
Guarding Agentic AI
“Nobody notices the pattern until someone actually goes looking for it”
Amit Ninio, Manager, Security Engineering at Silverfort, joined CTech to share his thoughts on agentic AI security, and why he thinks the real risk isn't rogue agents, but access controls built on the old assumption that a human's judgment sits behind every identity.
“Non-human identity sprawl is a big part of it, but the deeper problem is an assumption baked into the access controls we inherited: that a human with judgment sits behind every identity,” said Amit Ninio, Manager, Security Engineering at Silverfort, on his biggest fear about agentic AI's rollout in the tech industry. “Agents don't fit that model. They pick up delegated permissions one at a time, and each one looks harmless on its own. Nobody notices the pattern until someone actually goes looking for it.”
CTech reached out to a spread of Israeli companies to find out how they're actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents currently operating with real autonomy?
“It depends on the risk. The clearest example of an agent with real autonomy is our open-source vetting pipeline, which for low-risk, low-impact packages makes the approve or reject call itself, with no human in the loop. Anything headed into production or the product itself works differently, since a security reviewer checks the agent's findings before we sign off. we don't treat every AI agent the same. How much autonomy it gets depends on what it's actually being asked to do.”
What security controls are in place versus on the roadmap?
“First, we need to know an agent exists at all. We use Silverfort's own visibility into AI agents to discover what's actually running across our environment, from sanctioned tools to shadow agents and anything unaccounted for, and map each one back to its owner.
"From there, every agent gets its own verified identity instead of a shared service account, so we can trace any action back to the agent that took it. A plain instruction telling an agent not to do something can be talked around, so our controls live below the prompt layer instead. For tool calls, that means routing agent traffic through Silverfort's own MCP Gateway, which checks each call against policy using Authorization Planes and Scopes before it ever reaches the target system. It's the same runtime enforcement model we build for customers, pointed at our own environment first.
"Deterministic blocks alone aren't enough, though. Agents are persistent, and they'll keep probing until they find a way past a hard block to reach their goal. So we layered on monitoring and enforcement for intent at the session level, catching cases where each step looks fine on its own but the pattern doesn't.
"Looking ahead, we want to move agent execution off the person's own machine entirely. Right now, an agent that takes a wrong turn can reach the same credentials, files, and local access its human operator has, simply because it's running inside that person's own environment. Separating the two removes that risk by design, whether the agent is running interactively or on its own schedule.”
Have you had an incident or near-miss?
“Yes. An agent deployed a mock internal application to the cloud on its own, skipping architecture review, and the app ended up publicly exposed. We caught it through detection and fixed it quickly. It's a big reason deployments now go through tiered review - anything past the simplest, lowest-risk changes needs a security check first.”
Where has AI already made things better or safer?
“We run parallel agents against every codebase change. Each one scans against the same framework, covering OWASP's top vulnerability classes, CWE mapping, and some threat modeling, and looks for actual exploitability rather than just surface pattern matches. A single reviewer working alone couldn't match that depth at the speed we need, and we've seen it catch things that would've been missed, or caught too late, if it were left to one person.
"It's also changed who can do this work. Some of it used to require someone who'd spent years in one narrow specialty. Now someone with solid experience and curiosity can do it too, because the agent carries a lot of that specialized depth for them. That's reshaped the team almost as much as it's reshaped the tooling.”














