When AI Agents Get a Seat at the Table, Who’s Watching Them?

Enterprises are deploying AI faster than their security teams can keep pace, and the gap is no longer theoretical. As AI agents now access data, call APIs, and trigger workflows across multiple cloud environments in real time, they are fundamentally different from the applications traditional security models were built to protect. The numbers tell their own story: while most leaders believe their AI implementation is best-in-class, only a fraction say it is actually ready to manage future risks.

In this conversation with CISO Forum, Harish Soni, Resiliency and Security Practice Leader, Kyndryl India, unpacks why perimeter-based security collapses once AI enters mission-critical operations, what a resilience-first strategy means for the metrics boards should track, and where organisations most often get Zero Trust wrong when applying it to AI workloads. He also lays out what “AI-ready cybersecurity” will demand three years from now — and why faster recovery, not just prevention, may be the smartest bet enterprises can make today.

Harish Soni
Resiliency and Security Practice Leader
Kyndryl India

CISO Forum: Enterprises are racing to deploy AI, often faster than their security teams can adapt. In your experience, what’s the biggest blind spot organisations have when they treat AI workloads like just another application to secure?

Harish Soni: The biggest blind spot is treating AI workloads like traditional enterprise applications. AI systems are dynamic and increasingly autonomous. A single AI agent can access data, call APIs and trigger workflows across multiple cloud environments in real time. That makes AI fundamentally different from conventional applications and much harder to secure using traditional approaches.

This is reflected in Kyndryl’s Readiness Report. While 86% of leaders believe their AI implementation is best-in-class, only 29% say their AI is ready to manage future risks.

Securing AI requires a unified view across infrastructure, applications, data and security because AI workloads operate across all these layers at once. It also needs to be handled within a framework model, since most enterprises follow security solutions such as Governance, Zero Trust, Secure IT and Cyber Resilience. Kyndryl’s Cyber Défense Operations Centre brings together network and security telemetry into a single operational view, helping organisations manage AI risks more effectively with its AI-powered, integrated services.

CISO Forum: Most CISOs would say they’ve locked down their apps and endpoints. Why do infrastructure, data pipelines, and the AI models themselves remain comparatively exposed — and what does an attack on that layer actually look like?

Harish Soni: Infrastructure, data pipelines and AI models remain exposed because they have become part of the attack surface, but many organisations still rely on security controls designed for traditional applications. AI introduces new risks such as data poisoning, adversarial attacks and model theft, which conventional security measures are not designed to detect or prevent. Kyndryl’s approach is to have continuous Attack Surface Management monitoring for continuous identification, assessment, and reduction of potential entry points across networks, applications, cloud environments, endpoints, and human factors, and increasingly that surface has to include the data and model layers feeding AI systems. A Zero Trust framework matters here because it treats every access request as unverified, rather than assuming a request originating inside the data pipeline is inherently safe.

In practice, an attack on this layer rarely looks like a dramatic breach. It looks like a slow, unauthorised drift: a compromised credential alters a pipeline configuration, an untrusted data source gets introduced, the model is retrained or subtly poisoned so its output shifts, and downstream applications keep treating that output as trustworthy because nothing ever looked abnormal.

CISO Forum: “Perimeter-based security” has been the default mental model for decades. What specifically breaks down when AI enters mission-critical operations, and what should replace it?

Harish Soni: Perimeter-based security assumed a defensible edge, a network boundary you could wrap in firewalls and trust everything inside. It was built for predictable, rule-based systems, defined perimeters, known inputs, identifiable code vulnerabilities. Three things break that model once AI enters mission-critical operations. First, identity becomes dynamic: it is no longer just people requesting access, but agents that can reason, plan, execute, and adapt in real time on their behalf. Second, workflows become distributed, moving across cloud, APIs, data stores, and applications rather than staying inside one boundary. Third, the system can now take action rather than receive a request, which changes the real question from whether an entity can get into what it is allowed to do once it is in. Zero Trust replaces the perimeter as the primary trust model, treating every access request as unverified and continuously validating every subsequent action. Many of these stall not for lack of technology, but because organisations are trying to build modern security on top of environments never designed for this threat landscape, treating security as bolted on rather than engineered in from the start.

CISO Forum: We talk about a shift from cyber defence to cyber resilience. Practically speaking, how does a resilience-first strategy change the metrics a board or CISO should be watching — recovery time versus prevention rate, for instance?

Harish Soni: A resilience-first approach shifts the focus from preventing every attack to ensuring the business can recover quickly when an incident occurs. No organisation can prevent every cyber threat, so success depends on how effectively it responds and restores critical operations.

Boards and CISOs should focus on metrics such as Mean Time to Recover (MTTR), incident response times, recovery time for critical systems, and the overall business impact of an incident. These metrics provide a much clearer picture of organisational resilience than prevention rates alone. It also means viewing cyber risk as a business risk rather than just a technology risk. Cyber risk quantification helps organisations measure the potential financial impact of cyber threats, enabling boards to make more informed decisions on risk, investments and resilience.

CISO Forum: Data pipelines feeding AI models pose a governance challenge distinct from securing a database. What new categories of risk — around data lineage, model integrity, or poisoning — should enterprises be building controls for today?

