Artificial intelligence is shifting from assisting cybersecurity to taking on autonomous roles through agentic security. These AI agents identify and investigate threats without waiting for human input. Jaydeep Ruparelia, founder and CEO of Infopercept, said, “Cybersecurity is moving from SaaS, Software as a Service, to SAS: Service as Software.”

Synopsis

Artificial intelligence is evolving from assisting cybersecurity to taking on more responsibilities autonomously and efficiently. This shift, termed agentic security, enables AI to identify and investigate threats without waiting for human input. AI agents like Infopercept's Regiment AI can streamline workflows by connecting existing security technologies rather than requiring complete system replacements. While analysts may take on more complex tasks, managing AI will become a critical responsibility.

For years, artificial intelligence in cybersecurity has largely worked as an assistant. It could scan large volumes of data, flag suspicious activity, summarise alerts and help security teams decide what to do next. That model is now beginning to change. The next phase is agentic security, where AI agents are designed not just to identify a cyber threat but also to investigate it, validate what is happening, recommend or initiate a response and, in some cases, help drive remediation. The important difference is that these systems can work through a sequence of tasks rather than waiting for a human to give instructions at every step.

But giving AI more freedom inside a security environment also creates a difficult question: how much autonomy is safe? Cybersecurity companies are increasingly trying to answer that by putting policies, permissions, approvals and audit trails around AI agents. Infopercept's recently introduced Regiment AI is one example of this approach.

From AI copilot to AI agent

A conventional AI security tool may tell an analyst that a server appears vulnerable or that an unusual login needs investigation. An agentic system can potentially go further. It can gather information from different security tools, connect an alert with an asset or identity, investigate related activity, assess the potential attack path and prepare the next action. The system can then operate within rules defined by the organisation.

This is what makes agentic security different from simply adding a chatbot to a security platform. Jaydeep Ruparelia, founder and CEO of Infopercept, describes the broader shift as a move from software that provides a service to software that can perform a service. “Cybersecurity is moving from SaaS, Software as a Service, to SAS: Service as Software,” Ruparelia said.

Live Events

According to him, the idea is to bring AI agents and human security specialists into the same operating model, allowing tasks such as penetration testing, investigation, compliance evidence collection and remediation prioritisation to happen faster.

How does agentic security actually work?

The simplest way to understand it is to think of a security operation as a chain of decisions. First, something needs to be discovered. Then it has to be investigated. The organisation needs to establish whether the finding is genuine and understand its impact. Finally, someone has to decide what action should be taken.

“An agentic security architecture can divide these jobs between specialised agents. One agent might look for vulnerabilities. Another could investigate suspicious behaviour. A third could connect a finding with compliance requirements. A remediation agent could then help determine what needs to be fixed first. The agents do not necessarily operate with unrestricted access. Their actions can be limited by policies, permissions and approval requirements. That control layer is crucial,” Jaydeep Ruparelia said.

Why human control still matters

The phrase “AI fighting cyber threats on its own” can sound more dramatic than what organisations are actually willing to deploy. In a corporate environment, an AI system making an incorrect decision can cause serious problems. Blocking a legitimate user, shutting down a critical server or changing a security rule without proper approval could disrupt business operations.

That is why controlled autonomy is becoming an important part of the agentic security discussion. Regiment AI, according to Infopercept, is built around policies, permissions, approval mechanisms and auditability. This means an organisation can determine what an AI agent is allowed to do and where a human decision is required.

Ruparelia said the objective is not simply to add another AI assistant to a security team's toolkit. “The goal is to move beyond AI as a copilot and make it part of the security operating architecture, while keeping policies and accountability at the core,” he said. In other words, the AI can be given responsibility for carrying out defined tasks, but the organisation retains control over the boundaries.

AI agents can connect the dots faster

One of the biggest potential advantages of agentic security is speed. Modern enterprises generate enormous amounts of security data. Logs, endpoint alerts, identity events, vulnerability reports, threat intelligence feeds and compliance records can all sit in different systems. A security analyst may need to move between several tools before understanding what a single alert actually means. An agentic architecture can potentially bring these pieces together.

Infopercept founder says Regiment AI is designed to connect with existing security technologies, including SIEM, EDR, SOAR, IAM, CMDB, threat intelligence and ticketing systems. That means the organisation does not necessarily have to replace its existing security infrastructure to introduce AI agents. Instead, the agents can work across the existing environment and use information from those systems to make their decisions more relevant.

What happens when an attack is detected?

Consider a simplified example. A security system detects suspicious activity involving an employee account. Instead of simply sending an alert to an analyst, an agent could first gather information about the account, examine recent activity and check whether the identity has interacted with unusual devices or systems.

It could then look for related indicators elsewhere in the organisation. If the investigation points to a genuine threat, another agent could assess the affected assets and possible attack paths. A remediation workflow could then prioritise the response. Some actions may be automated. Others could require approval. The important point is that the AI is not just answering a question. It is moving through a sequence of connected security tasks.

Does this mean cybersecurity jobs will disappear?

Not necessarily. The more immediate change is likely to be in the nature of security work. Analysts spend considerable time on repetitive activities such as sorting alerts, gathering information, preparing reports and collecting evidence. AI agents could take over parts of these workflows, allowing human specialists to concentrate on complex investigations, risk decisions and incidents where judgement is critical.

There is also a new responsibility: managing the AI itself. Security teams will need to define what agents can access, what actions they can take, when approval is mandatory and how their decisions are reviewed. That could make AI governance a core part of cybersecurity operations.

The bigger shift in cybersecurity

Agentic security is ultimately about changing how security systems operate. Traditional tools often wait for a person to interpret an alert and decide what comes next. Agentic systems aim to connect multiple steps into a continuous workflow. That does not mean handing complete control to machines.

The more practical model is controlled autonomy, where AI can operate at machine speed while organisations retain policies, permissions and accountability. The technology is still evolving, and the risks are significant. But as cyberattacks become faster and security environments become more complicated, organisations are likely to look beyond AI that merely tells analysts what happened.

(You can now subscribe to our Economic Times WhatsApp channel)

(Catch all the Business News, Breaking News and Latest News Updates on The Economic Times.)

Subscribe to The Economic Times Prime and read the ET ePaper online.

...moreless

(You can now subscribe to our Economic Times WhatsApp channel)

(Catch all the Business News, Breaking News and Latest News Updates on The Economic Times.)

Subscribe to The Economic Times Prime and read the ET ePaper online.

...moreless