Home / Companies / AuthZed / Blog / Post Details
Content Deep Dive

Agentic AI is not Secure

Blog post from AuthZed

Post Details
Company
Date Published
Author
Irit Goihman
Word Count
1,595
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

AI agents are increasingly used in enterprise settings for automation and decision-making, but their autonomous nature introduces security challenges that traditional systems aren't equipped to handle. Communication protocols like the Model Context Protocol (MCP) and Agent-to-Agent (A2A) have been developed to standardize interactions, yet they largely leave authorization as an implementation-specific concern, relying on broad token mechanisms that lack granularity. This can lead to security vulnerabilities such as the Insufficient Granularity of Access Control, privilege persistence, and unauthorized access due to inadequate token management and revocation propagation. The A2A protocol, for example, uses broad JSON-RPC scopes and lacks a defined mechanism for user consent, which can lead to unauthorized data propagation and consent fatigue. While existing protocols recommend best practices for authorization, they do not enforce them, leaving agentic systems potentially unsafe without a centralized authorization layer to manage permissions dynamically and securely.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 6 3,387 723 216 -28%
MCP 6 5,396 444 162 +6%
Multi-agent systems 2 463 131 70 +37%
Kubernetes 1 1,723 279 106 +15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.