Ambient and Autonomous Security: Building Trust in the Agentic AI Era

Vasu Jakkal (Corporate Vice President, Microsoft Security · Microsoft), Dr. Mohamed Al Kuwaiti (Head of Cybersecurity · UAE Government Cybersecurity Council)

RSAC 2026 Conference · Main Stage Keynote

Overview

In this pivotal talk at the RSA Conference, Vasu Jakkal, Corporate Vice President of Microsoft Security, articulated a visionary future for cybersecurity in the rapidly evolving era of agentic AI. The presentation, titled "Ambient and Autonomous Security: Building Trust in the Agentic AI Era," explored how the proliferation of AI agents fundamentally alters the threat landscape and demands a radical transformation in defensive strategies. Jakkal underscored that traditional, siloed security approaches are no longer adequate against AI-powered, graph-based attacks that operate at machine speed.

Watch on YouTube

Key moments

  1. 0:00 Introduction and historical context of technology evolution
  2. 2:00 AI's present impact: science fiction becomes reality
  3. 3:15 Threat actors leveraging GenAI and agentic AI for attacks
  4. 5:00 AI transforms security: attackers operate at machine speed
  5. 6:00 Microsoft's vision: ambient and autonomous security for AI
  6. 8:00 Securing the agent workforce: preventing 'double agents'
  7. 10:00 Critical role of observability in agentic AI security

Ambient and Autonomous Security: Building Trust in the Agentic AI Era

Speakers: Vasu Jakkal, Corporate Vice President Microsoft Security; Dr. Mohamed Al Kuwaiti, Head of Cybersecurity for the UAE Government Cybersecurity Council

Conference: RSA Conference

YouTube: https://www.youtube.com/watch?v=o4xrjdEPfoc

Overview

In this pivotal talk at the RSA Conference, Vasu Jakkal, Corporate Vice President of Microsoft Security, articulated a visionary future for cybersecurity in the rapidly evolving era of agentic AI. The presentation, titled "Ambient and Autonomous Security: Building Trust in the Agentic AI Era," explored how the proliferation of AI agents fundamentally alters the threat landscape and demands a radical transformation in defensive strategies. Jakkal underscored that traditional, siloed security approaches are no longer adequate against AI-powered, graph-based attacks that operate at machine speed.

The core premise of the talk is that security must become as ambient and autonomous as the AI it seeks to protect. This paradigm shift necessitates security being deeply woven into every layer of the AI stack—from silicon to applications—operating continuously, proactively, and at an unprecedented scale. The discussion moved beyond theoretical concepts, presenting concrete architectural and operational shifts required to secure a world where AI agents are integral to the workforce, culminating in a powerful demonstration of national-scale AI security initiatives from the UAE.

This presentation holds significant importance for the cybersecurity community, offering a strategic blueprint for navigating the complexities of AI-driven threats and opportunities. It challenges defenders to rethink their approaches, embrace AI as an ally, and build trust at the very core of their organizations to catalyze innovation. By advocating for a future where security is an embedded, self-defending system, the talk provides a critical framework for securing our digital future against an adversary that is increasingly leveraging advanced AI capabilities.

Background

▶ Watch: Introduction and historical context of technology evolution (0:00)

The evolution of technology, from the birth of the World Wide Web and Linux in 1991 to today's driverless cars and AI-powered surgical tools, has been relentless. This rapid advancement, however, has consistently been mirrored by the sophistication of malicious actors. Today, the cybersecurity landscape stands at a critical inflexion point with the early, yet significant, use of AI-powered attacks. Microsoft Threat Intelligence has observed that threat actors are primarily leveraging Generative AI (GenAI) to enhance their tradecraft, making their operations more efficient and scalable.

Examples of this malicious use include North Korean actors, such as Jasper Sleet and Coral Sleet, employing AI for identity fabrication, social engineering, and maintaining long-term persistence at remarkably low costs. Beyond GenAI for tradecraft improvement, the industry is witnessing the nascent stages of agentic AI experimentation by threat actors, where AI models support decision-making and autonomous task execution. A stark illustration comes from Anthropic, which reported that its Claude model was used in an attack workflow, autonomously performing 80 to 90 percent of operational tasks without direct human oversight. This indicates that while human intent remains crucial, AI amplifies an expert attacker's effectiveness exponentially.

This shift means that contemporary threats are not merely faster; they are structurally different. Traditional security models, characterized by layers of siloed point solutions, static policies, and human-reliant responses, are ill-equipped to counter adversaries who think in graphs and operate continuously at machine speed across complex digital environments. The problem exists because security has historically been reactive and compartmentalized, failing to keep pace with the holistic, adaptive nature of modern attacks. The challenge, therefore, is to transform security from a series of isolated controls into a comprehensive, embedded, and intelligent system that can operate at the scale and speed of AI itself.

