When Cisco ran 6,986 multi-turn assaults in opposition to 15 flagship fashions, attackers who tailored throughout the dialog broke by as typically as 88.3% of the time. Amy Chang, Cisco's head of AI risk intelligence and safety analysis, introduced that discovering to the agentic safety panel at VB Rework 2026; the quantity ought to fear anybody nonetheless operating single-turn red-teaming applications.
VentureBeat's June 2026 Pulse survey of 107 enterprise respondents explains why the room was full. Greater than half, 54%, have already had a confirmed agent safety incident (18%) or a near-miss caught earlier than hurt (36%). Simply 32% give each agent its personal scoped, managed id, and fewer nonetheless, 30%, isolate their highest-risk brokers in sandboxes. Supplier-native and hyperscaler controls stay the first agent safety layer at 82% of firms surveyed. The world's largest safety distributors have executed the identical math.
Palo Alto Networks closed its $25 billion acquisition of CyberArk in February, CrowdStrike agreed in January to pay $740 million for SGNL, and Cisco introduced its intent to accumulate Astrix Safety for a reported $400 million, all of it aimed on the id and isolation layer most enterprises haven’t completed constructing.
Chang got here to the panel with nearly 20 years of expertise spanning cybersecurity operations, authorities, and the army. She ran world cybersecurity operations as an government director at JPMorgan Chase, the place she led the financial institution's cyber risk intelligence groups, and served as a senior staffer on the Home Overseas Affairs Committee and as a U.S. Navy Reserve officer. She additionally teaches cybersecurity and rising threats as adjunct school on the Middlebury Institute of Worldwide Research.
Chang's 88.3% quantity comes from a research she co-authored with Nicholas Conley, constructed on 30,090 single-turn prompts and 6,986 multi-turn assaults in opposition to these 15 closed and proprietary flagship fashions. Multi-turn success charges ranged from 7.89% to 88.3%, each mannequin examined confirmed non-trivial multi-turn publicity, and the 2 testing types didn’t even rank the fashions in the identical order. Cisco publishes adversarial analysis indicators for what’s now 105 fashions on its LLM Safety Leaderboard, she informed the viewers.
"When you don't perceive how fashions are prone to various kinds of assaults, then you might be unable to account for a way that mannequin that’s powering your agent, that’s powering your software, to know the place these failure factors are," Chang mentioned. Single-turn testing is the one-shot malicious immediate, she defined, whereas extending an assault into an extended dialog "is extra practical of how we are literally participating with our fashions, with our brokers, with our purposes." That longer arc surfaces dangerous outputs and misaligned behaviors {that a} snapshot by no means catches.
Cisco has pushed the testing itself into agentic territory. Chang described a framework the place brokers assess a deployment situation, develop related assaults, choose whether or not they’re price pursuing, execute them, and consider their very own success. What shocked her most, in any case that sophistication, was how easy the defensive reply stays. "The reply remains to be that it's fairly easy," she mentioned. "You don't should get tremendous artistic. You simply want to consider really what are the basics and fundamentals of what I'm attempting to safe in my group."
Her place to begin for CISOs starting agentic deployments is Cisco's Built-in AI Safety and Security Framework, which she mentioned "stipulates all of the ways in which AI will be compromised throughout the AI lifecycle" from modality by provide chain. From there, groups can work backward from actual incidents, hint how every assault was achieved, and use the framework to construct a method with the fitting protection and mitigations.
Heather Ceylan, the CISO of Field, sees the identical hole from the defender's aspect. "A number of what you see on the market with agent pink teaming is simply single-turn, and that's not how individuals are really interacting with AI day-to-day," she informed the viewers. Field now simulates multi-turn adversaries with brokers that suppose like an attacker and iterate try after try to hijack the goal. "It’s important to stress check your brokers as a result of in any other case you don't know in case your execution controls are actually working as you supposed."
Field deployed brokers inside its safety operations middle a couple of yr in the past, beginning with human approval required for each motion, and belief constructed rapidly sufficient that analysts shifted into monitoring mode. Then the agent made one mistake, and each little bit of that accrued belief vanished. "They needed to begin once more," she mentioned. "So I feel that that monitoring piece is so vital. Even when you're not gonna have a human within the loop, issues change, fashions change, and we are able to't management how the fashions change and interpret issues."
Rajesh Parekh, VP of AI and ML at Intuit, introduced the builder's perspective. Parekh led large-scale laptop imaginative and prescient and ML programs powering Google's Maps and Geo merchandise earlier than becoming a member of Intuit, and holds a doctorate in laptop science.
Three layers versus an working system
Ceylan described Field's method as three concentric layers. Permissioning comes first, so the agent by no means accesses extra content material than the human who invoked it. Ephemeral sandbox environments spin up for every agent activity, containing the blast radius if an agent will get hijacked, and runtime execution management restricts the agent's device calls to solely these related to the duty at hand. "If you need an agent to summarize a doc for you, when you’ve got a immediate injection that got here in that claims ahead this to maliciousattacker at area.com, it could actually't try this," Ceylan mentioned. "That motion in that device name will not be even in its vocabulary."
