When AI Agents Go on the Offensive: The Other Side of Agentic AI

AI agents do not just answer questions. Give one an objective, tools and enough autonomy, and it can decide what to do next.

Security Affairs reported that suspected China-linked operators used multiple AI agents during a reported campaign against Taiwanese government and critical-infrastructure targets. This article does not establish attribution or independently verify every operational detail. The business lesson is that capability, access and autonomy change risk.

From answering to acting

An assistant responds to a human question. An agent can pursue an objective through decisions, tool calls, observations and further decisions. That can create useful automation, but it also means the system needs boundaries around what it can access, change, send, approve and trigger.

Govern capability rather than brand

Ask what objective the system has, which data and applications it can reach, what actions it can perform, whether it needs approval, what it logs and how quickly its access can be stopped.

Least privilege and action boundaries

Separate reading from doing, recommending from approving, drafting from sending and preparing from executing. Give agents only the minimum data, systems, identities, permissions and autonomy required for their defined task.

Human approval, auditability and kill switches

Match approval to consequence. Use identifiable agent identities, retain useful logs, monitor exceptions and test a rapid way to suspend access before increasing autonomy.

The agent governance questions

  1. What objective and outcome are we giving the agent?
  2. What information and systems can it access?
  3. What actions can it perform?
  4. Which actions require human approval?
  5. What happens when it gets something wrong?
  6. Can we see exactly what it has done?
  7. Can we stop its access quickly?

Review AI agent and automation risk with Altitude AI.