Shared Responsibility in the Era of Smart Assistants: When Security Boundaries Blur Between Providers and Customers
Agentic AI—autonomous AI systems that act as intelligent “agents” on behalf of the user—is transforming the way organizations operate. Tech giants such as Microsoft and Salesforce are integrating these assistants directly into business systems to streamline processes and improve productivity. However, alongside the benefits, it is becoming clear that many organizations are unaware of their responsibility to protect the data these agents access.
Similar to cloud computing services, a Shared Responsibility Model applies here as well: the AI provider secures the technological infrastructure, but the customer is responsible for access configurations, data policies, and determining who is authorized to use the agents.
New Vulnerabilities in a New World: When an AI Agent Becomes a Gateway for Leaks
A prominent example is the “ForcedLeak” attack—a critical vulnerability chain discovered in Salesforce’s Agentforce system. This vulnerability allowed an attacker to steal sensitive customer data (CRM) using a technique known as Indirect Prompt Injection (a type of hidden “command injection”). This incident illustrated how easily a poorly configured AI agent can be breached.
Experts warn: autonomous agents, which often operate without human intervention, may be granted excessive privileges, expose corporate secrets, or utilize unsecure processes. The core issue is managerial—who is truly responsible when the AI acts in your name?
Mutual Responsibility and the Boundaries of Trust: Providers Give the Tools, but Customers Must Set the Limits
Security experts agree that responsibility is shared. The customer must establish clear access boundaries for agents, understand what data they consume and where they send it, and perform ongoing audits. The provider must implement advanced security measures, such as Multi-Factor Authentication (MFA) or Data Loss Prevention (DLP) controls, but must not rely on them as a standalone solution. As with phishing attempts, there is a need to protect users from their own mistakes and build an infrastructure that prevents a human error or misconfiguration from evolving into an organizational data breach.
Recommendations from IPV Security Information Security Experts:
* Defining Responsibility Boundaries: The provider is responsible for the AI infrastructure; the organization is responsible for data management, access permissions, and monitoring agent activities.
* Dynamic Access Controls: Ensure that the AI agent accesses only the data necessary for its specific task, rather than the entire corporate database.
* Multi-Factor Authentication: Implement MFA for any agent access to sensitive systems, such as CRM or ERP (Enterprise Resource Planning) systems.
* Complementary Tools: Deploy Secrets Scanning and DLP controls, while remembering that these tools alone do not provide complete protection.
* Training and Awareness: Train employees and managers on how to use AI tools responsibly and cautiously, avoiding the disclosure of unnecessary information to agents.
In conclusion, the Agentic AI revolution requires a cautious approach: it is not just a technology, but a shift in the structure of responsibility. To prevent the next “knowledge leak,” organizations must integrate technology, workflows, and human awareness. In a world where AI acts on its own, responsibility is never truly autonomous.
For more information: https://www.darkreading.com/cybersecurity-operations/ai-agent-security-awareness-responsibility
To consult with an expert, contact the specialists at IPV Security!