Key Findings

▶ Watch: Threat actors leveraging GenAI and agentic AI for attacks (3:15)

The talk articulates several key findings that fundamentally redefine the future of cybersecurity in the agentic AI era:

  1. The Rise of Agentic AI as a Dual-Use Technology: AI, especially agentic AI, is no longer science fiction but a present reality, impacting both offensive and defensive security. While it empowers attackers to be exponentially more effective, it simultaneously offers defenders an unprecedented opportunity to tilt the scales in their favor.
  2. Structural Shift in Threats: Current threats are not just faster; they are "structurally different." Attackers leverage AI to operate across interconnected graphs at machine speed, rendering traditional, siloed, and human-reliant security solutions obsolete.
  3. The Imperative for Ambient and Autonomous Security: To counter this new threat landscape, security must evolve to be ambient and autonomous, mirroring the AI it protects. This means security must be deeply woven into every layer of the AI stack—from silicon to agents, apps, platforms, and infrastructure—operating always-on, everywhere, and shifting from reactive to proactive.
  4. Agents as Colleagues and Potential "Double Agents": By 2028, IDC projects 1.3 billion agents will be in the workforce, with 80% of Fortune 500 organizations already building and using them. These agents must be secured with the same vigilance as humans, as they risk becoming "double agents" if manipulated by threat actors, leading to fraud, data leakage, and external attacks like prompt injections.
  5. The Need for an Observability Control Plane for Agents: Protecting agents requires comprehensive observability. Organizations will need an observability control plane that provides shared security controls for agent identity, threat protection, security posture, and data security/governance across IT, developer, and security teams.
  6. Zero Trust Extends to AI: In this environment of rapid progress, Zero Trust principles—continuous verification, least privileged access, and assume breach—are critical and must be explicitly extended to AI agents, covering identity, data, and runtime behavior.
  7. Defenders Augmented by AI Agents: AI agents will become an indispensable augmentation for every defender, serving as a primary interface to an organization's security data, logic, and tools. They will help in incident triage, optimizing policies, surfacing threat intelligence, and maintaining compliant endpoints, operating 24/7 at machine speed.
  8. National-Scale AI Security Initiatives: The vision extends beyond enterprise security to national resilience, exemplified by the UAE's pursuit of National XDR and Crystal Ball 2.0 for agent-to-agent intelligence sharing across borders. This highlights the potential for AI agents to strengthen national defense and international collaboration.

Technical Deep Dive

▶ Watch: AI transforms security: attackers operate at machine speed (5:00)

The proposed architecture for ambient and autonomous security in the agentic AI era is comprehensive, demanding a re-evaluation of security at foundational and operational levels. It moves beyond traditional perimeter defenses to an embedded, intelligent, and continuously adapting security posture.

Securing the Foundations

The journey begins by ensuring that the underlying digital infrastructure is "secure by design and by default." This foundational security must be continuously embedded across:

  • Hardware: Ensuring trust at the silicon level.
  • Networks: Implementing robust segmentation and continuous monitoring.
  • Sensors: Securing data ingress points and IoT devices.
  • Infrastructure: Hardening cloud, on-premises, and hybrid environments.
  • Cloud Facilities: Applying cloud native security best practices.

At this foundational level, ambient and autonomous security means the system is always sensing, reasoning, and adapting, rather than merely waiting for alerts. It's about building resilience from the ground up, enabling proactive defense.

Securing AI Agents: The Observability Control Plane

As AI agents become "colleagues," they introduce new attack surfaces and require dedicated security controls. The central tenet here is observability: "we cannot protect what we cannot see." This necessitates an observability control plane that offers shared security capabilities across IT, developer, and security teams for agent identity, threat protection, security posture, and data security/governance.

Agent Identity

AI agents must be treated as active participants requiring dynamic identity management. This involves:

  • Dynamic Identity: Based on behavior and context, similar to human identities.
  • Least Privileged Access (LPA): Agents should only have access to what is strictly needed, with access revoked when not in use.
  • Policy-Bound Controls: Enforcing granular access policies across applications, clouds, networks, and other resources to prevent unsafe actions before execution.

Threat Protections

Agentic security demands adaptive and continuous threat protection:

  • Continuous Assessment: Agents must be continuously assessed for risky permissions or misconfigurations to reduce exposure proactively.
  • Real-time Behavioral Monitoring: Monitoring agent behavior in real-time, inspecting actions, and blocking suspicious activities as they occur.
  • Correlation of Signals: Continuously correlating security signals across the entire environment to uncover stealthy or novel techniques that might otherwise be missed. This is critical for detecting advanced threats like jailbreaks and prompt injections, which require continuous reasoning across diverse signals to detect malicious intent and act at machine speed.

