The agentic AI attack surface is less a matter of new territory than of new velocity, as autonomous software now reads, writes and moves corporate content faster than any human adversary could. That shift is forcing security leaders to rebuild detection, visibility and governance around agents they cannot always see.
Much of that activity is landing back where enterprise defense started, on the endpoint, where tool calls and model context protocol connections execute. CrowdStrike Holdings Inc. has responded by extending the Falcon platform to police agents at the endpoint, treating each one as an asset with an identity and a data footprint attached, according to Cristian Rodriguez (pictured, left), field chief technology officer of the Americas at CrowdStrike.
“Every enterprise has a collection of assets, and those assets are made up of this anatomy of the type of system that they run on, the identity that that system is attached to, the type of data that that system can ultimately access, and then AI essentially automates and accelerates that entire experience from start to finish,” Rodriguez said. “AI becomes essentially very autonomous and kind of self-serving or very far-reaching without the right guardrails and without the right trust system in place. Those systems can kind of do a lot of damage in your environment.”
Rodriguez and Heather Ceylan (right), chief information security officer of Box Inc., spoke with theCUBE’s Dave Vellante and Rebecca Knight at Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. (* Disclosure below.)
Speed, not size, redefines the agentic AI attack surface
Box, which added controls to govern AI agents working with enterprise content in July, sits at the point where sensitive files meet autonomous software. The company inherits CrowdStrike’s device posture score to decide whether a request for that content is sanctioned, Ceylan explained.
“Attack surface is the same, but it’s not just humans who are the attackers anymore. It’s agents and they move at machine speed. So everything got faster. Our detections need to be faster, our visibility needs to be real time,” Ceylan said.
Early adopters are now discovering what they deployed. Enterprises that moved first are returning to CrowdStrike six months to a year later asking for visibility and data controls across the estate, Rodriguez noted.
“They’re calling us saying, we have a problem, the AI sprawl is real, we know it’s in our SaaS apps, we know it’s on our endpoints, we know it’s in our cloud instances, help us get our arms around visibility and governance programs and control, because we’ve bitten off a little more than we can chew,” Rodriguez said.
Securing the agentic AI attack surface remains unsettled work, with no agreed architecture and no shared responsibility model of the kind that eventually made cloud legible. Security teams have to move at least as fast as engineering to stay in the process at all, Ceylan noted.
“The next couple of years [are] going to be really uncomfortable for CISOs and security leaders around AI. We haven’t really figured out what does security for AI look like and what is a secure AI architecture. It’s changing by the day and everybody’s kind of figuring out what works best for their organization. But I think in two or three years, we’ll settle a little bit on this is how we secure AI and here are all the different pieces we need to control,” Ceylan said.
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Fal.Con:
(* Disclosure: TheCUBE is a paid media partner for the Fal.Con event. Neither CrowdStrike Holdings Inc., the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)





