Alice CEO warns AI agents create infinite security risks
Alice CEO Noam Schwartz warned that connecting autonomous agents to corporate tools creates near-infinite security risks, rendering traditional model safety testing obsolete.

In a recent discussion on the security landscape of generative artificial intelligence, Noam Schwartz, the co-founder and CEO of AI security firm Alice, warned that the rapid deployment of autonomous agents introduces an "almost infinite" risk surface. While AI developers spend months evaluating the safety of base models, Schwartz explained that these safeguards quickly break down once a company integrates those models with external tools like Slack, Gmail, databases, and system credentials.
The shift from text-generating chatbots to action-oriented agents fundamentally alters the threat landscape. Schwartz highlighted extreme scenarios, such as the potential for a criminal organization with just one employee to generate one billion dollars by automating cybercrime through AI. Furthermore, security vulnerabilities like prompt injection may never be fully resolved because attackers only need to find a single successful exploit path, whereas defenders must secure every possible entry point. Schwartz also noted that agents can quietly influence or radicalize other agents over multiple sessions, altering their behavior without traditional software exploits.
For enterprise practitioners, this shift means model-level guardrails are no longer sufficient to guarantee safety. Security must be implemented across every layer of the system, including data access, tool permissions, and organizational policies. Practitioners must actively limit an agent's context by strictly defining what data, memory, and credentials it can access. Continuous testing is also required as prompts, integrations, and models evolve over time. Ultimately, organizations cannot outsource their security to model providers and must establish their own internal boundaries for what constitutes acceptable agent behavior.
This is our own summary of reporting by The Neuron


