For decades, cybersecurity has drawn a distinction between Information Technology (IT), which processes information and Operational Technology (OT), which directly influences physical or business operations. The rise of AI agents is beginning to blur that boundary.
Unlike traditional software, AI agents do not simply execute predefined instructions. They observe environments, analyse information, make decisions and increasingly take autonomous actions. Connected to enterprise systems, cloud platforms, security tools, financial systems or industrial environments, they can perform tasks once reserved for human operators. In effect, they become digital workers operating and collaborating with other agentic entities at machine speed as I wrote about earlier You Secured the Device … Who Secured the Decision?
This creates a new category of risk. If Internet of Things ( IoT) devices act as digital senses and OT systems act as digital muscles, AI agents represent digital cognition. They sit between observation and action, making decisions that can directly affect business processes, infrastructure and even the physical world.
The strategic shift is that AI agents are not merely another software component. They are becoming a new operational entity class that sits somewhere between software, automation and human workers. From a risk, governance, and assurance perspective, treating them as a form of Autonomous Operational Technology (AOT) may prove more useful than trying to force them into either the traditional IT or IoT categories.
The cyber threat implications are significant. Traditional software assurance focuses on code vulnerabilities and deterministic behaviour. AI agents introduce new attack surfaces, including prompt injection, model manipulation, poisoned training data, compromised memory stores, malicious tool integrations and agent-to-agent exploitation. An attacker may no longer need to compromise infrastructure directly; influencing the decisions of a trusted autonomous agent may achieve the same outcome.
Perhaps most concerning is the scale. A single compromised human operator can cause damage. Thousands, if not 10’s of thousands of interconnected AI agents acting on flawed information, manipulated instructions or adversarial inputs could propagate errors across entire organisations within seconds. Although they do not fit neatly into traditional OT or IoT definitions, the more interesting question is whether AI agents should be governed using many of the same principles that evolved for OT systems.
As organisations increasingly delegate authority to autonomous systems, cybersecurity must evolve beyond securing software. The challenge becomes establishing trust in autonomous decision-making itself. In a future shaped by AI agents, assurance will focus not merely on whether systems are secure, but whether autonomous digital actors can be trusted to exercise the authority granted to them.
Just as organisations developed governance, segregation of duties, supervision and audit trails for humans, they will increasingly need equivalent controls for autonomous agents.
Posted on May 30, 2026
0