Enterprise AI adoption has moved faster than enterprise security has adapted. As organizations deploy autonomous AI agents to handle everything from customer service workflows to internal IT operations, a structural problem is emerging: these systems operate at a speed and complexity that conventional security monitoring was never built to handle.
Forrester Research is among the latest voices raising this concern directly with chief information security officers. The firm’s analysts argue that multi-agent AI deployments — where multiple autonomous systems collaborate, delegate tasks, and execute actions with limited human intervention — are creating audit blind spots that security teams cannot see into with their existing tooling.
What Makes Multi-Agent Deployments Different
Traditional enterprise software operates on well-understood, deterministic logic. When something goes wrong, there is a transaction log, an API call record, or a user action that can be traced. Security information and event management platforms — SIEMs — were built around this model. They ingest structured log data, correlate events against known signatures, and surface anomalies for human review.
Autonomous AI agents break most of these assumptions. A single agent can spawn sub-agents, pass instructions through natural language rather than structured commands, access multiple enterprise systems within a single workflow, and complete a chain of consequential actions before a human has had any opportunity to review them. The orchestration layer — where agents coordinate with one another — is often opaque even to the teams that deployed the system.
The result is an environment where significant actions are taken, but the trail of causation is difficult to reconstruct. Who authorized the action? Which agent initiated it? What instructions were passed between systems, and were those instructions tampered with in transit? These are questions that existing observability tooling frequently cannot answer.
The Prompt Injection Threat
One of the more acute risks embedded in multi-agent architectures is prompt injection — the manipulation of an agent’s inputs to redirect its behavior in ways its operators did not intend. Unlike traditional injection attacks, which exploit predictable software logic, prompt injection exploits the inherent flexibility of language models. An attacker who can influence data that an agent will read — through a poisoned document, a manipulated web page, or a crafted email — may be able to redirect that agent’s downstream actions entirely.
In a multi-agent system, this risk compounds. A compromised instruction passed to one agent can propagate through an entire orchestration chain, with each subsequent agent acting in good faith on corrupted inputs. By the time the effects manifest in observable system behavior, the malicious instruction may be several layers removed from any obvious point of entry.
This is not a theoretical concern. Security researchers have demonstrated prompt injection attacks against publicly available agent frameworks, and the attack surface grows as enterprises integrate agents with more privileged systems — internal databases, communication platforms, financial tooling, and code repositories.
What CISOs Are Working With
The practical challenge for security leaders is that the market for agent-specific observability and security tooling is still immature. Established SIEM vendors are beginning to adapt their platforms, and a cohort of newer companies are building purpose-built solutions for AI agent monitoring. But the gap between what enterprises are deploying and what security teams can actually see remains significant.
Several structural issues make this harder to close quickly. Agents often communicate through natural language rather than structured data formats, which limits how much traditional log parsers can extract. Orchestration frameworks vary considerably across vendors, meaning there is no standardized log schema for security teams to work from. And the pace of deployment means that by the time an organization’s security team has mapped one agent architecture, new systems may already be in production.
Forrester’s position is that CISOs need to be included earlier in AI deployment decisions — before agents are in production rather than after. That means establishing governance frameworks that require agent activity logging as a baseline, defining what constitutes an auditable action within agentic workflows, and ensuring that the teams building and deploying agents are accountable to security standards, not just performance metrics.
Guardrails as Infrastructure, Not Afterthought
The deeper issue surfaced by Forrester’s analysis is a governance one. Many organizations have treated AI agents as productivity tools rather than as autonomous actors with access to sensitive systems and the ability to take consequential actions. That framing shapes how risk is assessed — and in most cases, security and compliance teams have been brought in too late to shape agent architecture decisions.
What’s needed is a shift in how guardrails are conceptualized. Rather than layering controls onto agent systems after the fact, organizations need to build observability and constraint mechanisms into the agent design process itself. That includes defining the scope of what agents are authorized to do, ensuring that cross-agent communications are logged in a format security tools can consume, and establishing human-in-the-loop checkpoints for high-consequence actions.
None of this is simple to execute, particularly for enterprises that have already deployed agents at scale without these structures in place. But the Forrester analysis makes the cost of inaction clear: as agent deployments grow more complex and more deeply integrated into enterprise operations, the audit blind spot grows with them.
For Canadian organizations navigating both AI adoption pressure and an evolving regulatory environment around AI accountability, this is a problem that will not wait for the tooling to catch up on its own.
Related InsightTrack Analysis
- AI Agent Orchestration Frameworks for Workflow Automation
- Agentic AI Benefits and Risks for Canadian Enterprises
- Local AI Deployment in Canada: Business Benefits

