UK organisations ill-equipped to contain rogue AI agents

Many UK organisations (63%) are not well prepared to contain and recover from rogue actions by AI applications, research from Cohesity has found.  The danger comes from organisations not being able to control what they can’t see. Over half of UK businesses (55%) do not have a centralised inventory or clear view of their AI agents, copilots and workflows.

As AI agents move from experimentation into mission-critical operations, this visibility gap is putting British businesses at serious risk.   This risk is compounded by the fact that cyber recovery plans are out of sync with modern day business operations and today’s cyber threat landscape.

Amongst UK organisations that have experienced a material cyberattack in the past 12 months, over half (58%) found gaps in how their recovery plans accounted for AI systems and applications, AI workflows or machine learning models. The vast majority, 96%, say their cyber response and recovery plans must change to be effective against attacks accelerated and automated by frontier AI.

And nine in ten organisations (91%) who experienced a material cyberattack* in the past 12 months admitted that while plans may work on paper, in practice improvisation is often required. AI-driven threats are behaving in increasingly non-lateral ways, at machine speed, but many organisations’ cyber resiliency plans still assume systems and threat actors execute attacks using repeatable patterns.

AI agents are set to compound another problem: supply chain complexity. Seven in ten (71%) of UK organisations that had experienced a material cyberattack in the last year said recovery expanded far beyond their initial assessment. Meanwhile, almost a quarter (22%) said unverified third parties and systems significantly delayed a return to business as usual.

As AI agents draw on data, applications and services across an expanding web of systems, these dependencies will become harder to map and manage.

A single compromised supplier could result in long-term operational disruption. Olivier Savornin, Group VP & GM European Markets, commented: “Our research indicates that UK organisations have poor visibility of the AI agents across their systems and are under-prepared to recover when these systems take unintended actions.

“Unless organisations have an inventory of all the agents in their system and the data they interact with, they cannot identify – let alone remediate – when a software component is breached. Visibility is essential if AI agents are to deliver value in the enterprise, without compromising on security.

“Organisations need to move beyond thinking about AI as just another software tool, and ensure deployments remain observable, auditable and governable throughout their lifecycle.

“This requires extending cyber resilience across the infrastructure that builds and runs AI systems, so data accessed by agents can be restored to a verified baseline when disruptions do occur.”

Previous articleOvercrowding to fire safety: Karnataka HC issues safety guidelines for Bengaluru PGs
Next articleMangaluru prison jammers to be fine-tuned without affecting security