The images in this article were generated with artificial intelligence. How we publish
In the conferences and panels of the sector you hear a word over and over again: "agenic." But behind the media bulb there is a practical distinction that matters: it is not just about accelerating repetitive tasks, but about changing the nature of control. While classical automation moves faster roles, agentic agents act autonomously in real-time conditions, understand the operating context and execute complex analysis and action sequences. This combination makes risk and compliance management (GRC) a dynamic system rather than a static file that is consulted every quarter.
For those who come from the offensive - red team and purple team - this change is doubly worrying and revealing. The attackers already exploit elastic environments, fluid identities and ephemeral infrastructures; the difference is that these same capabilities can now be incorporated into the control apparatus. If the environment is continuous, the defenses and the tests must be continuous, not fragmented in old temporary windows. This reality requires rethinking processes, tools and responsibilities.

What does an agent bring that does not make a traditional RPA? Three things: autonomy (acts before triggers rather than waiting for a schedule), context (operates on the real state, not on a photo of months ago) and multi-step orchestration (analyzes, decides and acts in chain). From a practical point of view, this means that you can detect a drift in an MFA policy, document it with timestamped evidence and launch mediation tasks without immediate human intervention, yet maintaining human control over closing decisions.
That last nuance is critical: We're not talking about delegating human judgment to a black box.. Models can help with reasoning, summaries and orchestration, but rules, thresholds and acceptance decisions must continue to come from people. To support this confidence, it is essential to design an exhaustive traceability: trigger record, read data, evaluated rules, decision taken and attached evidence, all with time seal and signature of origin.
Tracability is not just transparency: it is reversibility and audibility. An agent who leaves a full log allows you to rebuild why a finding was generated, correct the instruction when there are false positives and present the chain of evidence to an auditor without relying on an opaque explanation. That's why the execution records are more important than the internal architecture of the model itself for compliance and forensic purposes.
In the field of operational safety, two rules of scope should apply: to grant the staff member the principle of minimum privilege(read-only access to evaluated systems and limited permission to write only on approved GRC objects) and maintain a human gating for critical actions (e.g. close risks or mark controls as effective). Detecting drift and opening an incidence can be automated; updating risk states or exceptions must go through human review.
The real risks are not just false positive: they are poorly configured agents, models manipulated by adverse inputs, and inappropriate delegation of decisions. This is why any deployment should include adversary testing (the team network on the agent), validation of input data, and connector expiry policies. Also, maintaining determinative controls for critical parts of the flow reduces the failure surface derived from the non-determination of the model.
From a practical perspective, the recommended adoption path is to start with high-burden and under-trial tasks: evidence gaps detection, report findings extraction, inventory reconciliation. Prove in cases like this allows to validate the execution pattern, evaluate the false positive rate and build confidence in the logs before entrusting high impact controls. This incremental approach increases the tolerance of error and facilitates rapid iterations.

In parallel to technical adoption, there is a policy and framework dimension that should be integrated. Document how agents meet risk management and audit requirements, and map these processes against standards such as ISO / IEC 27001 ( ISO 27001) or the NIST IA risk management framework ( NIST TO RMF) helps to structure controls, responsibilities and audit tests. It is also useful to understand the attacking and tactical landscape that could be used by agents, for example by consulting repositories such as MITRE ATT & CK ( MITRE ATT & CK).
For GRC and security teams, the list of specific actions to be prioritized includes defining auditable baselines, implementing performance log with signature and retention, limiting connector privileges, establishing confidence thresholds and human climbing routes, and subjecting agents to adversary testing. In addition, measuring operational indicators - time to detection, rate of false positives, average resolution time and percentage of reverse actions - will make it possible to demonstrate value and adjust governance.
The final balance is clear: agents can turn compliance into a real-time capacity but only if accompanied by conservative design, robust traceability and human control over critical decisions. Start with the boring and repetitive, test the hypothesis, collect evidence and then raise the bet. That's the safest way that technology really reduces risk and not just redistributes work.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...