Home / Companies / AuthZed / Blog / Post Details
Content Deep Dive

Agentic AI is not Secure

Blog post from AuthZed

Post Details
Company
Date Published
Author
Irit Goihman
Word Count
1,595
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

AI agents are increasingly used in enterprise settings for automation and decision-making, but their autonomous nature introduces security challenges that traditional systems aren't equipped to handle. Communication protocols like the Model Context Protocol (MCP) and Agent-to-Agent (A2A) have been developed to standardize interactions, yet they largely leave authorization as an implementation-specific concern, relying on broad token mechanisms that lack granularity. This can lead to security vulnerabilities such as the Insufficient Granularity of Access Control, privilege persistence, and unauthorized access due to inadequate token management and revocation propagation. The A2A protocol, for example, uses broad JSON-RPC scopes and lacks a defined mechanism for user consent, which can lead to unauthorized data propagation and consent fatigue. While existing protocols recommend best practices for authorization, they do not enforce them, leaving agentic systems potentially unsafe without a centralized authorization layer to manage permissions dynamically and securely.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 6 2,834 598 185 -18%
MCP 6 4,899 392 145 +47%
Multi-agent systems 2 373 107 60 +43%
Kubernetes 1 1,540 251 91 +19%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.