Cisco Executive Warns of Critical Authorization Gaps in AI Agent Security
Anthony Grieco, Cisco’s SVP and Chief Security and Trust Officer, highlighted a critical security vulnerability in AI agent deployments during an interview at RSAC 2026. He revealed that rogue agent incidents are occurring regularly within Cisco’s customer base, driven not by authentication failures but by broken authorization mechanisms. While agents successfully verify their identity, they often access data or perform actions beyond their intended scope due to a lack of granular control. Cisco’s 2026 State of AI Security report indicates that while 83% of organizations plan to deploy agentic capabilities, only 29% feel prepared to secure them. Industry experts note that organizations frequently clone human user profiles for agents, leading to immediate permission sprawl. Furthermore, current logging systems struggle to distinguish agent activity from human actions. Although five vendors, including Cisco, launched agent identity frameworks at the conference, none fully resolved the identified authorization gaps. Standards bodies like NIST and OWASP are concurrently developing guidelines to address these structural security challenges in the rapidly expanding agentic workforce.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection