Eyal Alkalay, CIO at Verbit.
Guarding Agentic AI

“Security has to evolve at the same speed as the agents themselves.”

Eyal Alkalay, CIO at Verbit, joined CTech to share his thoughts on agentic AI security, and why speed, access, and scale, not slower adoption, are the real risks to watch. 

"If a person with too much access makes a mistake, the impact is usually limited by how quickly that person can act. An AI agent can potentially take many actions across multiple systems in seconds," said Eyal Alkalay, CIO at Verbit, on the biggest risk he sees in agentic AI's rollout.
"If the agent has excessive permissions, receives a malicious instruction, is affected by prompt injection, or simply makes a bad decision, the impact can grow very quickly,” he explained.
“Even with this concern in mind, at Verbit we don't think the answer is to slow down our AI adoption, the challenge for the industry, and for us, is to make sure that security, identity, permissions, and monitoring evolve at the same speed as the agents themselves.”
1 View gallery
Eyal Alkalay, CIO at Verbit.
Eyal Alkalay, CIO at Verbit.
Eyal Alkalay, CIO at Verbit.
(Verbit)
CTech reached out to a spread of Israeli companies to find out how they're actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents currently operating with real autonomy?
At Verbit, AI is already an important part of how we build products and operate as a technology company. We are actively using and testing agentic capabilities, but we are deliberate about where we allow full autonomy. For higher-risk activities, especially those involving production systems, sensitive data, or significant changes, we still require human oversight and approval. As the technology and our controls mature, we expect the level of autonomy to increase.
What security controls are in place versus on the roadmap?
We approach AI agents much like we approach other automated or privileged access to our environment. Access is scoped based on need, permissions are limited, activity is logged and monitored, and access can be removed when necessary. We also have governance around the introduction and use of new AI tools. At the same time, agentic AI is moving very quickly, so this is not a finished security model, and we continue to evolve our controls around agent identity, permissions, access to company data, monitoring of agent activity, and the ability to stop or isolate an agent when needed.
Have you had an incident or near-miss?
We have not had a significant security incident caused by an autonomous AI agent, but, like most technology companies, though, we are seeing AI adoption move extremely fast, including employees experimenting with new tools and capabilities, we have recognized early in the process that this creates new risks, which is why we put governance and approval processes around AI use rather than waiting for an incident to drive those decisions.
Where has AI already made things better or safer?
We already see meaningful benefits from AI across Verbit. It helps our teams analyze large amounts of information faster, identify anomalies, support security investigations, accelerate development, and automate repetitive work.
The real value for us is not just replacing manual tasks, it is allowing our engineers, security teams, and other employees to work faster and spend more of their time on problems that require experience and judgment.
To conclude, that's the direction I see at Verbit: use AI at scale where it creates value, put the right controls around it, and keep people accountable for the decisions that matter.