Noam Brosh, CISO at UVeye.
Guarding Agentic AI

“Security cannot simply act as a roadblock, because that stops the momentum that leadership demands”

Noam Brosh, CISO at UVeye, joined CTech to share his thoughts on agentic AI security, and why the risk he's most focused on isn't technical anymore, it's how fast non-technical teams are deploying agents of their own. 

“The AI landscape in cybersecurity is unpredictable and moving so rapidly that no one can truly predict what tomorrow will bring. Right now, there is no single unified platform that can provide a complete security solution for all these emerging risks. The reality is that organizations need a stack of two to three complementary systems to manage current requirements and adapt to what is coming,” said Noam Brosh, CISO at UVeye, on his primary security concern regarding the industry-wide rollout of agentic AI.
“At the same time, the challenge is deeply human,” he explained. “It is no longer just developers adopting AI; non-technical teams in HR, Finance, and Marketing are actively deploying agents to hit ambitious KPIs and OKRs. People naturally want to maximize efficiency, but they often don't fully appreciate the risk created when non-human identities are granted over-privileged access."
"Security cannot simply act as a roadblock, because halting these initiatives stops the business momentum leadership demands. Granting write access across interconnected enterprise systems exposes organizations to indirect prompt injection attacks and machine-speed operational disruptions, so the priority must be guiding these teams to operate safely through multi-layered tools without bottlenecking progress.”
1 View gallery
Noam Brosh, CISO at UVeye.
Noam Brosh, CISO at UVeye.
Noam Brosh, CISO at UVeye.
(Photo: SecurityScorecard / BlackHat 2026)
CTech reached out to a spread of Israeli companies to find out how they're actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents currently operating with real autonomy?
Even though the world is rapidly turning agentic, and real AI autonomy is here and will be here to stay, our current use of AI in security-sensitive workflows remains designed around a human-in-the-loop model. While we leverage specialized AI tools and automation for rapid data processing, threat analysis, and pattern recognition, operational changes, code deployments, access adjustments, and remediations require explicit human validation before execution.
What security controls are in place versus on the roadmap?
On a practical level, we enforce strict least-privilege scoping, isolated sandbox execution environments, data minimization practices, and comprehensive audit logging for all model inputs and outputs. Today, achieving AI observability and visibility across endpoints, internal systems, and the cloud has become relatively straightforward, with many platforms offering it out of the box through sensors, web extensions, or gateways. The real battlefield everyone is focused on now is active agentic enforcement, particularly inside cloud production environments. Looking at our roadmap, rather than committing publicly to rigid technical features, we are prioritizing broader non-human identity governance concepts and dynamic control mechanisms so that active cloud enforcement evolves safely as our AI adoption grows.
Have you had an incident or near-miss?
We are not aware of any material security incidents attributable to AI agents to date. From my perspective, that comes down to maintaining a healthy level of caution: our approach centers on limited permissions and strong human oversight to catch potential issues early. By enforcing read-only default permissions and strict supervisory gating for active tasks, our goal is to identify and resolve model anomalies or hallucinations during the review phase before they reach production.
Where has AI already made things better or safer?
Coming from the SIEM world, I know firsthand how easy it is for analysts to get overwhelmed by massive log volumes and alert noise. Seeing next-generation SIEM platforms integrate native AI capabilities has been a major win. AI capabilities have significantly elevated our Security Operations Center (SOC) triage and threat intelligence workflows. Automating alert enrichment and log correlation allows our team to surface actionable insights far more rapidly, streamlining repetitive manual investigations and accelerating our overall response capability.