Security in the Age of Agentic AI
Vasu Jakkal (Corporate Vice President, Microsoft Security · Microsoft)
RSA Conference 2025 · Day 2 · West Stage · Keynote
Overview
Microsoft Security's Vasu Jakkal delivered a sweeping keynote at RSA 2025 that framed the rise of agentic AI as both the industry's most transformative opportunity and its most consequential security challenge. She argued that AI agents will soon permeate every layer of organizational and personal life — which means securing them, and using them to secure everything else, must be treated as two sides of the same imperative. The talk closed with a vision of what the security profession could become when AI absorbs the drudgery: a workforce finally freed for the creativity and governance it was always meant for. ---

Key moments
- 4:14 Password attacks doubled to 7,000 per second year-over-year
- 4:31 Microsoft tracks 1,500 threat actors, up fivefold from last year
- 5:55 20% of data breaches today involve insider threats
- 7:17 Microsoft security AI trained on 84 trillion daily signals
- 9:55 Fully autonomous AI security agents expected within two years
- 11:44 AI agents require identities, least-privilege access, lifecycle governance
- 13:04 AI governance must shift to dynamic probabilistic enforcement
- 15:51 Agentic AI can reverse attacker-defender asymmetry at scale
Security in the Age of Agentic AI
Speaker: Vasu Jakkal (Corporate Vice President, Microsoft Security)
Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco
Watch: YouTube
Reading time: ~7 minutes
TL;DR
Microsoft Security's Vasu Jakkal delivered a sweeping keynote at RSA 2025 that framed the rise of agentic AI as both the industry's most transformative opportunity and its most consequential security challenge. She argued that AI agents will soon permeate every layer of organizational and personal life — which means securing them, and using them to secure everything else, must be treated as two sides of the same imperative. The talk closed with a vision of what the security profession could become when AI absorbs the drudgery: a workforce finally freed for the creativity and governance it was always meant for.
Introduction
There is a long tradition of RSA keynotes that use the word "transformative" and mean it loosely. Vasu Jakkal's address to the Moscone Center on the final day of RSA Conference 2025 was not one of them. As Corporate Vice President of Microsoft Security, Jakkal oversees a portfolio spanning identity, compliance, endpoint, cloud security, and one of the largest threat intelligence operations on the planet. When she said agentic AI is "one of the most exciting inventions of our time," she was speaking with both the strategic authority of someone who leads a multibillion-dollar security business and the urgency of someone who has watched the threat landscape worsen in real time.
The data she opened with was a blunt corrective to any complacency in the room. Password attacks had risen from four thousand per second when Jakkal last addressed RSA to seven thousand per second — six hundred million attacks a day. The average time from a phishing click to full data exfiltration had compressed to seventy-two minutes. And the number of threat actors being tracked by Microsoft had ballooned from three hundred to fifteen hundred in a single year. "This is what we're facing," she said. "And the more prevalent and the more ubiquitous and capable agents become, it is going to be critical for us to defend at the scale and speed of AI and AI agents."
The Agentic Era: A New Kind of Digital Colleague
Jakkal opened with a panoramic vision of what the agentic AI era will look like in practice. Within a few years, she predicted, AI agents will be as ubiquitous as mobile apps — ambient, interactive companions woven into both professional and personal life. A research agent that surfaces deep subject-matter expertise. An analyst agent that converts raw data into actionable intelligence. A chief-of-staff agent coordinating calendars and household logistics simultaneously.
▶ Watch: Vision of agentic AI — digital colleagues and companions (0:00)
The implications for enterprise security are immediate and layered. These agents will act with a degree of autonomy — executing tasks, coordinating with other agents, making decisions — that raises fundamental questions about identity, access, governance, and accountability. "I know that no one better than this room understands that AI must first start with security," Jakkal said.
She outlined the security considerations that agentic AI introduces: What permissions do agents have? What data can they access? How are organizations preventing oversharing? How do agents interact with one another, and which interactions should be permitted? What does onboarding and decommissioning look like for a software entity that carries persistent identity and memory? These are not future-tense questions; they are design decisions being made right now by the teams building these systems.
Using AI to Secure: From Generative to Agentic
Two years ago, Microsoft launched its first generative AI applications for security, trained on the eighty-four trillion daily signals the company processes across its global network. Those early applications focused on threat investigation, incident reporting, and reverse-engineering assistance. By 2025, the scope had expanded significantly.
▶ Watch: Microsoft's AI journey — 84 trillion signals and early wins (6:00)
Jakkal described current AI agents performing vulnerability management — patching systems quickly, triaging billions of phishing alerts, and applying conditional access policies. But she was explicit that this is still the beginning. The near-term horizon she sketched is more ambitious: AI systems that predict attacks before they occur, shifting security's posture from reactive to anticipatory; agents that flag data risk at the moment content is created rather than after a breach; and automated access management that dynamically adjusts permissions as context changes.
The most structurally significant claim in the keynote was about timeline. Jakkal predicted that AI autonomy in security will move from "level zero" — mimicking and assisting human tasks — to "level three" within the next two years. At level three, AI systems create their own subgoals, adapt their methods to achieve objectives, and take action autonomously, with human oversight built in but not required for every step.
