How Will Agentic AI Transform Cybersecurity? Vasu Jakkal, Microsoft Security at RSAC 2025

17.6K views
β€’
April 29, 2025
by
RSA Conference
YouTube video player
How Will Agentic AI Transform Cybersecurity? Vasu Jakkal, Microsoft Security at RSAC 2025

TL;DR

Agentic AI can transform cybersecurity by investigating threats, triaging alerts, managing vulnerabilities, accelerating patches, adjusting access and eventually predicting attacks. Microsoft trains security models on 84 trillion daily signals, while defenders face 7,000 password attacks per second. Realizing the benefits requires verified identities, least privilege, protected data, continuous oversight and lifecycle governance, making the details of secure deployment essential reading.

Transcript

ANNOUNCER: Please welcome Corporate Vice President, Microsoft Security, Vasu Jakkal. >> VASU JAKKAL: All right. Well, good afternoon, everyone. How is everyone doing? I know, I know, it's getting late in here. Well, that was amazing and congratulations again to Bert. What a beautiful message of hope and humility. I do think this is what this com... Read More

Key Insights

  • Ubiquity expands the security boundary: Agents are expected to become as common as applications, possibly more so, and to operate across intimate areas of everyday life. Their ability to coordinate work, home and organizational activities means security must cover interactions among people, data, systems and other agents rather than protecting a single isolated application.
  • Ambient intelligence creates deep access: Research, analyst and chief of staff agents require information to generate insights, transform raw data or coordinate schedules. That usefulness can place them close to sensitive personal and organizational data. Permissions and privacy guardrails therefore determine whether ambient assistance remains appropriately bounded when work and home contexts interact.
  • Attack volume demands automated defense: Microsoft reports an increase from 4,000 to 7,000 password attacks per second, with the latter equaling 600 million attacks each day. This volume supports the argument that defenders need AI-scale capabilities, since conventional response capacity must contend with both enormous activity and increasingly capable agents.
  • Phishing leaves little response time: An attacker takes an average of 72 minutes or less to reach a user's full data after the user clicks a phishing link. That narrow interval makes rapid investigation, triage and access control especially important. Security agents can help compress defensive work that might otherwise proceed too slowly against the attack.
  • The tracked adversary population grew: Microsoft tracked 300 attackers in the previous year and 1,500 in the year of the talk. This increase illustrates why security teams face more than raw attack volume. They must also monitor an expanding set of threat actors while evaluating how AI may increase adversary productivity and capabilities.
  • Insider risk belongs in agent planning: Twenty percent of data breaches are attributed to insiders acting intentionally or unintentionally. Agent security therefore cannot focus only on external attackers. Access design, data preparation, logging and auditing must also address authorized environments where people or agents may expose information, misuse permissions or enable leakage.
  • Identity establishes an agent's boundaries: A distinct identity allows an organization to verify whether an agent is legitimate and define what it can do. It also supports decisions about the resources, data, people and agents with which it may interact. Explicit verification and least-privileged access must continue throughout the agent's lifecycle.
  • Data preparation precedes broad access: Organizations need to review permissions and policies before connecting agents to information. This preparation is intended to prevent oversharing and leakage while maintaining privacy across personal and professional boundaries. Giving an agent powerful capabilities without corresponding data controls would leave its actions insufficiently constrained.
  • Security AI needs specialized grounding: Microsoft trains its security models on 84 trillion signals seen every day and tunes them on security skills to reduce hallucinations. The models are then observed, audited and governed so their behavior can be checked against its intended purpose. The approach combines domain data with continuing operational oversight.
  • Current agents target repetitive security work: Reported applications include vulnerability management, rapid patching, phishing-alert triage and conditional access policies. Generative AI also assists with threat investigations, incident reports and reverse engineering. Together, these uses place AI across investigation, remediation and access decisions rather than confining it to a single security function.
  • Predictive protection is the next shift: Future agents could anticipate attacks, identify risk when content is created and determine dynamically who should receive access, when access is appropriate and which resources should be available. Coordination among security agents could move protection from responding after an event toward embedding security by design and default.
  • Dynamic systems require dynamic governance: Thinking agents can learn from people, plan, act and adjust while pursuing goals, so verification cannot remain limited to static laboratory testing. Governance must become dynamic and probabilistic. Monitoring, policies, identity, onboarding, offboarding and decommissioning must evolve while agents become more autonomous and still preserve human agency.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can agentic AI transform cybersecurity?

Agentic AI can investigate threats, prepare incident reports, reverse engineer malicious activity, manage vulnerabilities and accelerate patching. It can also triage phishing alerts and apply conditional access policies. Future agents could predict attacks, flag risks when data is created and adjust access according to the user, time and resource. These capabilities matter because defenders face 7,000 password attacks per second and phishing compromises that can reach full data in 72 minutes or less.

