Aviv Nahum, CEO of Above Security.
Guarding Agentic AI

“We are effectively creating a new population of synthetic insiders at enormous speed”

Aviv Nahum, CEO of Above Security, joined CTech to share his thoughts on agentic AI security, and why he thinks the real danger isn't rogue AI, but companies handing agents credentials and access faster than they can govern them.

“Not rogue AI. I think that framing is mostly a distraction,” said Aviv Nahum, CEO of Above Security, on his biggest fear about agentic AI's rollout in the tech industry.
“My concern is much more boring: companies are going to give thousands of agents credentials, access to sensitive data and permission to act across production systems before they have any real idea how to govern them. We are effectively creating a new population of synthetic insiders at enormous speed.”
1 View gallery
Aviv Nahum, CEO of Above Security.
Aviv Nahum, CEO of Above Security.
Aviv Nahum, CEO of Above Security.
(Photo: Yair Glazer)
CTech reached out to a spread of Israeli companies to find out how they're actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents currently operating with real autonomy?
“Yes. We already use agents with meaningful autonomy, especially for investigation, analysis and internal workflows. I think the useful distinction is not “human in the loop or not,” but what level of authority the agent has. We are comfortable letting agents do a lot on their own when the downside is bounded. The more consequential the action, the tighter the control.”
What security controls are in place versus on the roadmap?
“We treat agents like real identities. They have owners, scoped permissions, clear access boundaries and full activity visibility. But I think the bigger security question is behavioral: not only “is this agent allowed to do this?” but “does this action make sense given what the agent was supposed to be doing?” That is where the industry still has a lot of work to do.”
Have you had an incident or near-miss?
“Nothing material. But if you use agents seriously, you quickly see them take paths you did not explicitly design. Sometimes that is the whole point - they find a better way to complete the task. Sometimes it is exactly why you need controls. I would be more worried about a company claiming its agents always behave exactly as expected than one admitting they occasionally surprise them.”
Where has AI already made things better or safer?
“Security investigations. An agent can pull together activity across identity, endpoint, SaaS and data systems, build the timeline and test different explanations far faster than a person doing it manually. The win is not that the AI replaces the decision-maker. It removes a huge amount of mechanical investigative work so the person can spend their time on the actual judgment call.”