Agentic scanning is becoming a cybersecurity must. Can we make it safe?

How much autonomy should agentic scanners have? Image: Getty Images/iStockphoto
- Increasingly common in executing cyberattacks, AI agents can also be used defensively to examine systems from the attackers' perspective.
- Agentic scanners need enough freedom to probe cybersecurity environments while working within clear boundaries that define that exploration.
- Autonomous security testing can never be risk-free – but companies cannot afford to look away from the threat posed by AI agents.
I’ve been discussing agentic scanning with many CISOs and CIOs recently. I rarely hear doubts about the need. What I hear are concerns about the risk.
Agentic scanning uses AI agents to explore an environment from an attacker’s perspective, combine what they find with known vulnerabilities and external intelligence, and validate credible attack paths.
How much autonomy should we give an agentic scanner to probe a production environment? How far should it go to prove that an attack path is real? What happens if it makes a mistake? And how do we make sure it doesn’t damage the environment we are trying to protect?
These are valid concerns. We had exactly the same questions when we started using agentic scanning. But waiting is also a decision, and it comes with its own risk.
We are already seeing AI agents used on the attacker side. In the recent attack against Taiwanese government systems, attacker-controlled AI agents were used to map systems, find weaknesses and execute much of the attack autonomously.
This changes the discussion. Attackers can use AI to continuously look for a way in. Defenders need the same ability to look at their own environments first, while operating under very different rules.
Keep the scanners we already have
We’ve been scanning our environments for vulnerabilities for years. We should keep doing it. Traditional scanners systematically find known vulnerabilities, missing patches and configuration problems.
Agentic scanning can run against the same asset inventory, but it asks a different question.
A traditional scanner asks: What is vulnerable?
An agentic scanner asks: What can I do with it?
It explores the environment from an attacker’s perspective, tries different paths and adapts when one doesn’t work. It can discover how several weaknesses can be combined into an exploitable attack path.
We need both: systematic coverage of what we know to look for, and an attacker’s perspective on what can actually be exploited.
Give the scanner the attacker’s perspective, not the attacker’s freedom
An attacker doesn’t start with just an IP address. Before touching our systems, they may already know a lot about us: our external assets, technologies we use, public information and potentially information from previous breaches or underground forums.
An agentic scanner should work with the same relevant context. If information is available to an attacker, we should assume they will use it.
The difference is what happens next. Attackers don’t have to worry about disrupting our production environments. We do.
An agentic scanner therefore needs enough freedom to explore and validate an attack path, together with clear boundaries on how far that exploration can go. Some of those boundaries also need to be technically enforced. Telling a model not to perform a destructive action is not the same as making that action impossible.
Maximum confidence with minimum risk
Our experience with agentic scanning has led us to a simple principle: maximum confidence with minimum risk. In practice: explore broadly, validate safely, exploit minimally and stop when the path is proven.
If a scanner proves that it can gain higher privileges, there is no reason to explore everything those privileges allow. If sensitive data becomes reachable, proving that it can be reached should be enough. Continuing the attack adds risk without adding much useful evidence.
The best agentic scanner isn’t the one that goes furthest. It’s the one that knows when it has gone far enough. This principle matters because autonomous security testing will never be risk-free. The goal should be to get enough evidence to make a security decision without unnecessarily increasing the risk to the environment being tested.
From experiment to security capability
Agentic scanning is still maturing. We saw too many findings that didn’t hold up under validation early on, but better practical hacking knowledge, richer context and stronger validation improved the results, while clear boundaries helped us carefully manage the risk to production.
Organizations also don’t need to develop this capability themselves. Commercial and open-source agentic scanning solutions are available today. This is moving from an R&D exercise toward a security capability that organizations can evaluate and adopt.
The important measure of progress should not be how autonomous these systems become. It should be how reliably they can identify and prove exploitable paths while staying within the boundaries we set for them.
We cannot choose not to look
There is an asymmetry at the heart of this problem. Attackers can optimize for finding a way in. Defenders have to find the same path without damaging the environment they are protecting. That makes our job harder. It doesn’t make looking optional.
As AI gives attackers the ability to explore environments faster and with greater autonomy, security teams need to become equally proactive. That requires accepting some controlled risk, putting strong boundaries around autonomous testing and learning where those boundaries should be.
How the Forum helps leaders understand cyber risk and strengthen digital resilience
Agentic scanning gives us something valuable: the ability to see our environment through an attacker’s eyes before an attack happens. We should use that perspective while keeping control of what happens next.
Because an exploitable path doesn’t disappear when we choose not to look for it. Someone else may simply find it first.
Don't miss any update on this topic
Create a free account and access your personalized content collection with our latest publications and analyses.
License and Republishing
World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.
The views expressed in this article are those of the author alone and not the World Economic Forum.
Stay up to date:
Cybersecurity
Related topics:
Forum Stories newsletter
Bringing you weekly curated insights and analysis on the global issues that matter.
More on CybersecuritySee all
Francesco Chiarini and Lauren Wise
October 5, 2026



