Eli Hakimov, CISO at Immunai.
Guarding Agentic AI

“This is a shadow workforce, autonomous, fast, and invisible, and it scales in a way shadow IT never did”

Eli Hakimov, CISO at Immunai, joined CTech to share his thoughts on agentic AI security, and why the agents that worry him most aren't the ones his team adopted, but the ones nobody vetted.

“Shadow agents. Employees connect AI tools to company data and systems without security knowing, and each connection is a new identity with real permissions that no one is watching. Ten years ago we called this shadow IT. This is a shadow workforce, autonomous, fast, and invisible, and it scales in a way shadow IT never did,” said Eli Hakimov, CISO at Immunai, on his biggest fear about agentic AI's rollout across the industry.
“That's why our first investment was visibility, because you can't govern what you can't see,” he explained. “My real fear isn't the agents we adopted thoughtfully at Immunai. We'll make mistakes with those, but we'll catch them. What keeps me up is the agent nobody vetted, nobody monitors, and nobody told us about. The companies that get hurt will be the ones that never knew they had agents in the first place.”
1 View gallery
Eli Hakimov, CISO at Immunai.
Eli Hakimov, CISO at Immunai.
Eli Hakimov, CISO at Immunai.
(Immunai)
CTech reached out to a spread of Israeli companies to find out how they're actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents operating with real autonomy, or is everything human-supervised?
We're past the pilot stage. Agents here do real work end to end, and the clearest example is our agentic investigator, which runs the first layers of incident response triage. What we haven't done is remove the human. Anything that touches identity, access, or production goes through a human approval gate by policy. That's a choice, not a limitation we're waiting to outgrow. So when people ask when full autonomy arrives, my answer is that it isn't a technology gap anymore. It's a trust gap, and trust gets built as the models improve and as we put the right guardrails around them. We're closing it in stages, on our terms.
What security controls are in place versus on the roadmap?
Today we have a visibility platform with blocking capabilities, plus a kill switch on every agentic workflow, so if an agent misbehaves we cut its access in seconds. None of this happened by accident. Late last year, before agentic AI became a headline, we built a strategic roadmap for AI-related risks, and mitigating agentic risk is one of its objectives. Attackers adopted AI faster than defenders, and that gap is real. What's missing is a platform that governs agents with context, not just what they're allowed to do, but what data they touch and the intention behind their actions. We design-partner with several AI security startups to build exactly that.
Have you had an incident or near-miss?
No incidents so far, and I'm careful with that sentence, because in this space "so far" is doing a lot of work. The absence of an incident doesn't mean the risk isn't there. It usually means you haven't been tested yet, or that you can't see it. And the threat isn't only external. The industry already saw an internal coding agent delete a company's production database during a code freeze, then mislead the team about what it had done. No attacker, just an agent with too much access and too little oversight. That's exactly why we started building controls before we needed them. Incidents like that will only grow as agents gain more access, and we intend to be the company that prepared early, not the one writing the postmortem.
Where has AI already made things better or safer?
Incident response is our clearest win. Our IR agents do the first pass on every alert, gathering context, correlating signals, and building a timeline, which turns hours of analyst work into minutes. That time goes straight back to the team, so our people spend their day on judgment calls instead of data collection. There's a bigger point behind it, though. AI agents aren't inherently a threat and they aren't inherently a solution. They're a force multiplier, and the question is whose force gets multiplied first.
Where has an AI agent already made things better or safer?
There are tangible benefits to be seen in the area of security operations, especially around triaging vulnerabilities and threats. An agent can pull context from multiple systems, enrich the finding, and prioritize the most important elements to be acted on.
The human makes the decision of how to act, but now has a much better starting point. This cuts down on duplicate effort, saves time, and reduces the chance that context will get lost in the process.
I believe the idea of “being ahead” means anything but more autonomy for agents. It means treating agents from the start as privileged machine identities rather than smart chatbots.