Data Security

Given agents' interaction with sensitive information, robust data security is paramount:

  • Visibility into Data Interactions: The ability to see what data agents are processing, both input and output.
  • Data Loss Prevention (DLP): Applying DLP policies in real-time to prevent sensitive information from being exfiltrated.
  • Sensitivity Labeling: Automatically applying and enforcing sensitivity labels to data handled by agents.
  • Preventing Oversharing and Leakage: Proactively stopping data oversharing or leakage before it escalates into a breach.

Continuous Governance

Traditional periodic, human-driven governance is insufficient for autonomous agents. It must evolve into a continuous, built-in system of guardrails:

  • Built-in Guardrails: Continuously observing agent behavior and acting within defined boundaries.
  • Risk Prevention: Proactively preventing risks and constraining unsafe actions.
  • Alignment with Business Intentions and Regulations: Ensuring agents operate within business objectives and comply with relevant regulations, always with a human in the loop for oversight and validation.

AI Agents as Defenders' Augmentation

AI agents are not just a threat; they are a powerful tool for defenders. They can augment human security teams by:

  • Incident Triage: Rapidly analyzing and prioritizing security incidents.
  • Optimizing Identity and Conditional Access Policies: Continuously adapting access controls based on real-time context and risk.
  • Surfacing and Customizing Threat Intelligence: Providing relevant and timely threat intelligence tailored to an organization's specific context.
  • Maintaining Secure and Compliant Endpoints: Automating the monitoring and remediation of endpoint security posture.

These agents will act as a primary interface to an organization's security data, logic, and tools, requiring a comprehensive platform that enables them to access, learn, reason, and adapt at scale, 24/7, across complex databases and languages, in fractions of a second.

National-Scale AI Security: The UAE's Vision

The talk highlights the UAE's ambitious national strategy, demonstrating how agentic AI security can transcend enterprise boundaries.

  • National XDR (Extended Detection and Response): A unified capability delivering visibility and response across critical national sectors (government, financial, healthcare), powered by AI agents that correlate threats, share intelligence, and take real-time action at a country level.
  • Crystal Ball 2.0: An evolution of their international threat intelligence sharing initiative, designed to scale collaboration across countries, sectors, and communities. The key innovation is the shift from human-to-human to agent-to-agent intelligence sharing, enabling AI agents to exchange threat intelligence at machine speed across borders. This means a threat detected in one nation can trigger defensive actions everywhere instantly.

This vision shifts security from reactive to proactive and predictive, creating a continuously self-defending system operating at agentic speed, securing AI with AI.

Demo / Proof of Concept

▶ Watch: Securing the agent workforce: preventing 'double agents' (8:00)

While the talk did not feature a live, interactive demonstration of a specific tool or exploit, it provided compelling real-world and visionary examples that served as conceptual proofs of concept. Vasu Jakkal referenced observations from Microsoft Threat Intelligence regarding malicious actors like Jasper Sleet and Coral Sleet using GenAI for phishing lures and malware generation. She also cited Anthropic's report on Claude autonomously performing 80-90% of operational tasks in an attack workflow, illustrating the real-world impact of agentic AI in offensive operations.

The later segment, featuring Dr. Mohamed Al Kuwaiti, Head of Cybersecurity for the UAE Government Cybersecurity Council, described the UAE's national ambition to deploy one billion AI agents across various sectors. Their initiatives, such as National XDR and Crystal Ball 2.0, were presented as tangible examples of building a future where AI agents strengthen national resilience and facilitate agent-to-agent threat intelligence sharing at machine speed. These examples, though not live demonstrations, serve to validate the premise that agentic AI is already transforming both the threat and defense landscapes, demonstrating the practical application and strategic implications of the concepts discussed.

Defensive Implications

▶ Watch: Critical role of observability in agentic AI security (10:00)

The insights shared in this talk necessitate a fundamental re-evaluation of defensive strategies. Organizations and national entities must adopt a proactive, AI-centric approach to cybersecurity.

