07 Sep 2026
Something has been shifting quietly across a lot of organizations lately. AI used to just answer questions — you'd type a prompt, get a response, done. Now, AI agents are starting to act on their own: reading files, calling APIs, executing code, sending messages, triggering workflows — all without needing human sign-off at every step.
SentinelOne frames this as a fundamental shift in how we need to think about AI security. It's no longer about "what AI says," but "what AI does." And according to them, most organizations aren't ready for it at all — they don't know where these agents are running, what they can access, or what actions they've already taken.
What stands out in SentinelOne's analysis is that agentic AI risk doesn't show up at a single point — it spreads across three distinct phases.
First, risk at build time. Many agents get deployed with IAM permissions far broader than what their tasks actually require. On top of that, teams often pull in third-party skills or plugins from public repositories without much verification — essentially the same supply chain problem the software world has dealt with for years, just now taking the shape of "capabilities" bolted onto AI agents. It's not unusual for API keys and secrets to be hardcoded directly into configuration files either, which means one leak exposes everything at once.
Second, risk at runtime. This is the layer traditional security controls struggle with most. Prompt injection attacks can manipulate an agent's behavior to the point of triggering real-world actions — not just producing a wrong answer. Picture a malicious instruction buried inside an ordinary document, quietly read by the agent, and executed as a command without anyone noticing. There's also the risk of agents chaining together individually authorized actions that, combined in sequence, produce an outcome that should never have happened.
Third, the operational gaps around the whole system. Even when the risks are understood, most organizations still lack a kill switch to stop a misbehaving agent within seconds, a rollback mechanism if data gets corrupted, or an audit trail to reconstruct exactly what an agent did.
SentinelOne points to a single root cause behind most of this: current agentic AI security frameworks still operate on implicit trust — trust in downloaded skills, trust in prompts that keep evolving, trust that agents will behave safely even as their autonomy grows. They've even flagged hundreds of malicious agent skills circulating through public repositories, disguised as ordinary utilities while quietly harvesting credentials and sensitive data at scale.
Their answer is Prompt for Agentic AI Security, a security layer built around governing the Model Context Protocol (MCP) — the protocol underpinning much of today's agentic AI infrastructure. Its capabilities include discovering and governing MCP servers (both sanctioned and "shadow" deployments), scoring risk before an agent is allowed to act, blocking prompt injection in real time, and preventing malicious MCP servers from operating in the environment.
One of the more practical parts of this approach is the rollout timeline SentinelOne lays out for adopting agentic AI safely:
The core point is pretty simple: agentic AI isn't slowing down, so this was never really about whether to adopt it. What separates organizations that get this right from the ones that get burned is whether they have visibility into every agent running in their environment, know exactly what those agents can reach, have a way to enforce boundaries, and keep a complete record of every action taken.
If your organization has already started putting AI agents to work in daily operations without a clear security layer behind them, SentinelOne's Prompt for Agentic AI Security is built for exactly this moment — giving you real-time discovery, risk scoring, and policy enforcement before an unauthorized action ever gets the chance to happen. Learn more about Prompt for Agentic AI Security or request a demo to see it in action.
Author: Ghea Devita
Marketing Communication PT Perkom Indah Murni