Skip navigation EPAM
Dark Mode
Light Mode

Security Can’t Be an Afterthought as AI Agents Reshape DevOps

In the News

SD Times – Adam Auerbach, Head of Applied AI, NA, EPAM

Security Can’t Be an Afterthought as AI Agents Reshape DevOps

The engineering teams winning with AI agents right now share one trait: they stopped treating security as a gate at the end of the pipeline and started treating it as a design constraint from the beginning. That shift sounds simple, but it runs counter to how most organizations have approached AI adoption. Move fast, secure later. With AI agents, that sequence carries consequences it didn’t before.

The case for AI agents’ productivity is well documented. What gets less attention is what happens to your security posture when you hand that much autonomy to a system operating at machine speed, one that doesn’t just execute instructions but interprets context, makes judgment calls and acts across multiple systems simultaneously.

The default framing is that AI agents are a new tool that needs to be secured like any other tool. That framing misses something important. Traditional tools execute instructions; AI agents interpret context and make judgment calls. That distinction matters immensely when things go wrong.

When a conventional automation script is compromised, the blast radius is generally bounded by what the script was designed to do. When an AI agent is manipulated, through prompt injection, adversarial inputs or misconfigured permissions – traditional LLM applications – the blast radius is bounded by whatever the agent has access to, which in a mature DevOps environment can be substantial. Agents integrating with code repositories, deployment pipelines, project management platforms and external APIs inherit vulnerabilities from every surface they touch: SQL injection, remote code execution, broken access control and sensitive data leakage among them. Securing an AI agent is not a single policy decision, it’s a systems problem.

Read the full article here

Learn more about EPAM’s AI-Native Cyber Resilience Program and how to develop a cyber strategy for your organization today. 

FEATURED STORIES