Across technology, shifts tend to unfold in a familiar cycle. It starts with a promise that turns into adoption, then pressure and security teams are left to keep up. Public cloud is a clear example of this. Without a shared definition, cloud adoption lacked meaning in the enterprise, which created both opportunity and uncertainty. As a result, large organizations often struggled, facing setbacks including losing advantage to faster-moving competitors, or discovering shadow IT initiatives operating outside formal governance. Security, in response, became reactive rather than strategic.

We’re currently seeing this today with AI, but the consequences are greater. AI evolves in waves and allowing AI to operate without control may be one of the costliest mistakes organizations can make.

Understanding AI’s evolution

Early enterprise AI adoption – the first wave – centered on predictive analytics. Organizations invested in data lakes and machine learning systems designed to surface patterns quietly behind the scenes. These initiatives often advanced with minimal executive attention, and as the overall aim was to protect sensitive data, the challenge was relatively straightforward for security teams.

But this changed with the second wave of AI adoption – generative AI. As soon as systems capable of producing natural language, software code, and visual content became widely accessible, AI became a strategic imperative. However, this sudden spotlight introduced a new problem.

Generative AI was treated as synonymous with AI itself, obscuring the fact that not all AI models carry the same safeguards. As a result, security efforts gravitated toward what was most obvious rather than what was most significant. According to the World Economic Forum’s Global Cybersecurity outlook 2026, roughly one-third of organizations still lack any process to assess the security of AI tools before deployment, while 34% cite data leaks associated with generative and agentic AI as a leading cybersecurity risk. Consequently, many enterprises are adapting their existing tools rather than properly re-architecting security strategies. If we consider early AI and generative AI adoption to be waves one and two of AI, then it is the third wave – agentic AI – that is fundamentally changing the threat landscape.

The shift to autonomous agents

Agentic AI has distinctive qualities from other AI tools. It operates by connecting directly to business environments, often making decisions with limited human supervision, and its impact is already visible across enterprises. While current use of agentic AI across organizations is moderate today, adoption is expected to surge rapidly over the next couple of years. However, governance and security guardrails are still missing, which is creating gaps where legacy security thinking breaks down.

Each type of AI model has its own disadvantages. With predictive and generative AI, there are data exchange concerns. Agentic AI turns the problem into behavior and system integrity. When AI agents can access ERP platforms or financial infrastructure, the risk of compromise increases significantly. This is a familiar pattern: when the internet shifted from static pages to dynamic applications, it introduced entirely new classes of vulnerabilities, with SQL injection emerging as a defining threat. Agentic AI is repeating that cycle as automation consistently opens new attack paths. And at the moment, security teams are struggling to keep pace with the risks that it is introducing.

When over-confidence becomes a risk

Businesses are attempting to meet this evolving agentic AI threat head-on by increasing their cybersecurity budgets. However, there’s a critical disconnect as this rise in investment is in fact creating an illusion of security. Enterprises believe that they are secure as they control everything internally, but fail to consider the ecosystem of external partners, platforms, and AI-driven supply chains.

This confidence becomes dangerous when agentic AI moves outside organizational controls. Capabilities considered “internal” today can easily become part of supply-chain automation later. Sectors such as retail, logistics, and manufacturing are likely to accelerate this shift as they pursue sustainability targets or AI-driven optimization. Once agentic systems begin managing work between companies, the attack surface grows, allowing threats to propagate beyond an organization’s ability to contain security incidents.

Where security must change

Existing security principles still apply against AI threats, but they need to evolve. The controls needed to secure agentic AI largely stem from the same frameworks used to manage human users. What changes is the behavior, speed, and scale. From a security perspective, agents must be treated like humans, and subject to zero-trust controls. For AI agents, this includes being issued with identities, facing least-privileged access, and adhering to strict behavioral guidelines. If an agent were to rebel, its behavior should be deemed as suspicious human activity.

This makes segmentation non-negotiable as a practical way to reduce potential damage. Without updated guidelines, a compromised agent can move rapidly. As importantly, AI security cannot be layered on after the fact.

Beyond reactive security

If cloud adoption and AI evolution taught us anything, it’s that security strategies based on reactivity will eventually fall short. Today, innovation moves faster than governance frameworks or regulatory processes. Enterprises evolve beyond waiting for frameworks to mature or for breaches to dictate priorities and instead focus on a proactive approach.

Organizations must shift from tactical fixes to architectural flexibility. Security needs to adapt with AI instead of weakening against evolution. Agentic systems are only going to become more autonomous, more connected, and more deeply embedded in operations. AI has already altered the threat landscape, and organizational readiness will determine whether businesses absorb the impact or are overtaken by it. The reality is that unless enterprises adapt, they will only repeat the same mistakes made during early cloud adoption.