Lior Mazor, Chief Information Security Officer at Appcharge.
Guarding Agentic AI

“My biggest concern is that autonomy will move faster than accountability”

Lior Mazor, Chief Information Security Officer at Appcharge, joined CTech to share his thoughts on agentic AI security, and why he thinks agentic AI's biggest risk is a gap between how fast autonomy is expanding and how fast accountability is keeping up. 

“My biggest concern is that autonomy will move faster than accountability. Companies are giving AI agents access to code, systems and sensitive information, but the controls governing what those agents can see, decide and change are not always evolving at the same pace,” said Lior Mazor, Chief Information Security Officer at Appcharge, on his biggest fear about agentic AI rollout in the tech industry.
“An agent does not need malicious intent to cause damage. A poorly defined task, excessive access or the wrong information reaching the wrong people can be enough. The danger is treating speed as a substitute for control. The answer is not to block agentic AI. It is to define clear boundaries, limit where agents can operate, monitor their actions and keep human accountability in place. AI can move extremely fast, but responsibility still has to belong to a person,” he explained.
1 View gallery
Lior Mazor, Chief Information Security Officer at Appcharge.
Lior Mazor, Chief Information Security Officer at Appcharge.
Lior Mazor, Chief Information Security Officer at Appcharge.
(Courtesy)
CTech reached out to a spread of Israeli companies to find out how they're actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents currently operating with real autonomy?
At Appcharge, AI is already embedded across the way we build and operate the company, including software development, cybersecurity, finance, reporting and payment processes. AI agents support defined tasks within these workflows, but they do not operate without human oversight. People remain involved in directing, reviewing and approving their work, and retain accountability for the outcome.
What security controls are in place versus on the roadmap?
Today, we have several layers of control in place. Our AI-SDLC framework scans every code commit, flags vulnerabilities and can generate a proposed fix before a human reviews it. We also use an internal system called AI-DR to verify that employees are using only approved AI tools and to flag policy violations before they become incidents. These controls are supported by a defense-in-depth approach, so no single security mechanism is solely responsible for protecting customer data.
Have you had an incident or near-miss?
Not yet, but we recognize that the growing use of AI agents introduces new security risks, which makes preparedness and response increasingly important. Appcharge has a dedicated Incident Response team that combines established security tools with AI-based capabilities to investigate incidents and respond to cyber threats.
Where has AI already made things better or safer?
One clear improvement is the speed at which we can identify and address security issues. Our AI agents work continuously: they scan code for vulnerabilities, generate fixes, monitor compliance and triage security alerts. The AI-driven security operations agent can alert me to a potential breach and begin the initial investigation before I have even seen the alert. This allows the security team to respond faster and operate continuously without removing human accountability. AI is extending what the team can do, while our people continue to set direction, review decisions and remain responsible for the outcome. These security methods also support and secure Appcharge's broader use of AI, including the use of AI to write around 80% of the company's code.