Artificial intelligence agents are moving beyond simple chat and automation tasks. They are increasingly being given the ability to browse websites, communicate with services, access information, and perform actions on behalf of users.
That shift creates a new cybersecurity challenge.
An AI agent operating with a user’s permissions can potentially encounter malicious websites, phishing pages, unsafe files, deceptive instructions, or other hostile content while carrying out an otherwise legitimate task.
A recent development from doxx.net highlights this emerging security problem. The company has raised $38 million in Series A funding while introducing its Agentic Defined Networking, or ADN, platform in open beta. The platform is designed to provide AI agents with controlled connectivity and built in protection against malicious destinations.
Why AI Agents Need Their Own Security Controls
Traditional cybersecurity models were largely designed around human users, applications, devices, and network traffic.
AI agents introduce another type of actor.
An agent can potentially:
• Browse external websites
• Access enterprise applications
• Retrieve files and information
• Interact with APIs
• Communicate with external services
• Perform tasks using delegated permissions
• Make decisions based on information it encounters online
The challenge is that an agent may not reliably distinguish between trustworthy information and malicious instructions.
If an agent has access to sensitive systems or accounts, a seemingly harmless browsing activity could potentially expose an organization to additional security risks.
This makes agent identity, permissions, network access, and activity monitoring increasingly important.
The Internet Becomes Part of the AI Attack Surface
AI agents that interact with the public internet can encounter many of the same threats faced by human users.
These can include:
• Phishing websites
• Malware distribution sites
• Malicious downloads
• Credential harvesting pages
• Fraudulent applications
• Prompt injection content
• Malicious APIs
• Data exfiltration destinations
• Deceptive instructions embedded in web content
The difference is speed and scale.
An automated agent may process information much faster than a human and could potentially interact with multiple services during a single workflow.
This means security controls need to operate at the same point where the agent makes network and application decisions.
What Is Agentic Defined Networking?
According to SecurityWeek, doxx.net’s ADN platform is designed to provide agents and human users with a controlled private networking environment.
The platform includes DNS level threat protection intended to block known and emerging malicious destinations before an agent or user connects to them.
The company says its platform also includes agent integration and API controls, end to end communications, malware and phishing protection, and privacy focused networking capabilities.
The platform uses its own networking infrastructure, DNS root, certificate authority, IP space, and autonomous system number. SecurityWeek also reports that doxx.net says it blocked more than 38 million threats during its closed beta beginning in December 2025. That figure is a company reported claim rather than an independently verified measurement in the article.
AI Agent Permissions Need Strong Boundaries
One of the most important lessons from the growth of agentic AI is that organizations should not treat an AI agent exactly like a conventional application.
Agents may require access to:
• Corporate applications
• Databases
• Cloud services
• APIs
• Files and documents
• Communication platforms
• Internet resources
• Internal business systems
Each permission creates potential security implications.
Organizations should therefore apply least privilege principles to AI agents and limit access according to the specific task an agent is authorized to perform.
An agent responsible for scheduling meetings should not automatically receive access to financial systems.
An agent analyzing documents should not necessarily have permission to modify production databases.
Security boundaries should follow the agent’s actual business purpose.
Continuous Monitoring Becomes Essential
Traditional access controls alone may not provide enough visibility when AI agents are acting autonomously.
Security teams should monitor:
• Agent identities
• API activity
• Network destinations
• Authentication events
• Data access
• File transfers
• Tool usage
• Permission changes
• Unusual behavioral patterns
• Attempts to access restricted resources
Organizations
The Importance of AI Governance
should also maintain detailed audit logs so security teams can understand what an agent did, which resources it accessed, and what decisions or actions occurred during an automated workflow.
The emergence of agentic AI also creates governance questions.
Organizations should define:
• Which AI agents are approved
• Which employees or systems can deploy them
• What data each agent can access
• Which external services agents can communicate with
• Which actions require human approval
• How agent activity is logged
• How credentials and API keys are protected
• How agents are tested before deployment
• How incidents involving AI agents are investigated
AI governance should therefore extend beyond model performance and privacy.