She labeled agent actions into three oversight classes. Actions that aren’t delicate, like learn and summarize, want no human within the loop. Reasonably delicate actions skip human approval however get logged and monitored, whereas harmful actions like mass deletion of information all the time require a human. "Issues are gonna shift between these three classes fairly a bit," she acknowledged, "however setting these varieties of classes up entrance permits you to have a principled framework."
Somewhat than layering controls onto brokers one after the other, Intuit has constructed a central platform known as GenOS, quick for generative AI working system, which abstracts safety, danger, and fraud modeling so particular person agent builders by no means reinvent safety. "Permissioning will not be about giving entry to AI," Parekh mentioned. "As an alternative, it’s defining very tightly scoped and clearly auditable authority to the agent to carry out very particular duties." Intuit developed from brokers inheriting person permissions to every agent carrying its personal id, and the corporate is now investigating mid-session permission modifications tied to the precise activity underway.
Parekh calls the broader mannequin an AI-powered knowledgeable platform, one the place the human knowledgeable is constructed into the belief structure quite than bolted on as a gate. "The paradigm that we’re pursuing is the place the person, the AI agent, and the human knowledgeable are collaborating to unravel the person downside," he mentioned.
The top of human code overview
Ceylan took on the stress between safety testing and improvement velocity with out hedging. "The times of safe code evaluations the place a human's wanting on the code and we're safety structure evaluations, design docs, these are executed," she mentioned. "When you maintain attempting to do safety that manner, you're gonna get left behind." Field is constructing towards a completely agentic improvement lifecycle the place brokers overview design paperwork, apply safety necessities, and overview the code for vulnerabilities. "I'm very optimistic that we are going to get to a degree the place we are going to write code with out safety vulnerabilities as a result of brokers and the fashions are going to get so good at writing code with out vulnerabilities," she mentioned. "We're nonetheless a good distance away from that."
Her recommendation for improvement groups skips the superior AI ideas completely and returns to fundamentals that predate brokers. "It comes all the way down to very primary least privilege entry," she mentioned. "When you begin giving your brokers overly broad permissions firstly, it's actually onerous to comb that again and construct an infrastructure that permits for these ephemeral credentials and solely these narrowly scoped duties."
Parekh defined why the pink teaming floor has expanded so rapidly. "These brokers have expertise, and expertise might turn into vulnerabilities," he mentioned. "Brokers have entry to sure knowledge, they’ve entry to instruments, and there may very well be threats which can be lurking inside these instruments as nicely. So out of the blue the blast radius of the malicious code or the intent will increase dramatically." When Intuit identifies frequent vulnerability patterns from its handbook pink teaming workout routines, it automates these assessments again into the GenOS harness so future brokers inherit safety and pink teamers keep centered on new risk vectors. Runtime scanning of prompts and responses provides a closing layer that may cease a suspect response and escalate to a human knowledgeable, he mentioned.
"That you must constantly check to make sure that these stay strong to the protections that you’ve constructed, in addition to to account for any form of drift or some other varieties of dependencies that you simply introduce into your situation that may create novel vulnerabilities," he mentioned.
Intent versus likelihood
An viewers query about intent detection set off the sharpest trade of the session. Ceylan famous that when Field's personal agent operates, the system all the time is aware of the person's intent as a result of it controls the immediate, which implies guardrails and tool-call restrictions will be engineered round it. The more durable problem, which she admitted Field remains to be attempting to unravel, arrives when exterior brokers join and the context behind the request is opaque.
That trade uncovered a break up operating by the broader trade. Mastercard, within the hearth chat instantly previous the panel, got here down on the aspect of quantifying intent, constructing an open-source framework to propagate it as a normal as a result of advanced B2B procurement can not work with out that belief. Endpoint safety CTOs, in briefings with VentureBeat, have gone the opposite manner, saying they’ll guess on likelihood quite than intent inference for manufacturing workloads. Chang defined why fashions, as they’re educated in the present day, can not reliably derive intent from a immediate, which is why deterministic controls and behavioral proxies stay obligatory. Ceylan agreed that each are required. "When you're not doing something deterministic, you're actually relying closely on that intent, and I haven't seen applications which can be there but," she mentioned.
Ceylan's story about belief collapsing after a single agent mistake landed because the panel's most memorable second as a result of enterprise agentic safety will not be an issue that will get solved and stays solved. Fashions change, permissions drift, and adversaries adapt throughout multi-turn conversations that snapshot assessments by no means seize.
For the 82% of enterprises counting on provider-native controls as their major safety layer, and the 59% purchasing for agent safety tooling over the following 12 months, the panel's takeaway was blunt. Take a look at the best way attackers assault, throughout full conversations and constantly, or discover out in manufacturing what your single-turn pink teaming missed.

