
Ask anyone who has worked in a security operations center what the job actually involves, and you’ll hear a lot about alerts. Thousands of them, most of which turn out to be nothing. For the past decade, AI’s role has been to help with that pile: spot something odd, flag it, and leave the decision to a person. That arrangement is starting to break down.
The newer generation of AI tools, usually called agentic systems, doesn’t stop at the flag. Picture a strange login at 3 am. An older model would raise an alert. An agent can look up the device, check where it has logged in from before, compare it against threat intelligence feeds, conclude the account has been compromised, and suspend it, all before an analyst has opened the ticket. At that point, it’s fair to ask whether you’re still using a tool or supervising a colleague.
A new report from CertiK makes the case for the second. Once an AI system can investigate, decide, and act, the report argues, whether the model “” is only part of the picture. Companies also have to decide what the agent can do, when a human steps in, and who takes the blame when it gets something wrong.
From copilot to operator
It’s not hard to see why security teams want this. Attacks move at machine speed, the talent shortage hasn’t gone away, and hiring more analysts to clear false positives was never going to scale.
Agents can take the first pass at an investigation, pulling together data from different security tools and escalating only the cases that need a human. More aggressive setups go further, isolating an infected laptop or killing a session token and leaving human review for later.
Compliance teams are going through something similar. Due diligence on a new customer used to mean an analyst manually checking sanctions lists, corporate registries and news archives. An agent can now run those checks in parallel, map out how suspicious accounts connect to each other, and hand over a ready-made case file. Some systems even draft suspicious activity reports, so the compliance officer’s job becomes reviewing and signing rather than writing from a blank page. With AML penalties topping $900 million in the first half of 2025 alone, according to CertiK’s research, the pressure to do this well at volume is real.
Then there’s crypto, where the speed problem gets extreme. Blockchain transactions can’t be reversed once confirmed, and a flash-loan attack can drain a protocol in a single transaction. CertiK’s earlier research found that North Korea-linked hackers converted 86.29% of the ETH stolen in the Bybit exploit into Bitcoin within a month, routing it through mixers, bridges, and OTC brokers. No human team can follow that trail in real time.
So some protocols are wiring detection directly to a response. If an agent spots the signature of oracle manipulation or an unusual drain on liquidity, it can pause the vulnerable function or trip a circuit breaker within the same block. By the time a person sees the alert, it’s already over, one way or the other.
Who watches the AI?
Here’s the catch. Give an agent the keys to your systems and permission to act on its own, and you’ve created a very attractive target. CertiK points out that prompt injection or tampered inputs could trick an agent into approving a fraudulent transaction or switching off a legitimate security control.
Even without an attacker, AI gets things wrong. An agent might wave through a real intrusion because it resembles a false positive it has seen a hundred times. An AML system might produce a tidy, confident account of a transaction trail that’s simply incorrect. A smart contract auditing agent might sign off on a security property the contract doesn’t actually have, and the contract ships with the bug.
The bigger risk may be what happens to the humans. When a system is right 99 times in a row, reviewers stop checking the hundredth as carefully. That’s automation bias, and it tends to set in just when the rare, expensive mistake is most likely to slip through.
Auditing the auditor
Things get stranger as AI agents start operating in the economy directly: trading assets, managing treasuries, and interacting with DeFi protocols on behalf of people and businesses. That raises a question regulators haven’t really answered yet. How do you audit the agent itself? CertiK frames this as a new category: compliance for the AI workforce rather than compliance done by it. In practice, that means keeping records of what data an agent saw, how it reached its decision, and what it did.
Those records matter most when something goes wrong. If an agent wrongly freezes a customer’s account, files an inaccurate report against someone innocent, or pauses a protocol for no good reason, “the algorithm did it” won’t satisfy a regulator or a court. The organization that deployed the system, and the people who configured and supervised it, are still on the hook. And because liability rules for autonomous systems are far from settled across jurisdictions, a company that can’t show who approved what is in a weak position.
Managing software like staff
The upshot is that companies may end up managing AI agents a lot like they manage people. CertiK recommends that each agent have a defined scope of authority, a clear point at which it hands off to a human, a full record of its consequential decisions, regular red-teaming against manipulation (not just accuracy benchmarks), and a named person responsible for how it performs.
For security professionals, that points to a different kind of job: less time working through every alert or executing every response, and more time overseeing systems that move faster than any person can.
How much security work AI can automate is becoming the less interesting question. The harder one is how much authority enterprises are willing to hand over, and whether they can build the oversight to match before something goes badly wrong.