start working with the IT department as soon as an AI agent project is formulated to ensure that it complies with the PSSI that we have defined.” “As the need for AI agents arose, we strengthened our policy jointly, the CIO and myself, with rules on the creation of agents, models, projects, ways of testing them, access rules, etc.,” explains Bruno Chéry.

“AI has also brought CISOs closer to chief data officers (CDO), which is completely new,” observes Odile Duthil. The CDO is responsible for driving the strategy, governance and valorization of data within an organization. It therefore occupies a central place in the deployment of AI agents, because their effectiveness is only as good as the quality, security and governance of the data to which they have access. This is why the CISO must strengthen its collaboration with it in order to anticipate the needs of the business lines: “Here is what is happening now: the business lines will see the DSI and the CISO with a prototype of an AI agent. They express their needs, ask the DSI to provide them with it and industrialize it in the company’s information system. And this is where the CDO comes in. The CISO must in fact work with him to find out what data can be used for this or that AI agent project, knowing if the data is of quality, mapping the data, knowing if they can be handled without risk, if they are sensitive or not, etc.” So even if they can sow chaos, AI agents have one merit: they bring RSSI and CDO closer together.

Leave a Reply

Your email address will not be published. Required fields are marked *