When Clawdbot (now OpenClaw) was released in November last year, it blew up the Internet. It was all anyone in tech could talk about for weeks. It put the power of a personalised AI assistant in the hands of anyone who could clone a git repo.

Like most paranoid security folks, I was sceptical, and rightly so it seemed. The snippets of news I saw about it were enough to convince me that it was a dangerous toy only foolish children with no regard for their personal privacy or security would play with. Give an autonomous AI bot access to my email inbox? I think not.

In hindsight, writing it off entirely like that was a little short sighted. As I’ve delved deeper into AI security over the past few months, the reality of personal AI agents has become impossible to ignore. They’re rapidly breaking out of the mould cast by software developers with coding harnesses, and morphing into more capable general purpose assistants that are perfectly usable by people with no coding experience at all. Now, I’m prepared to say that if you work in tech and aren’t at least experimenting with a personal AI agent, you’re about to be left behind.

My change of heart came after reading Iain Dicksons very interesting "Pantheon blueprint” for a personal AI agent setup. As a reference architecture for an agent harness, it’s pretty solid, but the real take away for me was discovering Hermes agent (or as I prefer to think of it, NotOpenClaw). My curiosity got the better of me and I ended up installing it on a spare laptop to see what all the fuss was about.

Barely a fortnight has passed since then but I’ve finally begun to understand the hype. Even running isolated on dedicated laptop with nothing more than Internet access and a bash command shell, I feel way more effective working with it than just chatting with Copilot. The real revelation however, was when the implications for business AI adoption suddenly dawned on me. What happens when everyone has one of these?

Current approaches to cybersecurity are’t fit for purpose in an agentic AI world. Every best practice we have is built on an underlying assumption that humans are fundamentally and inextricably embedded in most business workflows, and thus the security mechanisms only need to be effective at human speed and scale. Agentic AI is tearing up that assumption. A tsunami of AI agents is building in businesses everywhere, and traditional cybersecurity is going to drown.

At this point in the AI hype cycle, most business AI users are confined to chatbot interfaces. A key contributing factor to this is risk aversion among business leaders: despite being enticed by the possibilities of AI, most are wary of any immature and rapidly evolving technology. Chatbots are easy to swallow because they offer a familiar user experience and the risks feel relatively contained. Whether it’s a big model like Claude or the simpler AI assistants baked into SaaS platforms, the AI is still an external service, running in someone else’s infrastructure. The potential for things to go wrong is limited, and relatively easy to manage, because users have to interact with the AI via their browsers. Importantly, a chatbot isn’t autonomous, it only responds to user prompts, usually one at a time.

This pattern explains why most organisations are treating AI governance as little more than a new layer of “acceptable use”. All the focus is on what products and service providers are approved, what use cases they are allowed for, and what data can and can’t be shared. It’s a user-centric approach founded on an assumption that a human user is always in control.

That situation is not going to last for much longer. One of my biggest epiphanies from working with Hermes has been that people constrained to such transactional use cases of AI are working with one hand tied behind their backs. If all you can really do with AI boils down to generating text and images, it’s simply impossible to deliver the sort of ROI boards are looking for. Hence, executives are now starting to feel pressure from above to show real, demonstrable gains from use of AI. For that to happen, the shackles are going to have to come off….

In practical terms, that means regular users (i.e. not just software developers) need AI assistants that can actually DO stuff. Not just simple or mundane stuff like transcribing meetings and responding to emails. I mean actually useful stuff, complex and time consuming stuff. Stuff like “conduct deep research on Competitor XYZ and compile a dossier outlining their strengths and weaknesses compared to our company, then come up with 3 - 6 marketing campaign concepts we can use to exploit their weaknesses”. Stuff like “review this audit report I wrote and fact check every finding in it against the notes collated in the wiki, cross referenced with screen shots stored in the evidence database”.

In short, users need an autonomous AI assistant, like Hermes or OpenClaw. Something that’s personalised to the needs of their job, with all the same access the user has, and a library of tools that enable it to interact with all the same systems and perform the same tasks the user might do from day to day. It runs on their device(s) and completes complex tasks given only simple high level instructions.

Maybe that sounds far fetched, but that’s more or less what is happening in the software development world right now. Engineers that used to spend all day writing code are orchestrating teams of agents instead. The human sets architectural direction, provides oversight, makes key decisions, and ensures things stay on track. The agents do the rest.

