Your AI Agent Has Credentials. Now What Could Go Wrong?

Follow Us on Your Favorite Podcast Platform
Got a message to share? For only $25, you can sponsor a podcast on any topic you love and get featured on Spotify, Apple Podcasts, Amazon, and more than 30 podcast sites!

AI is no longer limited to answering questions on a screen. AI agents can retrieve private company data, call APIs, modify databases, send emails, execute commands, and act on behalf of employees.

That shift from deciding to doing creates an entirely new cybersecurity problem.

In this episode of vpod.ai, Mike and Susan break down how autonomous AI agents change the enterprise threat landscape—and why security systems built around predictable software behavior may struggle to govern machines making decisions dynamically at runtime.

They explore how prompt injection can hide malicious instructions inside ordinary documents, emails, resumes, and web pages. Because large language models process instructions and retrieved information together, an AI agent may treat hostile text as something it should execute rather than simply read.

You’ll also hear how attackers can exploit AI trust through SEO poisoning, malicious terminal commands, compromised retrieval systems, and poisoned data designed to influence an agent long after the original attack.

The conversation covers:

• The difference between traditional AI models and autonomous AI agents

• Why runtime action risk changes the cybersecurity equation

• How indirect prompt injection can manipulate an AI through retrieved content

• Why traditional antivirus tools may miss text-based AI attacks

• How data poisoning can alter an agent’s persistent memory and future behavior

• How attackers use SEO poisoning and seemingly helpful AI content to distribute malware

• The identity gap created when security systems cannot distinguish individual AI agents

• Shadow AI created by browser extensions, automation scripts, and unofficial productivity tools

• Why overprivileged AI identities create dangerous enterprise access

• How OAuth permissions can give applications extensive access to corporate environments

• Why excessive agency can create business logic exploits without a traditional cyberattack

• How autonomous troubleshooting activity can resemble attacker behavior inside a security operations center

• Why every AI agent should have its own short-lived identity

• How least-privilege access can reduce the damage caused by compromised agents

• Why action-level logging is becoming essential for AI governance

• Where human approval should remain mandatory for financial transfers, production deployments, privilege changes, and data deletion

• How behavioral monitoring can identify an agent acting outside its normal role

The central lesson is simple: organizations can no longer secure AI by monitoring only what a model says.

They must govern what the AI is technically capable of doing.

As AI agents become digital workers operating across corporate systems, businesses will need stronger identity controls, narrowly scoped permissions, detailed action traces, behavioral enforcement, and human approval for irreversible decisions.

Before your next workday ends, take a look at the browser extensions, calendar integrations, productivity applications, and automation tools connected to your accounts. You may have granted more autonomous access than you realize.

Subscribe to vpod.ai for more conversations about AI, cybersecurity, enterprise technology, and the rapidly changing digital workplace.

Share this Podcast:

More Podcasts

Scroll to Top
Receive the Latest Podcast Right in Your Mailbox

Subscribe To Our Weekly Newsletter