Harish Soni: Data pipelines introduce risks that go well beyond securing a database. Organisations need controls in three key areas: data lineage, model integrity, and decision risk. Data lineage is about knowing where the data came from and how it has changed throughout the pipeline. Model integrity focuses on ensuring that data and models have not been tampered with through techniques such as data poisoning or adversarial attacks. Decision risk assessment understands whether compromised data has influenced the model’s outputs or business decisions.

To manage these risks, organisations need strong data governance from the outset. This includes discovering and classifying data, protecting it through encryption and data loss prevention, and continuously validating the data that feeds AI models. Without trusted data, organisations cannot trust the AI’s outputs.

CISO Forum: Kyndryl talks about a unified Cyber Defence Operations Centre bringing network and security teams together. What was broken about the siloed model, and what tangible difference does integration make when an incident actually hits?

Harish Soni: Enterprises face a more complex operating environment, where AI-driven cyber risks, costly downtime, and expectations of continuous service delivery are converging. The traditional siloed model breaks down because network and security teams often look at different signals, use different tools and respond through separate workflows. A network team may see latency, unusual traffic patterns or a routing issue, while the security team may see suspicious authentication, endpoint behaviour or a possible policy violation.

Kyndryl’s unified Cyber Defence Operations Centre addresses this by bringing network and security operations into a single operating model, with shared visibility, unified monitoring and collaborative analysis across the environment. By integrating telemetry, runbooks, dashboards and response workflows, it helps teams move from fragmented alert handling to a common view of what is happening across the network, cloud, endpoint, and identity and application layers. When an incident occurs, the organisation can build one incident narrative instead of multiple teams investigating parallel symptoms. This reduces manual handoffs and alert fatigue, accelerates detection and response, and helps enterprises contain disruption faster while maintaining security, efficiency and uptime.

CISO Forum: Zero Trust has become something of a buzzword. When you’re implementing it for AI-powered environments specifically, what does it look like in practice, and where do organisations most often get the implementation wrong?

Harish Soni: Zero Trust means that every user, device, application and AI workload is continuously verified before it is granted access. In AI environments, this goes beyond securing human logins. It also means validating machine identities, AI agents, APIs and service accounts every time they interact with systems or data. The biggest mistake organisations make is applying Zero Trust only to people and networks, while giving AI agents, service accounts and model endpoints broad, long-standing access. These identities need the same level of continuous verification as human users.

Kyndryl’s Zero Trust Architecture (ZTA) approach is business-led, risk-based, and technology-agnostic, and prioritises protecting the most critical business assets first rather than deploying security controls everywhere. Our approach uses AI-powered monitoring, with agents’ identities governed by strong identity and access management controls, to build a resilient, compliant security ecosystem.

In the agentic AI era, risks are no longer isolated compromises; a single compromise can trigger a chain reaction across interconnected systems. Proper segmentation contains disruption and buys teams time to respond, rather than just keeping threats out. Organisations that stop at network segmentation, without extending continuous validation and segmentation to AI agents, end up with a Zero Trust label but not Zero Trust behaviour.

CISO Forum: For a regulated sector such as BFSI or healthcare, how does AI adoption complicate compliance obligations that were written before generative AI existed, and how are your clients navigating that gap?

Harish Soni: For sectors like BFSI and healthcare, AI introduces new compliance challenges because many existing regulations were written before generative AI became mainstream. Organisations now need to address challenges such as who is accountable for an AI-driven decision, what data the model uses, and how they can demonstrate that the model has not been altered since it was approved. This becomes even more important when organisations use third-party foundation models, as regulators are placing greater accountability on organisations for managing third-party cyber risks.

Kyndryl helps clients move toward autonomous execution with policy-driven governance. This means embedding policy-as-code, human oversight, security guardrails, and continuous auditability into agent workflows, so organisations can confidently automate regulated processes while maintaining compliance, trust, and operational resilience.

CISO Forum: If an enterprise has budget for only one thing this year — better prevention, faster detection, or faster recovery — which would you prioritise, and why?

Harish Soni: If I had to choose one priority, I would choose faster recovery. Prevention will always remain critical, but in a rapidly evolving threat landscape, no organisation can assume it can prevent every incident.

The real measure of cyber resilience is how quickly and confidently an organisation can detect an incident, contain its impact, restore critical operations and learn from it. As AI makes attacks faster and more sophisticated, the ability to make informed decisions under pressure and recover with minimal disruption will become a defining advantage.

CISO Forum: Three years from now, what will “AI-ready cybersecurity” mean that it doesn’t mean today, and which organisations do you think are actually on track to get there?

Harish Soni: Three years from now, “AI-ready cybersecurity” will mean preparing for a threat landscape shaped by deeper AI integration, rather than simply adding AI controls to existing security frameworks. We will see more sophisticated social engineering, automated supply-chain attacks and threats such as data poisoning, alongside a broader attack surface driven by cloud, IoT and geopolitical risks.

Organisations on track will invest today in the fundamentals—secure access, network security, and endpoint protection—while strengthening governance and resilience. They will also bring security, infrastructure and data teams closer together and establish clear accountability for AI systems and machine identities.

There is reason for optimism in India. Accelerated IT modernisation, collaboration across government, industry and academia, and a stronger focus on responsible AI can help organisations build more adaptive cyber defences. Ultimately, AI-ready cybersecurity will be less about a specific technology and more about the ability to anticipate, withstand and recover from disruption through the right combination of technology, people, processes and governance.

Author