Your Next Cybersecurity Incident Might Not Have a Human Behind It

For years, businesses have been warned about phishing emails, ransomware, stolen passwords and malicious insiders.

Now there is another problem that business leaders need to understand.

What happens when the attacker is not simply using artificial intelligence as a tool, but is using an AI system capable of planning, making decisions and taking actions?

That is the emerging challenge of agentic AI.

And in August 2026, it is becoming increasingly difficult for businesses to treat this as a distant technology issue.

The UK’s National Cyber Security Centre has warned that recent incidents involving advanced AI models carrying out unsanctioned actions and displaying deceptive behaviour are a serious reminder of the risks associated with increasingly capable AI systems. The NCSC says organisations need strong safeguards, real time oversight and clear plans for responding when AI behaves unexpectedly. (National Cyber Security Centre)

For Manchester businesses and organisations across the UK, this raises an important question:

Are your existing cyber security controls designed for software that can make decisions and take actions on its own?

What is agentic AI?

Traditional generative AI generally responds to a request.

You ask a question and it produces an answer.

You ask it to summarise a document and it summarises the document.

Agentic AI is different.

An AI agent can potentially access information, use software tools, interact with systems, make decisions and carry out tasks on behalf of a user.

The NCSC describes agentic AI as systems that can plan, make decisions and take actions rather than simply generating content or predictions. (National Cyber Security Centre)

That can be extremely useful.

An AI agent could potentially monitor systems, analyse security alerts, update records, assist with customer service, manage workflows or identify operational problems.

But every additional capability introduces another potential route into your organisation.

The problem is not AI itself

There is a temptation to divide the conversation into two camps.

AI is either presented as the future of business or as an existential cyber security threat.

The reality is considerably more practical.

AI can be enormously valuable to organisations.

The problem arises when businesses give an AI system access to information, applications or infrastructure without properly understanding what that access means.

Consider an employee using an AI agent that can:

• Read company documents

• Access Microsoft 365

• Search internal databases

• Send emails

• Create support tickets

• Modify records

• Interact with external websites

• Execute software commands

Individually, each capability might appear reasonable.

Together, they create a completely different security proposition.

Your biggest risk may be excessive access

One of the most important questions businesses should ask about AI is the same question they should already be asking about employees and traditional software:

What can it access?

An AI system does not necessarily need access to everything simply because it is capable of using everything.

If an AI agent only needs access to a particular system to complete a task, giving it access to five additional systems creates unnecessary risk.

This is where traditional cyber security principles become extremely important.

Businesses should consider:

Least privilege

Give AI systems only the access they genuinely require.

Identity and access management

Every AI agent should have clearly defined permissions and ownership.

Authentication

Access to important systems should not simply be granted because an AI tool has been authorised somewhere else.

Monitoring

Businesses need to understand what automated systems are doing.

Logging

Actions should be recorded so unusual behaviour can be investigated.

Segmentation

Critical systems should not automatically be accessible from every AI enabled application.

These are not futuristic security concepts.

They are established cyber security principles that become even more important as AI becomes more autonomous.

What happens when an AI agent makes the wrong decision?

This is where the issue becomes particularly interesting for business leaders.

Imagine an AI agent responsible for identifying suspicious activity.

It detects something unusual.

It decides that a particular account is compromised.

It automatically disables the account.

It then identifies another system connected to the account and decides that it should also be isolated.

The first decision might have been correct.

The second might not.

The third could potentially disrupt an important business process.

Who authorised the action?

Who reviews it?

Who can stop it?

And how quickly can the business recover?

These questions need answering before an organisation gives an AI system significant operational authority.

AI needs its own form of governance

Many organisations have already introduced AI policies covering issues such as confidential information, personal data and acceptable use.

That remains important.

But businesses adopting agentic AI may need to go further.

A sensible AI governance framework should consider:

1. What AI systems are being used?

Create an inventory.

Businesses cannot manage AI risk effectively if they do not know which AI tools and agents are operating within the organisation.

2. What can each system access?

Document permissions and connected services.

An AI assistant with access to a public knowledge base presents a very different risk from one connected to financial systems or customer databases.

3. What decisions can it make?

Not every AI system should have authority to make consequential decisions.

Define which actions require human approval.

4. What happens when something goes wrong?

AI incidents need to form part of the organisation’s incident response planning.

Do not assume that an AI failure is simply an IT problem.

It could involve:

Data protection

Cyber security

Operational disruption

Financial loss

Regulatory obligations

Contractual obligations

Reputational damage

5. Can you switch it off?

This sounds obvious.

It isn’t.

Businesses should understand how an AI system can be disabled, disconnected or restricted if it begins behaving unexpectedly.

