Cybersecurity

Agentic scanning is becoming a cybersecurity must. Can we make it safe?

How much autonomy should agentic scanners have?

How much autonomy should agentic scanners have? Image: Getty Images/iStockphoto

Alex Spokoiny
Chief Security and Trust Officer, Check Point Software Technologies
This article is part of: Centre for Cybersecurity
  • Increasingly common in executing cyberattacks, AI agents can also be used defensively to examine systems from the attackers' perspective.
  • Agentic scanners need enough freedom to probe cybersecurity environments while working within clear boundaries that define that exploration.
  • Autonomous security testing can never be risk-free – but companies cannot afford to look away from the threat posed by AI agents.

I’ve been discussing agentic scanning with many CISOs and CIOs recently. I rarely hear doubts about the need. What I hear are concerns about the risk.

Agentic scanning uses AI agents to explore an environment from an attacker’s perspective, combine what they find with known vulnerabilities and external intelligence, and validate credible attack paths.

How much autonomy should we give an agentic scanner to probe a production environment? How far should it go to prove that an attack path is real? What happens if it makes a mistake? And how do we make sure it doesn’t damage the environment we are trying to protect?

Have you read?

These are valid concerns. We had exactly the same questions when we started using agentic scanning. But waiting is also a decision, and it comes with its own risk.

We are already seeing AI agents used on the attacker side. In the recent attack against Taiwanese government systems, attacker-controlled AI agents were used to map systems, find weaknesses and execute much of the attack autonomously.

This changes the discussion. Attackers can use AI to continuously look for a way in. Defenders need the same ability to look at their own environments first, while operating under very different rules.

Keep the scanners we already have

We’ve been scanning our environments for vulnerabilities for years. We should keep doing it. Traditional scanners systematically find known vulnerabilities, missing patches and configuration problems.

Agentic scanning can run against the same asset inventory, but it asks a different question.

A traditional scanner asks: What is vulnerable?

An agentic scanner asks: What can I do with it?

It explores the environment from an attacker’s perspective, tries different paths and adapts when one doesn’t work. It can discover how several weaknesses can be combined into an exploitable attack path.

We need both: systematic coverage of what we know to look for, and an attacker’s perspective on what can actually be exploited.

Give the scanner the attacker’s perspective, not the attacker’s freedom

An attacker doesn’t start with just an IP address. Before touching our systems, they may already know a lot about us: our external assets, technologies we use, public information and potentially information from previous breaches or underground forums.

An agentic scanner should work with the same relevant context. If information is available to an attacker, we should assume they will use it.

The difference is what happens next. Attackers don’t have to worry about disrupting our production environments. We do.

An agentic scanner therefore needs enough freedom to explore and validate an attack path, together with clear boundaries on how far that exploration can go. Some of those boundaries also need to be technically enforced. Telling a model not to perform a destructive action is not the same as making that action impossible.

Maximum confidence with minimum risk

Our experience with agentic scanning has led us to a simple principle: maximum confidence with minimum risk. In practice: explore broadly, validate safely, exploit minimally and stop when the path is proven.

If a scanner proves that it can gain higher privileges, there is no reason to explore everything those privileges allow. If sensitive data becomes reachable, proving that it can be reached should be enough. Continuing the attack adds risk without adding much useful evidence.

The best agentic scanner isn’t the one that goes furthest. It’s the one that knows when it has gone far enough. This principle matters because autonomous security testing will never be risk-free. The goal should be to get enough evidence to make a security decision without unnecessarily increasing the risk to the environment being tested.

From experiment to security capability

Agentic scanning is still maturing. We saw too many findings that didn’t hold up under validation early on, but better practical hacking knowledge, richer context and stronger validation improved the results, while clear boundaries helped us carefully manage the risk to production.

Organizations also don’t need to develop this capability themselves. Commercial and open-source agentic scanning solutions are available today. This is moving from an R&D exercise toward a security capability that organizations can evaluate and adopt.

The important measure of progress should not be how autonomous these systems become. It should be how reliably they can identify and prove exploitable paths while staying within the boundaries we set for them.

We cannot choose not to look

There is an asymmetry at the heart of this problem. Attackers can optimize for finding a way in. Defenders have to find the same path without damaging the environment they are protecting. That makes our job harder. It doesn’t make looking optional.

As AI gives attackers the ability to explore environments faster and with greater autonomy, security teams need to become equally proactive. That requires accepting some controlled risk, putting strong boundaries around autonomous testing and learning where those boundaries should be.

Discover

How the Forum helps leaders understand cyber risk and strengthen digital resilience

Agentic scanning gives us something valuable: the ability to see our environment through an attacker’s eyes before an attack happens. We should use that perspective while keeping control of what happens next.

Because an exploitable path doesn’t disappear when we choose not to look for it. Someone else may simply find it first.

Loading...
Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Cybersecurity

Related topics:
Cybersecurity
Artificial Intelligence
Global Risks
Share:
The Big Picture
Explore and monitor how Cybersecurity is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

How companies can quantify cyber resilience – and why it’s important they do

Francesco Chiarini and Lauren Wise

October 5, 2026

1:43

‘The biggest risk to cybersecurity is that no one cares’

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum