
Guarding Agentic AI
“I’m concerned by the human who stops looking.”
Yigal Elefant, CISO at AU10TIX, joined CTech to share his thoughts on agentic AI security, and why burnout, not the AI itself, is the risk that worries him most.
“Computers fail. AI has its own failures in addition to the computer’s failures. None of that is a reason to stop using it. Decide where you can absorb a failure and where you cannot. I’m not concerned or surprised by an agent being wrong. I expect that, and the correct junction is exactly how we plan for it. I’m concerned by the human who stops looking,” said Yigal Elefant, CISO at AU10TIX, on his biggest fear about agentic AI’s rollout across the industry.
“The market pace is what wears that human down,” he explained. “The blessing and the curse of this market is that work isn’t a place anymore. It’s everywhere, all the time. Push hard enough and review turns into a rubber stamp, where people still click approve, but nobody is really reading. That isn’t an AI failure, it’s burnout, and it takes out the one control everybody is relying on. I half expect a strange future in which companies run seven days a week with two parallel teams working four days each. I’d rather we designed for that on purpose than arrive there exhausted.”
CTech reached out to a spread of Israeli companies to find out how they’re actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents currently operating with real autonomy?
The hard part with “human in the loop” is identifying the junction where that human is actually required. I treat every AI agent like a dependency I imported: reviewed, but not fully trusted. Can anyone honestly say nobody ever missed anything in a code review? We accept that uncertainty and we design around it, so agents do work autonomously on internal and reversible tasks. What we invest in is mapping the decision points and ensuring that a human is in the loop at the ones that really matter. Involving a human everywhere doesn’t make things safer, just slower. Involving a human at the correct junction is what protects you.
What security controls are in place versus on the roadmap?
The most important factor here is keeping things as simple as possible. The more complex a control is, the harder it becomes to manage and secure. If I can’t explain a control in one sentence, I can’t enforce it either. We built this in two layers: on the technical side, our agents run inside a managed AI foundry, with scoped permissions, contained and monitored, and logs that we actually read. One boundary instead of twelve. On the human side, every AI use has a named owner. We have a company AI leader, and AI champions inside each team who are responsible for both implementing AI and for supervising and controlling it.
Have you had an incident or near-miss?
Nothing so far. But that isn’t luck, and it’s an ongoing, never-ending mission. Most of the work is on the context we give the agent rather than on the agent itself, and if you stop doing that work it drifts. We did have a near miss that keeps us honest. An agent recommended a configuration change that would have locked us out of our own access. Review caught it, which is exactly what the human at that junction is there for.
Where has AI already made things better or safer?
AI has moved the needle in every team. Our AI leader ran a Skill-A-Thon to get the ideas out of people’s heads and into the company’s day-to-day. Dev teams built their own skill that gets them to root cause in ten minutes. Our fraud group uses AI to link identity fraud attempts and feed that back into the product. In security we use it to analyze reported phishing emails, so when an employee reports something there’s real analysis behind the answer instead of a queue.
When I was barely ten, my father taught me how to build a PC. He always told me that a computer is only as smart as the person running it. I think the same is true for AI. Smart isn’t telling AI to secure your company and then going for a coffee while it works. It’s guiding it to the problems that are actually yours, and working with it to achieve the right fix for your company. The tool got faster. The judgment is still yours.