  1. Extend Zero Trust to AI Agents: Implement Zero Trust principles for all AI agents. This means continuous verification of agent identity, adherence to least privileged access at all times, and an "assume breach" mindset covering agent identity, data interactions, and runtime behavior. Agents must earn the right to operate in the environment through rigorous validation.
  2. Establish an Observability Control Plane: Develop and deploy a comprehensive observability control plane dedicated to AI agents. This platform should provide unified visibility and shared security controls across IT, developer, and security teams for agent identity, threat protection, security posture, and data security, ensuring that all agent activities are continuously monitored and logged.
  3. Implement Dynamic Agent Identity and Access Management: Treat AI agents as active participants with dynamic identities based on their behavior and context. Enforce granular, policy-bound controls to ensure agents only access necessary resources, and revoke access immediately when not required. This reduces the attack surface presented by potentially compromised agents.
  4. Adopt Continuous, Adaptive Threat Protection for Agents: Move beyond static rules to deploy threat protection systems that continuously assess agent configurations, monitor their behavior in real-time, and correlate signals across the entire environment. This is crucial for detecting novel techniques like jailbreaks and prompt injections that target AI models directly.
  5. Strengthen Data Security for Agent Interactions: Implement robust Data Loss Prevention (DLP) policies and sensitivity labeling in real-time for all data handled by AI agents. Ensure visibility into how agents interact with sensitive information (ingress and egress) to prevent oversharing and leakage.
  6. Embed Continuous Governance and Guardrails: Shift from periodic governance to a continuous, built-in system of guardrails for AI agents. These systems must observe behavior, prevent risks, constrain unsafe actions, and maintain alignment with business objectives and regulations, always with human oversight and validation.
  7. Evolve Security Skillsets for Agent Management: Security professionals must adapt their skills to manage, continuously validate, and evaluate AI agents as integral members of their security teams. This includes understanding AI ethics, prompt engineering, and how to build and secure no-code/low-code agents.
  8. Leverage AI for Defensive Augmentation: Actively deploy AI agents to augment human defenders. Use them for tasks such as incident triage, optimizing conditional access policies, customizing threat intelligence, and maintaining endpoint compliance. This allows human teams to focus on higher-level strategic challenges while agents handle repetitive, high-volume tasks at machine speed.
  9. Participate in Agent-to-Agent Threat Intelligence Sharing: Explore and contribute to initiatives like Crystal Ball 2.0 that facilitate agent-to-agent intelligence sharing. This enables machine-speed threat detection and defensive action activation across organizational and national borders, fostering collective resilience.

Key Takeaways

  • AI Transforms the Threat Landscape: AI-powered attacks are structurally different and operate at machine speed, rendering traditional, siloed security solutions ineffective.
  • Security Must Become Ambient and Autonomous: Future security needs to be deeply embedded, always-on, and proactive, operating at the scale and speed of the AI it protects.
  • AI Agents are Both an Opportunity and a Risk: While AI agents can significantly augment defenders, they also represent new attack surfaces and require the same vigilance as human identities to prevent them from becoming "double agents."
  • Comprehensive Observability and Control are Paramount: Establishing an observability control plane for AI agents is crucial, encompassing dynamic identity management, real-time threat protection, data security, and continuous governance.
  • Zero Trust Principles Extend to AI: Implementing Zero Trust for AI agents—with continuous verification, least privileged access, and an assume-breach mentality—is fundamental for building trust and ensuring their safe operation.
  • Collaboration and Skill Evolution are Essential: The cybersecurity community must foster collaboration (including agent-to-agent intelligence sharing) and continuously evolve skillsets to manage, validate, and leverage AI agents effectively.

About the Speaker(s)

Vasu Jakkal is the Corporate Vice President for Microsoft Security. In this role, she is a leading voice in the cybersecurity industry, driving Microsoft's vision for security and trust in an increasingly digital world. Her expertise spans across various aspects of cybersecurity, focusing on how technology advancements, particularly AI, reshape the defensive landscape and the strategies required to secure it. Jakkal is a passionate advocate for community collaboration and innovation in addressing complex security challenges.

Dr. Mohamed Al Kuwaiti serves as the Head of Cybersecurity for the UAE Government Cybersecurity Council. He is a prominent leader in national cybersecurity initiatives and international collaboration. Dr. Al Kuwaiti is instrumental in shaping the UAE's ambitious strategies for integrating AI agents across various governmental and economic sectors, demonstrating a forward-thinking approach to national resilience and defense through advanced cybersecurity frameworks like National XDR and Crystal Ball 2.0. His work exemplifies the practical application of agentic AI security at a national scale.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A polished executive keynote from a Microsoft CVP and a UAE government official that reads more like a product roadmap announcement and government PR piece than security research. The talk is heavy on vision and buzzwords, light on technical substance, and contains zero original research. It's well-produced corporate messaging dressed up as a security talk, which is exactly the kind of thing that makes practitioners roll their eyes and head to the hallway track.

Heather Calloway (CISO) — WEAK

A Microsoft VP and a UAE government official deliver a polished, well-produced vision of agentic AI security — but this is vendor architecture advocacy dressed as strategic leadership. The threat framing is real, the terminology is correct, and the UAE national XDR angle is genuinely interesting. But there is no evidence proportional to the claims, no honest treatment of what is unknown, and no actionable guidance that a CISO couldn't have derived from a product whitepaper. The gap between the size of the thesis and the rigor supporting it is significant.

→ Top-rated talks at RSAC 2026 Conference

All talks from RSAC 2026 Conference