Forrester Research has issued a direct warning to chief information security officers: AI agents are not just a productivity tool — they are an expanding attack surface that existing security architectures were not built to contain. The implications are significant for any enterprise running agentic workloads. For Canadian organizations, they are compounded by a policy environment that is still catching up to even conventional AI risk, let alone the autonomous variety.
What Makes Agents Categorically Different
The core problem Forrester identifies is autonomy. Unlike a static large language model responding to a prompt, AI agents are designed to take sequences of actions — browsing the web, calling APIs, writing and executing code, managing files, and interacting with external services — often with minimal human checkpoints. That capability profile fundamentally changes the threat model.
Security teams are accustomed to defending against threats that target humans or known software vulnerabilities. Agents introduce a third category: systems that can be manipulated through their inputs to act against the interests of the organization that deployed them. Prompt injection — where malicious content embedded in external data hijacks an agent’s instruction set — is one of the most immediate vectors. An agent tasked with summarizing customer emails or browsing supplier websites can be covertly redirected by adversarial content it encounters in the wild.
Forrester also flags privilege escalation as a structural concern. Agents are frequently granted broad permissions to be useful — access to internal databases, communication platforms, code repositories. When those agents are compromised or behave unexpectedly, the blast radius reflects the permissions they were given, not just the sophistication of the attack.
The Canadian Policy Mismatch
Ottawa has been advancing its AI governance posture over the past several years. The now-shelved Bill C-27 included the Artificial Intelligence and Data Act, which would have established baseline obligations for high-impact AI systems. Voluntary codes of conduct have been introduced in the interim. The Canadian Centre for Cyber Security publishes guidance on AI security. These are not nothing — but they share a common design assumption: that AI systems are tools operated by humans who remain in the decisional loop.
Agentic AI disrupts that assumption in ways current frameworks do not address. When an autonomous agent makes a decision that results in a data breach, a compliance violation, or an unauthorized transaction, existing Canadian policy offers no clear answer to several basic questions: Who is liable — the CISO, the AI vendor, the developer who configured the agent? What constitutes an incident under reporting obligations if the agent’s action was technically within its granted permissions? How should organizations document and audit decisions made by systems that generate no traditional logs?
These are not hypothetical edge cases. They are foreseeable operational realities for any Canadian financial institution, health authority, or federal contractor that deploys agentic systems at scale — which, given the pace of enterprise AI adoption, means within the next 12 to 24 months for many organizations.
Incident Response for Systems That Don’t Stop
Traditional incident response assumes a human attacker or a piece of malware that can be isolated and removed. Agents complicate containment. An agent that has been manipulated through prompt injection may continue executing its task queue — sending emails, modifying records, making API calls — while a security team is still determining whether an incident has occurred. The speed of autonomous execution and the breadth of agent permissions can mean that by the time a response is mounted, the actionable window has already closed.
Canadian CISOs need playbooks that account for this. That means pre-defining kill switches and revocation protocols before agents are deployed, not after an incident. It means treating agent credentials with the same scrutiny applied to privileged human accounts — ideally through just-in-time access provisioning that limits what an agent can touch at any given moment. And it means building monitoring infrastructure capable of detecting anomalous agent behaviour in near-real time, which is a non-trivial engineering challenge given how varied normal agent behaviour can be.
What CISOs Should Be Doing Now
In the absence of clear regulatory guidance, the burden falls on security leadership to build internal accountability structures. A few priorities stand out from the Forrester analysis and the broader threat landscape.
- Establish an agent inventory. Organizations frequently lack visibility into which agentic systems are running, what permissions they hold, and who owns accountability for their behaviour. A registry is a prerequisite for governance.
- Apply least-privilege rigorously. Agents should be scoped to the minimum permissions required for a defined task. Broad access grants made for convenience become liability at the moment of compromise.
- Implement input and output validation. Agents that interact with external content — web pages, emails, documents — need filtering layers that can detect and neutralize prompt injection attempts before they reach the model.
- Define incident thresholds explicitly. Boards and legal teams need to agree in advance on what constitutes a reportable incident when an agent is involved, because the ambiguity will not resolve itself in the middle of a crisis.
- Engage with Ottawa proactively. Canadian industry associations and individual organizations have standing to contribute to ongoing AI governance consultations. The frameworks being written now will govern agentic deployments for years — security perspectives need to be in the room.
The Governance Gap Is Closing — Slowly
The EU AI Act, now in force, includes provisions relevant to automated decision-making systems, though its application to agentic architectures is still being interpreted. The United States has seen executive-level attention to AI security through NIST’s AI Risk Management Framework. Canada, post-C-27, is in a more uncertain position — the policy pipeline is active but not yet delivering binding obligations.
That gap is not permanent, but it is real, and it is the environment in which Canadian CISOs are making deployment decisions today. Forrester’s warning is timely: the organizations that treat agentic AI as a security-first infrastructure problem — not just an efficiency opportunity — will be better positioned when incidents occur and when regulators eventually arrive with requirements. Both outcomes are a matter of when, not if.
Related InsightTrack Analysis
- AI Agent Orchestration Frameworks for Workflow Automation
- Agentic AI Benefits and Risks for Canadian Enterprises
- Local AI Deployment in Canada: Business Benefits