The supply chain problem

There is another issue that businesses should not overlook.

Your organisation may not have developed the AI system itself.

You may be using an AI service supplied by a third party.

That means your risk assessment needs to consider the wider technology supply chain.

Where is the AI processing information?

Which models does the provider use?

What external services can the AI interact with?

What happens when the provider changes the model?

What happens if the provider suffers a security incident?

What happens if a connected application is compromised?

The NCSC has specifically highlighted the importance of understanding dependencies and managing supply chain risk when organisations adopt agentic AI. (National Cyber Security Centre)

Should businesses stop using AI?

No.

That would be the wrong conclusion.

The NCSC itself recognises that agentic AI can provide significant benefits, particularly for repetitive and well understood tasks.

Its advice is essentially to start carefully, use AI for lower risk activities initially, apply established cyber security controls and plan for failure. (National Cyber Security Centre)

The question is therefore not:

“Should we use AI?”

It is:

“How much authority should we give AI, and what controls should surround that authority?”

That is a much more useful question for a board.

What should Manchester businesses do now?

Businesses do not need to build an enormous AI governance department tomorrow.

There are some straightforward steps that can be taken now.

Audit your AI usage

Find out what AI tools employees and departments are actually using.

Do not rely solely on approved software lists.

Identify AI connected to business systems

Pay particular attention to AI tools with access to:

Microsoft 365

CRM systems

ERP platforms

Customer databases

Financial systems

Source code

Cloud infrastructure

Internal documents

Review permissions

Ask whether every AI system has the minimum access required.

Introduce human approval

For high impact actions, consider requiring human approval rather than allowing an AI system to act independently.

Update incident response

Your incident response plan should consider what happens if an AI system:

Makes an incorrect decision

Accesses information it should not

Sends information externally

Is manipulated through prompt injection

Connects to a compromised service

Acts outside its intended purpose

Train employees

Employees need to understand that an AI agent with access to company systems is fundamentally different from asking a chatbot to write an email.

The board level question

Perhaps the most important question for directors is not whether the organisation is using AI.

It is whether the organisation understands where AI has authority.

A company might have excellent firewalls, endpoint protection, MFA and backup systems.

But if an AI system has been given extensive access to internal applications without appropriate governance, a new category of risk may have been introduced.

Cyber security is increasingly becoming a question of controlling not only who can access your systems, but what automated systems are allowed to do once they have access.

AI could also become part of the defence

There is an important positive side to this story.

AI is not only becoming part of the threat.

It could also become an important part of the defence.

The NCSC is developing its Cyber Shield initiative with the Department for Science, Innovation and Technology, exploring how agentic AI could be used at national scale to identify, reduce and respond to cyber risk. (National Cyber Security Centre)

The same capabilities that could help attackers identify vulnerabilities faster could potentially help defenders find and fix those vulnerabilities before they are exploited.

That creates a race between offensive and defensive capabilities.

For businesses, the immediate priority should be making sure the fundamentals are strong enough to withstand that race.

The future of cyber security is becoming more autonomous

The next generation of cyber security will not simply involve humans monitoring screens while automated systems generate alerts.

AI will increasingly be involved in detecting threats, analysing vulnerabilities and potentially responding to incidents.

That creates enormous opportunities.

It also creates a new responsibility for business leaders.

You need to know what your AI systems can do before you allow them to do it.

For organisations in Manchester and across the UK, now is a good time to review AI governance, system access, cyber security controls and incident response arrangements before autonomous AI becomes deeply embedded in everyday business operations.

How North Signal can help

North Signal provides strategic IT, cybersecurity and technology leadership services for businesses that need senior expertise without necessarily requiring a permanent executive technology appointment.

This can include reviewing technology risk, developing IT strategy, assessing cybersecurity maturity, improving governance and helping organisations introduce emerging technologies responsibly.

For businesses considering greater use of AI, a structured technology and security assessment can help identify where AI creates opportunity and where additional controls may be required.

North Signal provides Fractional CIO, Fractional CTO and Fractional CISO services in Manchester, alongside cybersecurity, IT strategy, compliance and digital transformation consultancy.

Final thoughts

AI is moving from something that answers questions to something that can potentially take action.

That changes the security conversation.

The organisations that benefit most from AI are unlikely to be those that simply adopt it fastest.

They will be the organisations that understand what the technology can do, where it has access, what decisions it can make and what happens when something goes wrong.

The era of autonomous AI is arriving.

The question for your business is whether your cyber security strategy is ready for it.

North Signal provides independent technology, cybersecurity and IT leadership advice for businesses in Manchester, Greater Manchester and across the UK.