AI Governance Institute
← News
Research2026-09-19

Mandiant: AI Agents Create Attack Surface That Identity and Telemetry Controls Cannot Yet See

Source

Mandiant warns of AI agents fuelling new attack risks

Security Brief Australia

Via Security Brief Australia

What happened

Mandiant, Google's threat intelligence and incident response unit, published a warning on AI agent attack surface expansion that compliance and security teams have not yet built the telemetry architecture to detect. The firm identified AI agents as a distinct class of privileged workload that generates novel signal types -- prompt streams, chained API calls, tool invocations -- that conventional SIEM and EDR pipelines do not ingest by default. Without connecting those signals, enterprises cannot detect misuse, data exfiltration, or scope drift in real time. Mandiant recommended adaptive identity controls designed specifically for non-human agent identities, continuous behavioral telemetry integrated across endpoint and API layers, and automated response capabilities capable of operating at agent speed. The warning arrives as a growing cluster of agentic AI incidents and industry research confirm that organizations deploying agents without adapted monitoring are already experiencing undisclosed exposure.

Why it matters

  • ·Regulators and auditors are increasingly asking whether enterprises can demonstrate continuous oversight of agent behavior. Without prompt-stream and API-activity telemetry fed into governed monitoring tools, compliance teams cannot provide that evidence, creating documentation and audit-readiness gaps under frameworks such as ISO/IEC 42001:2023.
  • ·Mandiant's focus on adaptive identity controls signals that static, human-centric IAM configurations are inadequate for agent deployments. Agents that operate under standing credentials or broad OAuth scopes create privilege escalation paths that existing access control reviews will not surface, as recent OAuth attack-chain research has confirmed.
  • ·Incident response playbooks built for human-initiated events are too slow for agent-speed attacks. Mandiant's call for automated response pipelines means compliance teams must update IRC controls and test whether their AI incident classification and notification procedures can operate within the compressed timelines that agentic attacks now require.

Governance controls affected

What to do now

  • Audit whether your SIEM and EDR platforms ingest agent-specific telemetry: prompt logs, tool invocation records, and API call chains, not just endpoint and network events.
  • Review all deployed agent identities against your non-human identity management policy and revoke any standing credentials that exceed the minimum scope needed for the agent's defined task.
  • Update your AI incident response playbook to include agent-specific detection signatures and automated containment triggers that can operate without waiting for human review.
  • Run a tabletop exercise simulating an agent-driven exfiltration scenario to test whether your current monitoring pipeline would generate an alert within an operationally meaningful timeframe.
  • Map each production AI agent to a behavioral baseline and configure anomaly detection rules that flag deviations in API call volume, data access patterns, or tool usage outside defined task boundaries.

What to watch next

Mandiant's warning is one signal in a converging pattern: regulatory bodies, standards organizations, and peer security firms are moving toward formal requirements for agent-specific behavioral monitoring. Watch for CISA to update its agentic AI guidance with prescriptive telemetry requirements, and monitor whether the Five Eyes agentic AI security guidance is revised to reference SIEM integration baselines. South Korea's draft agentic AI security rules and emerging enterprise certification standards such as AIUC-1 are also likely to codify telemetry and identity controls as mandatory, not advisory, creating compliance obligations for any organization that has treated agent monitoring as a best-effort capability.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.