09/01/2026
The security industry has one habit it can't shake. AI agents are about to test it a fourth time.
Every layer of enterprise security has followed the same arc. Network security began in software and eventually needed hardware-enforced segmentation. Endpoint security began in software and eventually needed TPMs and secure boot. Cloud followed the same path.
AI agents are at the start of that pattern now. They arrived as chatbots and have become, in effect, employees with database access, API keys and system privileges, acting without a human reviewing each step, at machine speed, across every system they touch. The first critical MCP vulnerability (CVE-2025-49596, CVSS 9.4) appeared within eight months of the protocol's release.
The industry's answer so far has been guardrails, permissions and monitoring. All of it necessary. All of it operating inside the same software trust boundary a compromised agent is already standing in.
In TechRadar Pro, our CEO Camellia Chan, sets out what three decades of security history suggest comes next, and why the industry shouldn't wait for a major compromise to learn the lesson a fourth time.
Read the full piece: https://www.techradar.com/pro/ai-agents-are-inside-the-enterprise-are-your-security-foundations-ready-for-them