Synopsis: An AI agent can reach the right destination through a route nobody anticipated. That flexibility is useful until it involves credentials, databases or infrastructure the agent should not touch. Harold Byun, CEO of BlueRock Security, argues that containing the risk requires more than watching prompts and responses. Security controls need to govern what an agent can actually execute, before an unexpected decision becomes a destructive action.
Byun joins Mike Vizard to examine why familiar security assumptions become less reliable when software chooses its own path through a task. A sandbox can limit an agent’s environment, but Byun warns against treating basic isolation as a complete defense. Legitimate tools can still be used in unexpected ways, and access controls may not account for every route an agent discovers. His emphasis is on constraining actions, rather than assuming the system will consistently make safe choices.
Credential harvesting, database deletion and destructive infrastructure commands give that argument concrete stakes. Byun describes using behavioral analysis to establish what normal activity looks like, then applying controls that intervene when execution moves outside expected boundaries. Monitoring remains useful, but detecting damage after the fact is different from preventing it. Teams also need to track changes to agent configurations, code, tools and skills, because the behavior they approved initially may not be the behavior running later.
Always-on operation makes those boundaries particularly important. An agent expected to work overnight cannot depend on a person approving every few minutes of activity. Byun argues that organizations need an AI operations stack with visibility into identity, access paths and runtime behavior, backed by policies that can stop dangerous actions without halting all useful work. The challenge is deciding which actions agents may perform independently and ensuring those limits still hold when nobody is watching.

