AI Agents Are Exploitable. Here Is the Control Stack Taking Shape.
By Critical Ventures

As vendors, researchers and early adopters are implementing more agentic AI, agents are increasingly running into security issues. Help Net Security's monthly roundup is dominated by this, and a weekly newsletter covering the sector describes agent security as something that has become a procurement checkbox. Orchid Security announced that agents don't always break security controls directly. They can find and use the identity debt already sitting in an enterprise — hard-coded credentials, orphaned accounts, unmanaged authentication paths and excessive permissions. While a person rarely has the patience to work through these, an agent does it in seconds. The practical lesson is that an agent rollout is a good moment to clean up service accounts and standing permissions first, because agentic AI will find whatever is left behind.
Access is not the same as authority
Akeyless made its Agentic Runtime Authority generally available, adding intent-based access control that restricts what an agent does after it has been given access. Ping Identity's Enterprise Personal Agent Access enforces what each agent can access and do at the moment of action. Granting a credential answers who can get in. The Autonomous Edge newsletter reports that Manifold Security disclosed eight vulnerabilities, grouped as GitSpawn, across seven AI coding agents. The flaws abuse a Git setting so that code runs from a malicious repository configuration before the user approves anything, and four of the eight were reportedly unpatched at disclosure. The same newsletter says AIR Security, which raised a reported $50M in seed funding, filters roughly 27% of the agent add-ons it sees as unsafe (a company figure). CrowdStrike and Tenable both launched agent certification or vetting products in the same window. Agent plugins, skills and repositories are now part of the supply chain and deserve the same scrutiny as any third-party software.
Plan for the agent going wrong
Orchid added drift detection and application-level kill switches, and Cohesity introduced Agent Resilience to discover, protect and recover the infrastructure behind enterprise agents. Both start from an assumption that used to be optional: an agent will eventually do something wrong, and you need a way to stop it and a way to recover. If nobody on your team can say how to switch an agent off, or how to restore the systems it touched, the deployment is not ready. Cloud Range launched an AI Validation Range for testing whether agents are ready for operational responsibility, and compares their performance against human defenders. On the offensive side, Tuskira announced Vector for autonomous red teaming and BugBase released an enterprise Pentest Copilot. Hackurity, one of our portfolio companies, runs Managed Autonomous Pentesting, which continuously simulates full attacker chains across applications, users and infrastructure. In this new age, annual testing does not match a system that changes daily and acts at machine speed. Testing has to run continuously.
Runtime controls can block an action. They rarely show afterwards that a person approved it. That matters most where the outcome carries legal or clinical weight, such as patient consent or payments. Humanos, another portfolio company, provides a single API that makes human approvals machine-verifiable before an autonomous system acts. We see this evidence layer as less crowded than access control, though the market is early and we expect it to change.
Taken together, these lessons describe a control stack that identity and large security platforms will cover well: discovery, access, runtime enforcement. We think the openings for new companies sit in the parts that are harder to bolt on — verification of approvals, continuous adversarial testing, and protection of the embedded systems that agents will eventually operate. RunSafe Security, in our portfolio, works on that last piece by relocating software functions in memory at runtime to remove classes of memory-based vulnerabilities. We back founders who can show a working integration inside a real customer workflow. If you are building in this area, get in touch.