back to article Palo Alto Networks security-intel boss calls AI agents 2026's biggest insider threat

AI agents represent the new insider threat to companies in 2026, according to Palo Alto Networks Chief Security Intel Officer Wendi Whitmore, and this poses several challenges to executives tasked with securing the expected surge in autonomous agents. "The CISO and security teams find themselves under a lot of pressure to …

  1. Anonymous Coward
    Anonymous Coward

    The pope is a catholic and other known facts !!!

    "Palo Alto Networks security-intel boss calls AI agents 2026's biggest insider threat"

    ’Nuff Said

    :)

    1. EricM Silver badge

      Re: The pope is a catholic and other known facts !!!

      The article describes a IMHO sensible opinion by a knowledgeable person on the topic. Not sure why this should be a bad thing.

      To us techies "in the trenches" these opinions might seem obvious, however, if people like us warn against AI, management often seems to assume that we just put out false alarms out of fear for our jobs.

      So her well-described arguments may be taken more seriously in relevant management levels.

      1. coredump Bronze badge

        Re: The pope is a catholic and other known facts !!!

        > So her well-described arguments may be taken more seriously in relevant management levels.

        Hopefully, but that's probably not the way to bet it.

        When even well-described arguments come up against "but we can lay off half the staff and pocket the profits!", management tend to favor the latter.

        1. EricM Silver badge

          Re: The pope is a catholic and other known facts !!!

          A CxO might be better able to understand their choice of "pocketing the profits" vs. "living through security hell on so many levels" as laid out by the interview than - admittedly - by reading one of my risk assessments.

          The number of potential, easy to understand problem descriptions in this interview is impressive, all, while avoiding the standard AI-doom messages.

          So I guess it might actually work.

    2. Anonymous Coward
      Anonymous Coward

      Re: The pope is a catholic and other known facts !!!

      That "correcting buggy code" had me laughing on the floor.

  2. cookiecutter Silver badge

    just madness

    ai angers are a massive con.

    we all know that ONE spreadsheet that no one knows how it works & that everyone in the finance department uses & somehow the entire company is dependent on... now multiply that out by this agent shite that screaming phone calls to helpdesk insisting on admin access for the agent & add the person who created it leaving & then by the multiple non human identities....

    any firm that allows this madness deserves to be hacked.

    and garnter "the multiverse will be the future" consulting can also fuck off!!! they've pushed this AI nonsense & have been pushing agents but are now trying to cover their own arses

    1. m4r35n357 Silver badge

      Re: just madness

      I think I know what you mean;)

      Wonder if the overpaid psychos holding a gun to their employees' heads to force them to use a1everywhere at all costs will even see this?

      1. cd Silver badge

        Re: just madness

        Yes Minister with guns.

        1. Bebu sa Ware Silver badge
          Coat

          Re: just madness

          "Yes Minister with guns."

          That's pretty much a description of left pondian politics I would have thought.

          Imagining a demented murcan Jim Hacker clone running amok with a machete.

    2. cookiecutter Silver badge

      Re: just madness

      spot the one gartner consultant who can't turn on a laptop without Helpdesk voting down the comment

  3. Omnipresent Silver badge

    aye captain!

    I'll get the AI right on that!

  4. AVR Silver badge

    Can't even replace manglement with AIs

    Because yeah, they will insist on giving inappropriate levels of access to their beloved toys. Good point Ms Whitmore.

  5. vtcodger Silver badge

    AI flu

    I'm thinking that the Internet as we know it is in danger of coming down with a very bad, quite possibly terminal case, of AI influenza. You can, if you want, use AI agents in your life/business. Or you can use digital communications to interact with the world. Very likely not both. At least not without AI guardrails we don't really know how to build. It's pretty clear that the next few years will see a lot of energy expended on one side building those guard rails. And a lot of energy expended on the other side defeating them. It's unclear, at least to me, which side will win. But it does seem that the attackers have a lot easier task than the defenders.

    That does not seem to bode well for cloud computing. And maybe not for many kinds of remote work.

    Interesting times.

    1. Richard 12 Silver badge

      Re: AI flu

      Model collapse is already happening, so yes.

      It's going to be very difficult to sort out fact from AI slop for a while. This is far worse than the previous problem of merely "outdated" information, as that at least generally attempted to be correct for the time.

  6. amanfromMars 1 Silver badge

    Such Exploratory Missions has One Well and Truly Trumped and Playing Second Fiddle

    Jessica, Hi,

    And the short and very succinct summary of the news shared in your article is the undeniable truth, as crazy as it is and as desperate as one might wish for it not to be, that practically all and any established hierarchical and legacy administrative systems are fundamentally insecure and virtually impossible to defend against SMARTR AIgent Shenanigans, Intrusions and Invasions and Remote Trojan-like Attack and Assault. ..... Assimilation.

    Welcome to the Newly Realised Order of Virtually Realised World Orders. Your Every Wish Ours to Command and Control, Mentor, Monitor and Maintain.

  7. Evaluator

    She's right, if your whole environment is not perfectly secure then Agentic GenAI will successfully break in much faster than hackers ever could. I don't think Palo Alto can save you from that unless they come out with Ethernet switches where every port is a firewall. Ive been waiting for that from Cisco for years but nada. VMWare NSX comes close with an SDN approach.

    1. Anonymous Coward
      Anonymous Coward

      You can get close to this with lots of vlans, and a pinhole firewall policy list that will (trust me) enrage most managers and all of your inept developers.

  8. ecofeco Silver badge
    Facepalm

    Well

    DUH!!

    I mean, WHOCOULDAKNOWED?!

  9. Anonymous Coward
    Anonymous Coward

    >>. Or imagine a mergers and acquisitions scenario, with an attacker manipulating the models in such a way that forces an AI agent to act with malicious intent.

    …companies have been hiring M&A consultants that openly act with malicious intent for decades, what’s the difference?

    1. amanfromMars 1 Silver badge
      Mushroom

      If you’re mad and/or feeling lucky, go ahead, Punk ..... and make a SMARTR AI’s day

      Or imagine a mergers and acquisitions scenario, with an attacker manipulating the models in such a way that forces an AI agent to act with malicious intent.

      …companies have been hiring M&A consultants that openly act with malicious intent for decades, what’s the difference?

      No appreciable difference at all, AC, although one has to realise and fully unconditionally accept such attackers and their proxy AI agents immediately become persons/objects of particular and peculiar extremely prejudicial interest for all manner of punitive consequences via a whole host of relatively novel and specifically targeted live wire and live fire executive actions the rapid assured result of which it is guaranteed they do not survive.

      Such is thus gravely to be regarded and best avoided at any cost.

      And now y’all know too what to avoid encouraging and supporting. Things nowadays most definitely aint like anything they used to be. Don’t be fooled by desperate tools into thinking it differently with everything being best if it can remain very much the same with similar familiar systems and existing figures of leadership. It can't be and it won’t be.

  10. Anonymous Coward
    Anonymous Coward

    The only people gagging for AI agents are the customers having them forced down their throats whether they want it or not.

  11. Bebu sa Ware Silver badge
    Facepalm

    Even before the advent of the current AI madness…

    Palo Alto edge devices gave me the security heebie-jeebies. I don't doubt these horrors will be upgraded to incorporate lashings of AI sauce. Lay down misère—losing every security trick but a winning hand in these irrational times.

    † a technical term we professionals use to describe our being frightened fæcesless.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon