<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[AI Agents are not programs.]]></title><description><![CDATA[<p>AI Agents are not programs. They are digital workers.</p><p>Discuss amongst yourselves.</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://stateofsecurity.com/ai-agents-are-already-working-for-you-whos-managing-them/" title="AI Agents Are Already Working for You. Who’s Managing Them?">
<img src="https://stateofsecurity.com/wp-content/uploads/2018/10/MSIblogheader1000x2881_new.jpg" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>







<div class="card-body">
<h5 class="card-title">
<a href="https://stateofsecurity.com/ai-agents-are-already-working-for-you-whos-managing-them/">
AI Agents Are Already Working for You. Who’s Managing Them?
</a>
</h5>
<p class="card-text line-clamp-3">Tweet AI Agents Are Not Applications. They Are Digital Workers. Most organizations are adopting AI agents faster than they are learning how to govern them. That is the problem. A chatbot that answers questions is one thing. An AI agent … Continue reading →</p>
</div>
<a href="https://stateofsecurity.com/ai-agents-are-already-working-for-you-whos-managing-them/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://stateofsecurity.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0">MSI :: State of Security <span class="text-secondary">(stateofsecurity.com)</span></p>
</a>
</div><p></p><p><a href="https://infosec.exchange/tags/agenticai" rel="tag">#<span>agenticai</span></a> <a href="https://infosec.exchange/tags/identity" rel="tag">#<span>identity</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/686583b8-843a-4039-9979-3f69c5499969/ai-agents-are-not-programs.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 02:55:20 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/686583b8-843a-4039-9979-3f69c5499969.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 12 May 2026 03:48:38 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to AI Agents are not programs. on Tue, 12 May 2026 14:32:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> <span><a href="/user/badsamurai%40infosec.exchange">@<span>badsamurai</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> I think Michael's analysis is pretty much spot on. What Brent is trying to get people that are suffering from some AI psychosis to think about is the fact that digital identity is a real thing, and folks should take advantage of the control that they do have. I can say from my experience that a lot of developers just run their agents under their privilege, which is obviously a mistake.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116562091063839342</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116562091063839342</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 14:32:40 GMT</pubDate></item><item><title><![CDATA[Reply to AI Agents are not programs. on Tue, 12 May 2026 14:21:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> <span><a href="/user/badsamurai%40infosec.exchange">@<span>badsamurai</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> DR;HTLUAW</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116562045606806345</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116562045606806345</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 14:21:06 GMT</pubDate></item><item><title><![CDATA[Reply to AI Agents are not programs. on Tue, 12 May 2026 13:51:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/badsamurai%40infosec.exchange">@<span>badsamurai</span></a></span> <span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> In full fairness, I believe the author writes that they should be handled "like" digital workers, but I agree that the term is inapposite. </p><p>The governance issue is real though. Agents running amok as a proxy for their operators is a disaster waiting to happen. Scoping their access is an identity problem. Think of it like a Chaos Service Account. I'm charitably suggesting that's the point here. </p><p>I've not read the whole book, but I hope there's a section regarding a standard to determine when the risks and costs outweigh potential benefits. Nobody seems to want to admit that most of the time, pulling the plug is the correct business decision.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/mttaggart/statuses/116561929640796894</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/mttaggart/statuses/116561929640796894</guid><dc:creator><![CDATA[mttaggart@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 13:51:37 GMT</pubDate></item><item><title><![CDATA[Reply to AI Agents are not programs. on Tue, 12 May 2026 12:57:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> I know plenty of incredibly smart and talented people that I’m now genuinely concerned with their interactions and takes from AI; I wish it was just some slop projects and their family photo as Studio Ghibli.</p><p>The author starts ok with calling for better governance and ownership. But calling AI agents <em>digital workers</em> is offensive and not a pathway to governance.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116561716610359871</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116561716610359871</guid><dc:creator><![CDATA[badsamurai@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 12:57:26 GMT</pubDate></item><item><title><![CDATA[Reply to AI Agents are not programs. on Tue, 12 May 2026 12:43:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/badsamurai%40infosec.exchange">@<span>badsamurai</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> I understand, but you should know I have known Brent for 30 years, and he is an order of magnitude smarter than you and I put together.  Why is he writing about this?  Because <em>people are using it</em>.  You and me and everyone else can have all the bad attitude we want, and be able to point at the smoking wreckage in two years and say "I told you so!" or we can work to mitigate the damage.  I choose the latter.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116561662719144998</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116561662719144998</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 12:43:44 GMT</pubDate></item><item><title><![CDATA[Reply to AI Agents are not programs. on Tue, 12 May 2026 12:10:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> <span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> couldn’t make it more than 2 pages. This is the stuff you see from people with a level of <em>AI psychosis</em>.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116561530371212627</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116561530371212627</guid><dc:creator><![CDATA[badsamurai@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 12:10:04 GMT</pubDate></item><item><title><![CDATA[Reply to AI Agents are not programs. on Tue, 12 May 2026 11:05:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> Aww come on.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116561278169759064</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116561278169759064</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 11:05:56 GMT</pubDate></item><item><title><![CDATA[Reply to AI Agents are not programs. on Tue, 12 May 2026 04:15:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> Improvement over time... Certainly not yet. But maybe in a bit.  It's a wild ride and I'm not sure any of us can afford a ricket.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/popio/statuses/116559662484061277</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/popio/statuses/116559662484061277</guid><dc:creator><![CDATA[popio@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 04:15:03 GMT</pubDate></item><item><title><![CDATA[Reply to AI Agents are not programs. on Tue, 12 May 2026 03:50:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> <sub><sub><sub><sub><sub>no</sub></sub></sub></sub></sub></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116559564635369457</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116559564635369457</guid><dc:creator><![CDATA[cr0w@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 03:50:09 GMT</pubDate></item></channel></rss>