AI Strategy #12. AI Security in the Agentic Era: From Prompt Injection to Identity and Tool Abuse
Agentic AI changes the security problem because a model is no longer limited to producing text. An enterprise agent can retrieve private data, maintain memory, choose tools, call APIs, communicate with other agents and alter the state of business systems. A successful prompt injection against a chatbot may produce a bad answer. The same injection against an agent with access to email, source code, ERP or customer data can become an authorization, data-loss or transaction-integrity incident. The important security boundary therefore moves beyond the model. Agentic AI security is not primarily about stopping the model from receiving a malicious instruction. It is about ensuring that an untrusted instruction cannot acquire trusted identity, privileged data or dangerous execution authority. This is why conventional cybersecurity remains essential but no longer sufficient by itself. Identity, least privilege, network segmentation, software supply-chain controls and incident respo...