Novo AI
BetaStratNovo · Always here to help
Hi, I'm Novo AI — your intelligent guide to StratNovo. Ask me anything about our services, pricing, or how we can help build your product.
Novo AI may be inaccurate — verify key details with the team.
AI agents are moving beyond answering questions. As they gain access to tools, data and business systems, security has to evolve with them.

AI agents are changing what artificial intelligence can do. For years, most business conversations around AI focused on systems that generate something: an answer, a report, an image, a piece of code or a recommendation. That is changing. Modern AI agents can increasingly do more than generate responses. They can browse the web, retrieve information, use software tools, work with files, interact with applications and execute multi-step tasks on behalf of users. Anthropic describes this shift as a move toward systems that can plan, use tools, observe results and continue working toward a goal with less human intervention. That additional capability creates a new problem. The more an AI agent can do, the more important it becomes to control what it is allowed to do. A chatbot and an AI agent are not the same security problem Consider a traditional chatbot. You ask: “Summarise these documents.” The system produces an answer. Now consider an AI agent connected to your company's systems. You ask: “Review these customer complaints, identify urgent cases, update the relevant records and notify the appropriate team.” The agent may need to read documents, access a database, interact with an application and send messages. The second system has considerably more authority. That means an error is no longer limited to a bad response on a screen. An agent could potentially access information it should not access, make an incorrect change, send information to the wrong person or execute an action that was never intended. This is why AI agents are becoming a new security boundary. The problem with giving AI too much access One of the most important principles in security is least privilege: a system should have only the access it actually needs. The same principle needs to apply to AI agents. If an agent is only supposed to analyse documents, why should it have permission to modify a database? If it is researching information, why should it have access to confidential email? If it is preparing a payment, should it also have permission to approve and execute that payment? The answer should generally be no. OpenAI's current guidance for agents similarly recommends limiting an agent's access to only the data and capabilities required for its task, while using confirmation for consequential actions. The challenge is that businesses are increasingly connecting AI systems to the tools they already use. That makes permission design an AI engineering problem as much as an IT security problem. Then there is prompt injection There is another problem that is easy to overlook. An AI agent does not only receive instructions from its user. It may also encounter information from websites, emails, documents, databases or other external sources. That information can contain instructions designed to manipulate the agent. This is known as prompt injection. Imagine asking an AI agent to research a website. Hidden inside that website could be malicious instructions telling the agent to ignore its original task, reveal information or perform another action. The user never asked the agent to do those things. The agent encountered the instructions while carrying out its task. OpenAI describes prompt injection as an evolving security challenge for AI systems that interact with external content, and notes that these attacks increasingly resemble social engineering rather than simple attempts to override a model's prompt. This creates an important distinction: Not everything an AI agent reads should be treated as an instruction. Human approval is useful — but it is not enough A natural response is: “Just make the AI ask a human before doing anything important.” Human oversight absolutely matters. But it is not a complete security strategy. Anthropic has written about the limitations of relying exclusively on human approval. In its own experience, users can become accustomed to repeated permission requests and approve them without carefully examining every action. Anthropic therefore emphasises containment and access boundaries alongside human supervision. The better approach is layered. An agent should operate within clearly defined boundaries. Those boundaries can include: Limited permissions Only give the agent access to what it needs. Sandboxing Restrict what the agent can access and execute. Human approval Require confirmation before high-impact actions. Monitoring Record and observe what the agent is doing. Audit trails Make actions traceable after the fact. Testing and red-teaming Continuously test the system against unexpected and malicious inputs. Clear separation of responsibilities Do not allow one agent to freely read, modify and approve everything. The bigger shift This changes how organisations should think about AI adoption. The question should no longer be: “Can we connect AI to this system?” It should be: “What authority should the AI have inside this system?” Those are very different questions. A business may be able to technically connect an agent to its CRM, email, financial system or internal database in a matter of hours. That does not mean it should. Before deployment, organisations need to understand: What data can the agent access? What tools can it use? What actions can it perform? Which actions require approval? What happens when the agent encounters untrusted information? How are its actions monitored? How can its access be revoked? What happens when the agent makes a mistake? These are not future questions. They are becoming deployment questions today. AI security is becoming part of AI engineering The industry has spent enormous effort making AI models more capable. The next challenge is making those capabilities usable safely and reliably in real environments. That means AI systems cannot be treated as isolated models. A production AI agent is a combination of: Model + Data + Context + Tools + Permissions + Workflow + Security + Monitoring + Human Oversight If one of those components is poorly designed, the entire system can become unreliable. For Stratnovo, this is an important distinction. We should not think about AI simply as a model that produces an impressive answer. The more valuable question is: Can we build an AI system that can actually operate within a business while remaining controlled, observable and accountable? That is where the real engineering challenge begins. The takeaway AI agents will become increasingly capable of taking action. That capability creates enormous opportunities for automation and productivity. But autonomy without boundaries is not innovation. It is unmanaged risk. As businesses move from AI that generates to AI that acts, security needs to move with it. The future of AI will not only be determined by how intelligent our models become. It will also depend on how well we design the systems around them. The smarter the agent becomes, the more carefully we need to define what it is allowed to do.
Written by
Stratnovo
20 August 2026