Vibhum Dubey, a cybersecurity researcher and red teamer, said the shift comes when models are embedded into operational systems. “An agent that can read an email, inspect a repository, access a cloud environment… becomes part of the enterprise attack surface,” he said, pointing to how multiple permitted actions can be chained together.
The disclosures also highlight how models interact with memory and reusable context in ways that can influence future behavior. Analysts said this introduces risks such as persistent, unauthorized changes to an agent’s behavior across sessions, particularly when context is reused without validation.
Kaushik said organizations should focus on how systems are designed around the model, not just the model itself. The key question, she said, is whether the surrounding architecture can “prevent, detect and contain an unsafe action.”