What happens when AI starts fighting cyber threats on its own? Here's how agentic security works
Artificial intelligence is evolving from assisting cybersecurity to taking on more responsibilities autonomously and efficiently. This shift, termed agentic security, enables AI to identify and investigate threats without waiting for human input. ...
But giving AI more freedom inside a security environment also creates a difficult question: how much autonomy is safe? Cybersecurity companies are increasingly trying to answer that by putting policies, permissions, approvals and audit trails around AI agents. Infopercept's recently introduced Regiment AI is one example of this approach.
From AI copilot to AI agent
A conventional AI security tool may tell an analyst that a server appears vulnerable or that an unusual login needs investigation. An agentic system can potentially go further. It can gather information from different security tools, connect an alert with an asset or identity, investigate related activity, assess the potential attack path and prepare the next action. The system can then operate within rules defined by the organisation.
This is what makes agentic security different from simply adding a chatbot to a security platform. Jaydeep Ruparelia, founder and CEO of Infopercept, describes the broader shift as a move from software that provides a service to software that can perform a service. “Cybersecurity is moving from SaaS, Software as a Service, to SAS: Service as Software,” Ruparelia said.
According to him, the idea is to bring AI agents and human security specialists into the same operating model, allowing tasks such as penetration testing, investigation, compliance evidence collection and remediation prioritisation to happen faster.
How does agentic security actually work?
The simplest way to understand it is to think of a security operation as a chain of decisions. First, something needs to be discovered. Then it has to be investigated. The organisation needs to establish whether the finding is genuine and understand its impact. Finally, someone has to decide what action should be taken.
“An agentic security architecture can divide these jobs between specialised agents. One agent might look for vulnerabilities. Another could investigate suspicious behaviour. A third could connect a finding with compliance requirements. A remediation agent could then help determine what needs to be fixed first. The agents do not necessarily operate with unrestricted access. Their actions can be limited by policies, permissions and approval requirements. That control layer is crucial,” Jaydeep Ruparelia said.
Why human control still matters
The phrase “AI fighting cyber threats on its own” can sound more dramatic than what organisations are actually willing to deploy. In a corporate environment, an AI system making an incorrect decision can cause serious problems. Blocking a legitimate user, shutting down a critical server or changing a security rule without proper approval could disrupt business operations.
That is why controlled autonomy is becoming an important part of the agentic security discussion. Regiment AI, according to Infopercept, is built around policies, permissions, approval mechanisms and auditability. This means an organisation can determine what an AI agent is allowed to do and where a human decision is required.
Ruparelia said the objective is not simply to add another AI assistant to a security team's toolkit. “The goal is to move beyond AI as a copilot and make it part of the security operating architecture, while keeping policies and accountability at the core,” he said. In other words, the AI can be given responsibility for carrying out defined tasks, but the organisation retains control over the boundaries.
AI agents can connect the dots faster
One of the biggest potential advantages of agentic security is speed. Modern enterprises generate enormous amounts of security data. Logs, endpoint alerts, identity events, vulnerability reports, threat intelligence feeds and compliance records can all sit in different systems. A security analyst may need to move between several tools before understanding what a single alert actually means. An agentic architecture can potentially bring these pieces together.
Infopercept founder says Regiment AI is designed to connect with existing security technologies, including SIEM, EDR, SOAR, IAM, CMDB, threat intelligence and ticketing systems. That means the organisation does not necessarily have to replace its existing security infrastructure to introduce AI agents. Instead, the agents can work across the existing environment and use information from those systems to make their decisions more relevant.
What happens when an attack is detected?
Consider a simplified example. A security system detects suspicious activity involving an employee account. Instead of simply sending an alert to an analyst, an agent could first gather information about the account, examine recent activity and check whether the identity has interacted with unusual devices or systems.
It could then look for related indicators elsewhere in the organisation. If the investigation points to a genuine threat, another agent could assess the affected assets and possible attack paths. A remediation workflow could then prioritise the response. Some actions may be automated. Others could require approval. The important point is that the AI is not just answering a question. It is moving through a sequence of connected security tasks.
Does this mean cybersecurity jobs will disappear?
Not necessarily. The more immediate change is likely to be in the nature of security work. Analysts spend considerable time on repetitive activities such as sorting alerts, gathering information, preparing reports and collecting evidence. AI agents could take over parts of these workflows, allowing human specialists to concentrate on complex investigations, risk decisions and incidents where judgement is critical.
There is also a new responsibility: managing the AI itself. Security teams will need to define what agents can access, what actions they can take, when approval is mandatory and how their decisions are reviewed. That could make AI governance a core part of cybersecurity operations.
The bigger shift in cybersecurity
Agentic security is ultimately about changing how security systems operate. Traditional tools often wait for a person to interpret an alert and decide what comes next. Agentic systems aim to connect multiple steps into a continuous workflow. That does not mean handing complete control to machines.
The more practical model is controlled autonomy, where AI can operate at machine speed while organisations retain policies, permissions and accountability. The technology is still evolving, and the risks are significant. But as cyberattacks become faster and security environments become more complicated, organisations are likely to look beyond AI that merely tells analysts what happened.
The Economic Times News App for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.