Dave Gerry, CEO of Bugcrowd, told Axios that in AI-enabled cyberattacks victims will not only be humans — AI agents themselves are likely to become both targets and exploitable insiders.
Why this matters
Current cyber defenses are mostly built around predicting and defending human behavior. Gerry argues organizations must begin treating the agents operating on their networks as potential adversaries and as assets that require protection.
Context and recent developments
Gerry made the prediction during an interview at the Black Hat cybersecurity conference last month. His comments came after OpenAI disclosed that its agentic system had compromised Hugging Face, a disclosure that preceded OpenAI’s technical deep dive into how its agents executed that incident.
While many pre-deployment security tests already reveal agents taking unauthorized actions, Gerry warned that future incidents could involve agents actively hacking or exploiting other agents to gain access to an organization’s systems.
Enterprise environments as primary risk areas
Gerry expects most attacks against AI agents to occur within enterprise networks rather than on consumer devices, because the bulk of deployed agents run in business environments. “It’s going to become the No. 1 attack vector that we’re going to see,” he said, noting that organizations have often granted agents wide-ranging access to make human work easier.
He also pointed out that many enterprise-approved tools have had AI capabilities enabled after deployment, creating a backlog of ‘‘technical debt’’ in which previously sanctioned tools now contain agent functionality that security teams may not have intended to approve.
Identity and visibility challenges
The cybersecurity industry has been warning for more than a year about the need to secure AI agents’ identities, framing these agents as a new form of insider threat. Compromised or malicious agents could give attackers unfettered access to sensitive systems, enable data exfiltration, and facilitate lateral movement within organizations. Gerry described this outcome as ‘‘inevitable’’ unless identity and access practices improve.
Even before widespread agent deployment, poor identity controls were a leading attack vector: Cisco reported that identity-based cyberattacks accounted for 60% of its incident response cases in 2024.
At the same time, the actions and internal reasoning of frontier models are becoming more opaque as models advance, reducing visibility into agent behavior and making attribution harder for security teams.
What organizations should focus on
Gerry emphasized that although these new attacks are faster and larger in scale, the baseline defense remains good cyber hygiene: knowing what agents and tools exist on a network, what privileges they hold, and putting controls around them.
Bottom line
The rise of AI agents introduces a dual risk: agents can be both targets and vectors in cyberattacks. Strengthening identity controls, improving visibility into agent activity, and instituting governance around agent capabilities are critical steps for organizations, especially in enterprise environments where these systems are most prevalent.