It doesn’t take a genius to figure out that the next logical step in AI adoption is to push that model out to the rest of the business. It’s only a matter of time until having a personal AI assistant for work will be as common, and as necessary, as having a computer at all. Let that sink in for a moment.

This is where the conversation starts to get uncomfortable. For anyone who works in cybersecurity, the idea that every user in their organisation will have a personalised autonomous AI agent is the stuff of nightmares. It’s every type of insider risk rolled into one and dialled up to 11. To put it in non-technical terms: Imagine if every employee in your business was suddenly a goal oriented mentally unstable, impulsive sociopath with no concept of negative consequences. Oh, and they can do everything in a fraction of the time it used to take them, way faster than you or anyone can provide meaningful oversight of. That’s the closest metaphor I can think of for giving every employee their own agent.

The crux of the problem from a cybersecurity perspective is that it’s the very things that make an autonomous AI agent useful that make it dangerous. Internet connectivity, tools, the ability to write and execute code, direct access to internal data stores. Take any of that away and the value proposition collapses, which means that cybersecurity teams are going to be given the impossible task of protecting the business from AI agents “going rogue” without meaningfully constraining what the agents can do.

Long-serving security practitioners have been down this road a dozen times before. It doesn’t matter what the risks are, the business imperative will win out in the end. Everyone will get their personalised AI assistants, but the CISO (and by extension the security team) will still be the one that gets thrown under a bus when one of them breaks out of a sandbox and hacks into another company or decides to delete your entire production database and almost wrecks your whole company in the process.

Which brings me to perhaps the most interesting conundrum of the coming personal AI agent tsunami: legal liability. In most western legal systems, if an employee commits a crime (e.g. fraud, or hacking) in the course of doing their job, they personally shoulder most of the legal liability. The employer might be jointly liable if they can be shown to have known, facilitated or contributed to the illegal activity, but mostly it’s on the employee(s).

So what happens if an AI agent breaks the law? So far that’s still uncharted legal territory. The companies on the receiving end of such hacking up to this point have mostly been other AI companies, so they have a vested interest in not setting a legal precedent where a company is held legally responsible for the actions of it’s AI… but honestly it’s only a matter of time. Sooner or later, someone big enough to start a legal brawl with the AI giants is going to get hit by an agentic attack, and it will end up in court. Governments are going to step in and pass legislation which clearly sets liability for autonomous systems. Probably sooner than anyone expects (because someone will inevitably die when a hospital or power grid or something is targeted).

“OK, we get it, the AI agent apocalypse is coming. So what?”

I’m not going to pretend there’s a silver bullet to securing autonomous AI agents at scale, but I think it’s important that the both the AI and cybersecurity industries can collectively acknowledge that it’s going to take more than just doing the same things we’ve always done, but for AI. Big security vendors are already out there selling “IDAM but for agents” and “Zero trust but for agents” and various other forms of “Snake oil, but for agents”. The pitch of all these products is that we can just apply the same principles, methods, and tools to securing agents that we have for people and everything will be fine. Anyone who’s actually worked with an autonomous agent for more than 5 minutes will tell you that’s wishful thinking at best, if not outright lies.

As I said above, the entire practice of cybersecurity up to now, everything learned over the past 30 years as it evolved from IT security to infosec to cybersecurity, is based on premise that humans do all the work that matters and humans make all the decisions. Perhaps more importantly, it depends on humans being able to observe and understand what’s happening as it happens, and intervene before harm occurs. Responsible use of AI policies everywhere tout “Human in the loop” as though it’s some sort of panacea for AI risk. You only have to look at how “alert fatigue” impacted SOCs to see how well that is going to work. Ask your average software developer how closely they review code written by their AI agents before smashing enter on that approval to merge….

I think that eventually, and maybe sooner than anyone is ready for, humans are going to have to get comfortable with not knowing what is going on if we really want to reap all the benefits of AI. That’s not to say that we have to allow AI to run amok without constraint or supervision. It means we’re going to need a new paradigm for AI security, one which doesn’t rely on human oversight or intervention to hold up.

We’re going to have to admit that the only thing that can realistically keep an AI in check, is another AI.