A recent study by Box, a major company specializing in managing digital content, found that 83% of organizations are currently testing or using artificial intelligence (AI) agents. Guillaume Braux, a senior pre-sales engineer at Box, has warned about a serious issue that could affect how these AI agents are used in businesses. He explained that in the past 18 to 24 months, AI agents have become more advanced, able to perform tasks like reading, editing, and moving files quickly within a company's digital systems.
Braux pointed out that the risks associated with AI agents are not just about unauthorized access to networks, but also about how the agents behave. These virtual assistants now have legitimate access to company data, which creates new security challenges. One major concern is the possibility of "prompt injection," where an AI agent is tricked into following incorrect or harmful instructions when handling company information. This could lead to employees sharing more data than intended and make it hard to track what an AI agent has done.
According to Braux, it is very difficult to track the activities of these AI agents. If a data leak happens through one of them, it could be nearly impossible to know exactly what data was accessed, how it was used, or what actions the agent took. He acknowledged that completely banning AI agents would slow down business innovation, but he argued that it's not practical to stop their use entirely, as they are now a regular part of many companies' operations.
Instead of banning AI agents, Braux suggested that companies should change how they manage and secure interactions between AI agents and company data. In the past, security was focused on controlling access to data through network perimeters. However, with many AI agents potentially accessing data, the approach needs to shift toward protecting data itself, regardless of where it is accessed from. Braux explained that systems need to be able to control who—whether a person or an AI agent—can access specific data, and Box is working on tools to help ensure data, especially documents, is protected at the right level.
Enterprise AI Agents Pose New Security Risks, Expert Warns
AI-rewritten from original reportingHow it works
ai-agentscybersecurityenterprise-softwaredata-securityboxgovernance



