AGENTIC AI SECURITY / BEGINNER

What Makes An AI Agent Different From A Chatbot, And Why Security Teams Care

A chatbot writes text for a person to read. An agent turns model output into actions with real permissions. That shift changes who can attack it and what they can achieve.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

When a chatbot gets something wrong, a person usually reads the mistake and decides what to do with it. An AI agent is built to skip that step. It reads a goal, plans a series of steps, calls tools such as email, file storage or a payment system, and acts with whatever access it has been given.

That single difference reshapes the security problem. A harmful answer is still possible, but the bigger worry becomes a harmful action taken with someone else’s authority. This article explains what an agent is made of, where the new openings for attackers sit, and what early government and industry guidance asks organisations to do. If you want a fuller explanation of how agents plan and use tools, start with the AI Agents And Multi-Agent Systems group.

From Answers To Actions

In May 2026, six cyber security agencies from Australia, the United States, Canada, New Zealand and the United Kingdom published joint guidance called “Careful Adoption of Agentic AI Services”.1 It describes an agentic system as one or more agents that rely on a model, usually a large language model, to interpret the world, decide and act. Around the model sit external tools, external data sources, memory and planning workflows.

The guidance draws the line against ordinary generative AI clearly. Generative AI produces text, images or audio for a person to use. Agentic AI connects that capability to software systems so it can reason, plan and take actions without a human stepping in at each stage.

FeatureChat assistantAI agent
OutputText for a person to readTool calls that change systems or send data
Who actsThe human, after readingThe agent, often without a pause
AccessUsually none beyond the conversationCredentials for email, files, APIs and other agents
InputsMostly what the user typesWeb pages, documents, emails, tool results and memory
MemoryUsually limited to the sessionCan persist across tasks and be reused later
Worst likely failureA misleading answer, or a leak of something it was shownA data leak, payment, deletion or code execution
What changes when a language model becomes an agent.

Why The Attack Surface Grows

Agents inherit every weakness of the model underneath them. The joint guidance gives a plain example: an attacker hides instructions in a phishing email, and an agent that monitors the inbox reads them and downloads malware.1 The agent did what its text told it to do. The problem is that some of that text came from the attacker.

Each extra component adds another way in. A web search tool pulls third-party text into the model’s context. A memory store can be seeded with false information that resurfaces weeks later. A connector to another agent brings in messages the first agent may trust without checking. The guidance puts it simply: every component widens the attack surface.

  1. A Goal Arrives

    A user, a schedule or another system asks the agent to do something.

  2. The Agent Gathers Context

    It reads emails, documents, web pages, memory and tool results. Some of this text may have been written by an attacker.

  3. The Model Plans

    The model cannot reliably tell instructions apart from data, so planted text can change the plan.

  4. The Agent Calls Tools

    It uses its own credentials to read, write, send, pay or run code.

  5. Effects Reach The Outside World

    Data leaves the organisation, records change, or another agent receives the result and acts on it.

How untrusted content can travel through an agent. Each arrow is a place where a control can sit.

OWASP, the open security community best known for its web application Top 10, reached the same view. Its Top 10 for Agentic Applications, published in December 2025 with input from more than 100 experts, describes agents as systems that plan, act and make decisions across complex workflows.2 Its first entry, Agent Goal Hijack, rests on a simple observation: agents cannot reliably separate legitimate instructions from content an attacker controls.3

The Shift In Who Holds Authority

A second change is about identity. When a person approves a payment, the audit log shows a person. When an agent does it, the log shows a service account, a token or a delegated user session. If many agents share one key, or one agent holds far more access than its task needs, a single compromise inherits all of it.

The joint guidance describes this as the “confused deputy” pattern. A low-privileged user, or a tampered tool, persuades a high-privileged agent to do something the user could not do directly. Because the action runs under a trusted identity, the logs look normal and detection is delayed.1

What Early Guidance Asks For

The guidance from governments, OWASP and the large AI developers points in one direction. Google’s paper on secure agents sets out three principles: an agent should have a clearly defined human controller, its powers should be carefully limited, and its actions and planning should be observable.4 Google pairs fixed, rule-based controls with defences that rely on model reasoning, aiming to get the strengths of both.

OWASP adds the idea of “least agency”: do not give a system autonomy it does not need, because unnecessary autonomy enlarges the attack surface without adding value.3 The joint government guidance asks organisations to fold agentic AI into their existing security model rather than treat it as a separate discipline, to start with low-risk and non-sensitive tasks, and never to give agents broad or unrestricted access to sensitive data or critical systems.1

None of these documents is a law. They are guidance. As of October 2026 they give security teams a shared starting point for a first assessment of an agent. The AI Governance And Regulation group covers the frameworks and laws that sit above them.

Questions To Ask Before Deploying An Agent

A short set of questions catches most early mistakes:

  • What can this agent read, and could any of that content come from outside the organisation?
  • What can it change or send, and could those actions be undone?
  • Whose identity does it act under, and is that identity shared with anything else?
  • Which actions need a human to approve them, and who decided that?
  • Could we reconstruct, from logs, why it did what it did?

The later articles in this group take each question further, beginning with a simple test for spotting the riskiest combinations of access.

Footnotes

  1. ASD’s ACSC, CISA, NSA, Canadian Centre for Cyber Security, NCSC-NZ and NCSC-UK, “Careful Adoption of Agentic AI Services”, 1 May 2026. ncsc.govt.nz ↩ ↩2 ↩3 ↩4

  2. OWASP GenAI Security Project, “OWASP Top 10 for Agentic Applications for 2026”, 9 December 2025. genai.owasp.org ↩

  3. OWASP GenAI Security Project, “OWASP Top 10 for Agentic Applications 2026” (full document), December 2025. genai.owasp.org ↩ ↩2

  4. S. Díaz, C. Kern and K. Olive, Google, “Google’s Approach for Secure AI Agents: An Introduction”, May 2025. research.google ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.