It should also address identity, authorization, networking, monitoring, security testing, and incident response.
Security Testing Must Evolve With Agentic AI
Organizations adopting AI agents should consider dedicated security testing for agent workflows.
Security assessments can evaluate whether agents can be manipulated through:
• Prompt injection
• Malicious web content
• Unauthorized tool calls
• Excessive permissions
• Insecure APIs
• Credential exposure
• Data leakage
• Unsafe file processing
• Improper access controls
• Indirect instruction attacks
Red team exercises can also simulate realistic scenarios where an agent encounters malicious content and determine whether existing controls prevent unsafe actions.
Industries That Need to Prepare
The risks associated with internet connected AI agents can affect organizations across multiple sectors.
Financial Services
Banks, fintech companies, investment firms, and payment providers can use AI agents for customer support, operations, research, fraud analysis, and internal automation. These environments require strong controls around financial data, customer information, authentication, and transaction systems.
Healthcare
Healthcare organizations may deploy AI for administrative workflows, patient services, document processing, and data analysis. Security controls are particularly important when agents interact with sensitive health information and regulated systems.
Retail and E-commerce
Retail organizations can use agents for customer support, inventory operations, marketing, analytics, and online services. Controls around customer data, payment environments, APIs, and external websites are essential.
Manufacturing
Manufacturers increasingly use AI across operational technology, supply chain management, engineering, maintenance, and enterprise applications. Agent permissions should be carefully separated between business systems and operational environments.
Government
Government agencies may use AI agents for administrative services, information processing, citizen services, and internal operations. Strong identity controls, monitoring, data protection, and governance are important when agents interact with sensitive government systems.
Technology and SaaS
Technology companies and SaaS providers are likely to be among the most active adopters of agentic AI. They also face significant risks because agents may have access to source code, cloud infrastructure, customer information, development environments, and production systems.
What Organizations Should Do Now
Organizations preparing for agentic AI adoption should consider a security framework that includes:
Inventory AI agents.
Maintain visibility into which agents exist, what they do, and who owns them.
Apply least privilege.
Give agents only the permissions necessary to perform their assigned tasks.
Control internet access.
Restrict agent connectivity and prevent unnecessary communication with untrusted destinations.
Protect non human identities.
Secure API keys, service accounts, tokens, and other credentials used by AI agents.
Monitor agent activity.
Track network connections, tool usage, data access, authentication, and unusual behavior.
Test agent workflows.
Conduct security assessments and adversarial testing before deploying agents into sensitive environments.
Require human approval for high impact actions.
Financial transactions, privileged changes, production modifications, and sensitive data transfers may require additional authorization.
Prepare incident response procedures.
Security teams should have procedures for disabling compromised agents, revoking credentials, investigating activity, and containing unauthorized access.
Conclusion
The rapid adoption of AI agents is changing the way organizations think about cybersecurity.
AI agents are not simply software features. They can become active participants in enterprise workflows with access to applications, data, APIs, and internet resources.
The $38 million funding round announced by doxx.net and the introduction of its ADN platform reflect the growing market focus on securing AI agents while they operate on behalf of users.
For enterprises, the broader lesson is that AI adoption and cybersecurity architecture need to evolve together.
Organizations should establish clear agent identities, enforce least privilege, control network access, protect credentials, continuously monitor activity, and test agent behavior against realistic attack scenarios.
As AI agents become more capable and autonomous, securing what they can access may become just as important as securing the models themselves.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
For organizations adopting AI agents, COE Security can help assess agentic AI architectures, evaluate AI and LLM security risks, test agent permissions and workflows, assess API and cloud integrations, and identify vulnerabilities that could lead to unauthorized actions or data exposure.
COE Security can also support financial services, healthcare, retail, manufacturing, technology, and government organizations with AI security assessments, penetration testing, cloud security, identity and access management, application security, threat monitoring, secure development practices, and compliance aligned security programs.
Our approach can help organizations introduce AI agents while maintaining appropriate security controls, monitoring capabilities, and governance processes.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.
Click to read our LinkedIn feature article