Q: What security controls do AI agents need?

AI agents need identities, explicit verification, least-privileged permissions and appropriate data access. Organizations must define what each agent may do and which people, resources or other agents it may work with. Logging, auditing, observability, threat monitoring, governance and regulatory compliance provide continuing oversight. These controls must span development, onboarding, operation, offboarding and decommissioning because risk exists throughout the lifecycle.

Q: Why is identity central to agentic AI security?

Identity establishes whether an agent is legitimate and connects that agent to enforceable permissions. It helps determine which data and systems the agent may access and which people or agents it may engage. Explicit verification and least privilege limit access to what the work requires. These controls need to adapt as the agent, its responsibilities and associated risks change.

Q: How should organizations protect data used by AI agents?

Organizations should prepare data before granting agents broad access by reviewing permissions and applying appropriate policies. They should prevent oversharing and leakage while maintaining privacy guardrails between work and home contexts. Logging, auditing and observability help reveal how agents use information after access is granted. This is necessary because agents depend on data and may cross boundaries among personal, professional and organizational systems.

Q: How is AI already being used in security operations?

Generative AI already helps with threat investigations, incident reporting and reverse engineering. Agentic applications include vulnerability management, rapid patching, phishing-alert triage and conditional access policies. Microsoft trains its security models on 84 trillion daily signals and tunes them on security skills to reduce hallucinations. Observation, auditing and governance are then used to check that those systems perform their intended work.

Q: What attacks can threat actors support with AI?

Threat actors can use AI to increase their productivity and expand existing forms of attack. Examples include vulnerability discovery, malware and malware variants, phishing, social engineering and intelligent password cracking. They can also create deepfakes. Defenders consequently need both AI-enabled security capabilities and protections for the models and agents that adversaries may attempt to misuse or compromise.

Q: How autonomous could AI security agents become?

Agents are expected to progress from mimicking human tasks toward greater independence. More autonomous systems could create their own sub-goals, potentially change models to pursue objectives and take actions independently. Human agency must remain preserved as this autonomy increases. The shift makes permissions, rules of engagement and continuous oversight important because an agent's behavior may extend beyond explicitly assigned steps.

Q: Why must governance for agentic AI be dynamic?

Agents can learn from people, plan, act and adjust their behavior while working toward goals. Static laboratory verification cannot account for every change in an operating agent or its environment. Governance therefore needs dynamic, probabilistic verification supported by monitoring, auditing and observability. Policies, identities, permissions and lifecycle controls must evolve so agents remain compliant and continue behaving as intended.

Summary & Key Takeaways

  • Envisioning interactive digital partners: Vasu Jakkal describes agents becoming as ubiquitous as applications and bringing ambient intelligence into personal and professional life. They could serve as companions, colleagues, assistants and thought partners. Research agents may develop deep subject matter insights, analyst agents may convert raw data into analytics, and chief of staff agents may coordinate work schedules with home assistants. These systems could also address health care, education, transportation and cybersecurity while collaborating with people and other agents.

  • Confronting an accelerated threat landscape: Greater agent capability arrives amid 7,000 password attacks per second, equal to 600 million daily, compared with 4,000 per second the previous year. Microsoft increased its tracked attackers from 300 to 1,500. After a user clicks a phishing link, an attacker takes an average of 72 minutes or less to access the user's full data. These conditions require defenders to operate at the scale and speed of AI and AI agents.

  • Defining comprehensive agent protections: Security begins with identity, permissions and clear limits on what every agent may do. Organizations must determine which data, resources, people and other agents each system can access. They also need privacy guardrails across work and home, protection against internal and external threats, and safeguards against oversharing and leakage. Lifecycle controls must cover onboarding and decommissioning, while auditing, observability, governance and compliance establish continuing accountability.

  • Applying AI to security work: Microsoft presents two connected priorities, using AI to secure the world and securing AI itself. Its security models are trained on 84 trillion signals observed every day and tuned on security skills to reduce hallucinations. Generative AI already supports threat investigations, incident reporting and reverse engineering. Agentic systems extend this work into vulnerability management, rapid patching, phishing-alert triage and conditional access, with future agents potentially anticipating attacks and identifying risks as data is created.

  • Governing increasing agent autonomy: AI agents are expected to advance from mimicking human tasks toward creating sub-goals and acting independently while preserving human agency. Because agents learn, plan, act and adapt, static verification cannot provide sufficient assurance throughout their operation. Identity controls, permissions, policies, monitoring and verification must change with the agent and its work. Secure development must also address attackers using AI for vulnerability discovery, malware variants, phishing, social engineering, password cracking and deepfakes.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSA Conference πŸ“š