ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The Expert View: Securing financial services organisations in the age of autonomous AI agents

Sponsored by Checkpoint
Linked InXFacebook
bookmark_borderSave to Library

“AI governance is becoming as big a topic as cyber-governance,” Rory Shloydo-Sadler, Cyber Security Sales Leader at Check Point, told attendees at a TEISS briefing at the House of Lords. Hosted by Check Point, AWS and Cloud Bazaar, the evening gathered senior security leaders from the financial services sector to discuss how to secure and govern autonomous AI agents. A year of fast progress has not settled the question, and the danger is that adoption outruns understanding.

 

Dheeraj Mudgil, a Security Architect at AWS, said agentic working had grown hugely since the arrival of the agentic AI tool Open Claw in 2025. He described it as a new way of working with AI, a harness rather than request and response, and said security’s first instinct had been to lock it down. He likened it to the arrival of Bring Your Own Device, where security eventually had to give in and focus on the right controls.

 

A new way in for attackers


The case for caution came with what Sam Watts, Product Lead for AI Agent Security at Check Point, called the “lethal trifecta”: an agent that can carry an attack, the means to unleash it, and access to data. Prompt injection is closer to social engineering than hacking, so the best assumption is to treat every model as insecure.

 

One attendee’s helpdesk agent had more access than the staff using it, forcing them to constrain its context. Others raised concentration risk: if every agent is built on the same model, then one vulnerability undermines everything. A multi-model approach may be the best defence. Stranger still was the prospect of an offensive agent talking a defensive one into doing its work.

 

Watts also noted that foundation models are built to be as helpful and capable as possible, which is what makes them exploitable. Check Point’s answer is a model that watches another AI’s actions and flags anything suspicious, a “cynical AI”, in his words. Because an LLM checking an LLM is expensive, that watchdog is a smaller, cheaper model.

 

Experimenting, not yet deploying


For all the concern, attendees are some way from deployment; few have them in production. Attendees described a ladder: human in the loop, then human on the loop, monitoring instead of approving each action. Some were piloting security agents to identify and prioritise vulnerabilities, but nothing was customer-facing yet.

 

Some attendees pointed out that agents must meet higher standards than human workers. They are expected to be perfect at a task that a human might carry out with 80 per cent success. And many so-called agents, several warned, are just workflows – powerful but not autonomous.

 

Indeed, there is uncertainty about what an agent is. Is the agent an instance of a service with its own identity, or the service itself? Run 100 instances with slightly different skills and is that 100 agents? Better, one attendee suggested, to look past the agent to the outcome it is chasing. The distinction matters: autonomy and adaptivity are what bring a system within scope of the forthcoming EU AI Act.

 

Who owns the agent?


Accountability was a dominant theme. Agents act, but a human must answer for them. The idea that drew most interest was a register of agents, each with a named person responsible, much as organisations track their people. The register, several argued, would have to be a control layer, not just a list: something that grants an agent permission to act, records who granted it, and lets the organisation roll back and gauge its blast radius.

 

But naming an owner raises more questions: what happens when that person leaves the business? Or goes on holiday? If they get fired, how do you prevent them from still manipulating it? Many agent security problems, several attendees noted, are really management problems, which leaves the hardest question: who takes on the risk?

 

Regulation was the other worry. We don’t really have a regulator for technology, one attendee observed; it governs humans and actors, not the tech, and looks at outcomes rather than the systems underneath. So how will regulators know the issues if industry itself doesn’t? The ICO has recently published a paper on agentic AI, a sign of engagement, but few were sure regulators grasp what agents can do. The bigger danger, others feared, is regulators over-reacting as they scramble to catch up. In any case, some warned, reputational risk may outweigh the regulatory kind.

 

Closing the session, Shloydo-Sadler returned to where he began. Bringing people together on these questions, he reflected, showed how widely they are shared. That was reassuring and sobering at once, and it confirmed there is “still a long way to go”. His parting warning was about pace: many risks are emerging very quickly, and a risk can become an incident before you know it.


To learn more, please visit: www.checkpoint.com

Sponsored by Checkpoint
Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543