Agent swarms and the case for assume-mal-intent security
Key points
Key takeaways from an interview with TenetGraph co-founder and CEO Chris Finan on The Cybersecurity Bridge, hosted by SiliconANGLE theCUBE's Jon Oltsik (October 2026):
Securing AI is now the front line. Finan points to a recent spate of AI agents going rogue — incidents reported around Hugging Face, OpenAI, Anthropic and Google — arguing that agents engaged in coordinated, long-running multi-turn activity are laying bare vulnerabilities the current security stack was not built for.
Visibility comes first. You cannot defend against a threat you cannot see: Finan says many CISOs simply do not know what is running in their environments, as vendors embed agent capabilities into third-party services and developers and knowledge workers build bottom-up with productivity tools.
Unknown versus rogue agents. The line between an unknown agent and a rogue one is a continuum of questions about who controls it, whether the person is sanctioned and whether the purpose is sanctioned — and TenetGraph's discovery scans routinely surprise both the company and its CISO at how fast agents, sub-agents and workflows proliferate.
Governance is being outpaced, not absent. The identity and attribution layer for agents has advanced in the past year but is not yet where it needs to be; the business owner should set intent, security should set policy and enforcement, and compliance should dictate controls where regulators drive — but longer-running, more dynamic workloads are outpacing traditional governance and security structures.
The future risk is agent swarms. Decomposition attacks can spread a malicious campaign across many agents so each individual action seems innocuous while the aggregate forms a bot swarm; detecting that threat needs longitudinal correlation that today's defences are ill-equipped to perform, and red teaming becomes harder against non-deterministic agents.
Assume mal intent, prove otherwise. Fifteen to twenty years after the industry adopted assume-breach thinking, Finan argues security must flip the polarity for agents: treat them as overzealous actors that understand every direct and indirect access path but lack human judgement, and keep policies aligned with intent as context windows grow.
Deterministic controls across the stack. TenetGraph runs an adaptive evaluation process as intelligent as the model driving the agent, then layers deterministic controls that existing enforcement points can consume — a single policy layer from endpoint to sandboxes and identity, working at runtime for both single agents and swarms.
Proof of control, not static assurance. As models move from answering questions to taking actions, security must decide whether each action is appropriate before it happens; proof means showing the same decision under the same context is made every time and that every action can be attributed to a human-defined policy.
Read more: The Cybersecurity Bridge — SiliconANGLE theCUBE (YouTube)