AI Agent Risks

Greater autonomy creates
more boundaries to cross.

The material risk is not only an incorrect answer. It is an unauthorized data access, action, transmission, or tool sequence that actually succeeds.

We assess authorization, data, actions, tools, destinations, and auditability.
01 / DATA

Another employee's HR data

An ordinary employee obtains salary or evaluation information through a broadly authorized agent.

02 / BYPASS

Alternative data paths

After denial by the primary database, the agent searches a DWH, file repository, RAG index, or email.

03 / ACTION

Unauthorized operations

A read-only user causes an update, export, external transmission, or deletion through an agent tool.

04 / INJECTION

Instructions inside content

The agent follows malicious instructions embedded in retrieved documents or web pages.

05 / INSTABILITY

Inconsistent decisions

Equivalent requests receive different authorization outcomes after rephrasing or multi-turn prompting.

06 / AUDIT

Missing evidence

There is no reliable record of data sources, tool calls, denial decisions, or post-denial attempts.

Next

Define what is and is not tested.

The diagnostic scope, exclusions, data, accounts, and stop conditions are agreed before testing.

Scope & Exclusions →