A fresh report champions treating artificial intelligence agents like actual workforce members, pointing out that they have shifted from simply generating passive threat warnings to executing autonomous actions.
Liability Remains With Human Managers#
Agentic artificial intelligence is fundamentally transforming cybersecurity, anti-money laundering, and regulatory compliance, turning supportive toolkits into autonomous operational actors. Moving past passive alert filtering, these systems carry out multi-step reasoning, integrate external APIs, and execute live remediation measures with minimal human intervention.
Drawing from a fresh Web3 security report by Certik, organizations must manage agentic AI like autonomous workforce members by assigning them clear roles, bounded authority, and strict human supervisory accountability.
Certik contends that this shift is essential as artificial intelligence advances from simple threat detection toward executing end-to-end incident responses, patch creations, and transaction monitoring. Still, because deployment managers carry complete legal and operational liability, Certik stresses that organizations must operate AI agents under bounded authority, explicit escalation protocols, and named human oversight.
Certik’s advocacy for a workforce framework arrives amid escalating machine-speed attacks, a chronic worldwide cybersecurity talent shortage, and soaring anti-money laundering penalties that crossed $900 million during the first half of 2025 alone.
Although experts hail artificial intelligence as a vital defense against cybercrime, critics counter that bad actors are leveraging identical capabilities, neutralizing those security gains. Because cybercriminals operate faster than legacy enforcement and corporate defenders, their adoption of AI agents will inevitably accelerate the frequency, speed, and sophistication of exploits. Compounding this challenge is the classic asymmetry of cybersecurity: attackers need only one open vector to succeed, whereas defenders must secure every boundary.
Defenders Keep Their Home-Field Advantage#
Natalie Newson, a senior blockchain investigator at Certik, rejects the notion that defenders are perpetually playing catch-up. While acknowledging that artificial intelligence indeed strengthens threat actors, she stresses that defenders hold a critical edge attackers can never replicate: home-field advantage.
“We get to see the code before it ships, we know what normal behavior looks like for a protocol, and we can run the same AI-driven exploit discovery against our own systems first. In Web3 especially, everything an attacker does is on a public ledger, so their reconnaissance, funding and test transactions all leave a trail that machines are very good at reading,”
Stay in the loop
Get crypto news before the market moves
Join thousands of investors who read our daily briefing.
No spam. Unsubscribe anytime.
Even so, Newson warns that periodic defense cannot withstand a continuous offense. To survive, organizations must transform security from static checkpoints into dynamic systems that match the speed of incoming threats.
Adversaries also capitalize on zero regulatory friction, launching attacks instantly without being weighed down by compliance overhead or risk controls. Although Newson concedes that this grants attackers an initial head start, she insists that speed alone guarantees no ultimate success.
“An attacker can move at machine speed, but they still have to go through the chain to get paid, and that’s where monitoring and circuit breakers sit,” Newson argued.
She explained that real-time tracking of pending transactions enables automated systems to catch unfolding exploits and halt contracts instantly, containing breaches without waiting for human input. Backing these tools with strict guardrails while layering them alongside traditional audits and formal verification alters the threat economics by forcing attackers to outpace machines rather than humans.
Mandatory Audits Proposed for AI Reasoning#
At the same time, Certik’s report concludes that although agentic artificial intelligence has crossed the threshold from aiding decisions to executing them, adopting these tools without proportional governance simply trades manual capacity limits for complex systemic risks.
To tackle this challenge, the report urges organizations to clearly separate agent execution from human supervision across every organizational chart and job description. Additionally, it champions making the continuous recording and auditing of an AI agent’s internal reasoning logs a mandatory compliance discipline.