▶ Watch: Autonomy levels — from task assistance to level 3 (10:00)
"Tomorrow it's going to be more autonomous," she said, "where it's going to be able to create its own subgoals, maybe change the models itself to achieve its goals and take these actions serendipitously and autonomously."
Securing AI: Identity, Data, Governance, and the Threat Landscape
The second major axis of the keynote addressed what Jakkal called the "deeply interconnected" challenge of securing AI itself. Her framework was organized around four pillars.
Identity is the first and perhaps most foundational. AI agents will need identities — persistent, verifiable, subject to zero-trust principles. Organizations must be able to verify agents explicitly, manage least-privilege access, and track the full lifecycle of every agent from onboarding through decommissioning.
▶ Watch: Securing AI — identity, data, and governance (12:00)
Data is elevated because AI is, ultimately, a function of the data it operates on. Whether organizations have the right permissions, policies, and oversharing prevention in place is not an abstract compliance question; it is an operational security question with direct consequences for what AI agents can be trusted to do.
Threat monitoring for AI-specific attacks is a genuinely new discipline. Prompt injection, large-language-model poisoning, model abuse, and wallet abuse represent a class of threats that did not exist in meaningful form two years ago and are now active vectors in the wild.
Governance is perhaps where Jakkal's vision was most forward-leaning. Static, lab-based verification of AI systems is already inadequate. Because AI is adaptive and continuously learning, governance must shift to what she described as "dynamic probabilistic verification" — continuously auditing agents across their lifecycle, enforcing policies that evolve as work evolves, and embedding security as a sub-agent within every AI agent so that enterprise policies are enforced at the source.
"As AI dynamically changes, security needs to dynamically change with that AI," she said.
The Human Role: From Task-Doer to Governor and Innovator
Jakkal reserved the keynote's most affecting argument for last: what happens to the humans when AI absorbs the routine work?
▶ Watch: Redefining human roles in the agentic workforce (14:00)
Her answer was not a cautionary tale about displacement but an aspirational vision of a profession finally able to do what it set out to do. Security practitioners joined the workforce to investigate, to innovate, to protect — not to triage alerts for twelve hours a day. Agentic AI, she argued, creates the conditions for that original aspiration to be realized.
The role she described is not passive. Humans become the directors and governors of AI agents: defining what agents should do, evaluating whether they are doing it correctly, and ensuring that the AI workforce embodies the same principles of fairness, transparency, accountability, and inclusion that responsible organizations aspire to. Governance, she emphasized, is not a checkbox. It is "an irreplaceable role."
▶ Watch: Cognitive diversity and the future security workforce (16:00)
Jakkal also made a pointed argument about cognitive diversity. The attackers targeting organizations come from every background and every culture. The defenders must match that breadth. "The AI that we build in security and the AI that we use in security needs to have this diversity at the heart of it," she said. Building and learning AI is, in her framing, no longer optional for security professionals: "For us to thrive in this new world, it's a must-have."
She closed with a call to embrace rather than resist the discomfort of acquiring new skills — and with a reminder that security has always been a collective endeavor. "You've heard me say often that security is a team sport. It is. It takes a village."
Notable Quotes
"Last year we were tracking three hundred threat actors at Microsoft. This year it's fifteen hundred. This is what we're facing."
— Vasu Jakkal
"We need to defend at the scale and speed of AI and AI agents."
— Vasu Jakkal
"Governance is an irreplaceable role that we need to focus on because it is critical as defenders that we make sure these AI agents do what they are intended to do and to help and serve humanity the way they're intended to."
— Vasu Jakkal
"Developing AI, learning AI is not going to be a nice-to-have. For us to thrive in this new world, it's a must-have."
— Vasu Jakkal
Key Takeaways
- The threat landscape is accelerating regardless of AI. Seven thousand password attacks per second, fifteen hundred tracked threat actors, and a 72-minute breach clock are the baseline conditions against which AI's defensive value must be measured.
- AI agents will require an entirely new security framework. Identity, access management, data governance, and compliance must all be redesigned to accommodate entities that act autonomously, persist over time, and collaborate with other agents.
- The autonomy trajectory is faster than most organizations expect. Microsoft's prediction of level-three AI autonomy within two years is not a marketing projection — it is a design constraint that security architects need to account for now.
- Securing AI requires dynamic, not static, governance. As AI systems learn and adapt, the verification mechanisms must adapt with them. Lab-based, point-in-time compliance audits are already outdated as a primary governance mechanism.
- AI-specific attack vectors are real and active. Prompt injection, model poisoning, and model abuse require purpose-built monitoring — they cannot be addressed with conventional endpoint or network security tools.
- The highest-value human role in an agentic world is governance and creativity. Security professionals who embrace AI as a force multiplier will own the decisions that matter most: what agents do, whether they're doing it correctly, and how to innovate at the frontier.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Jakkal's keynote is competently delivered, technically substantive on agent identity and dynamic governance, and significantly better than most Microsoft RSA appearances. The 'level zero to level three autonomy in two years' prediction and the dynamic probabilistic verification framing are the ideas worth tracking; the rest is polished platform narrative from the world's largest security vendor.
Heather Calloway (CISO) — SOLID
Microsoft's Vasu Jakkal: 1,500 tracked threat actors (up from 300 in one year), 72-minute average phishing-to-exfiltration window, and a four-pillar governance framework for securing AI agents — identity, data protection, threat monitoring, and dynamic probabilistic verification.