Insights & Data

Agentic AI Has Moved Enterprise Security From Perimeters to Everyday Endpoints

Agentic AI Has Moved Enterprise Security From Perimeters to Everyday Endpoints
Share

AI agents are no longer confined to answering questions. They can read files, execute commands, modify code and trigger business processes with a user’s privileges.

A CrowdStrike white paper argues that this shift makes the endpoint the new security control point. For African enterprises adopting AI quickly, the deeper lesson is vendor-neutral: productivity gains must be matched by visibility, least privilege, data controls and governance at the point where automated actions occur.

AI Security Reaches the Execution Layer

The newest enterprise risk may look like a helpful colleague.

  • An AI coding assistant can inspect a repository and run shell commands.
  • A desktop agent can reorganise folders and draft reports from internal documents.
  • An open-source assistant can connect to email, browsers, cloud tools and business systems.

Each capability saves time. Each also converts a prompt into an action taken inside a real operating environment.

CrowdStrike’s 2026 white paper, Securing AI Where It Executes: The Endpoint Is the New Control Point for AI Agent Security, examines this shift.

The paper is written to position CrowdStrike’s Falcon platform, so its product claims are vendor claims. Its broader diagnosis, however, is relevant to banks, telecoms companies, governments, health providers and growing businesses across Africa:

  • AI governance cannot stop at an acceptable use policy when agents have permission to touch files, identities, code and data.

Autonomy Turns Helpful Software Into Active Risk

Traditional generative AI mainly produced content for a person to review. Agentic systems can plan and execute multiple steps. The distinction is the difference between suggesting a command and running it, or summarising a document and moving the original file.

The white paper examines Claude Code, Claude Cowork and OpenClaw as three examples.

  • Claude Code can operate across codebases, repositories and development pipelines.
  • Cowork can work with user-approved desktop folders and browser workflows.
  • OpenClaw can connect models with more than 100 skill extensions and local services.

The same autonomy creates new routes for prompt injection, malicious plugins, excessive permissions and silent data movement.

  • The document cites an identified Claude Code consent bypass rated 8.7 on the CVSS scale.
  • It also says OpenClaw passed 100,000 GitHub stars within weeks and cites third-party research indicating use on work devices within 22% of one security vendor’s customer base.

Three Agent Models Expose Different Control Gaps

Security teams have often focused on networks, login controls and approved software. Agentic activity cuts across those layers.

  • A legitimate user may install an approved tool, then grant it broad access.
  • A malicious instruction may arrive through a document, webpage, plugin or repository rather than a conventional executable.

The endpoint provides useful evidence because it records what actually happened: the parent process, child processes, file access, registry changes, network connections and commands.

However, endpoint telemetry alone is not enough.

  • Organisations also need identity context, prompt-level protection, data loss prevention, software supply chain checks and controls across browsers, software services and cloud workloads.

The paper reports visibility across more than 1,800 AI applications and nearly 160 million unique application instances through CrowdStrike telemetry.

  • Those figures illustrate the scale claimed by one provider, not an independent measure of the entire market.

They nevertheless underline how quickly AI use can outgrow manual inventories.

Endpoint Visibility Can Enable Safer AI Adoption

The goal of stronger controls is not to stop useful automation.

  • It is to make adoption governable.
  • If a company can see which agents are installed, what data they can reach and which actions they perform. 
  • It can distinguish legitimate work from suspicious behaviour and respond before a small error becomes a systemic incident.

This is especially relevant in African markets where organisations may be digitising rapidly while security teams, budgets and specialist talent remain stretched.

  • A smaller institution cannot afford a separate control system for every model or agent.
  • It needs a consistent baseline covering inventory, permissions, logging, review and response.

Good governance can also increase confidence among customers, regulators and boards.

  • Clear audit trails make it easier to investigate an incident, verify compliance and decide which workflows are safe to automate.
  • Security becomes an enabler when it gives leaders evidence for a measured yes rather than forcing a blanket no.

Enterprises Must Govern Privilege, Prompts and Processes

Security leaders should first discover the AI footprint across employee devices and development environments.

  • The inventory should include applications, local models, agents, extensions, Model Context Protocol servers and integrations.
  • Ownership and business purpose must be recorded.

Next, access should follow the principle of least privilege.

  • Agents should receive only the folders, credentials, tools and network destinations required for a task.
  • High-impact actions, including deletion, payment, production deployment or bulk data transfer, should require human approval.
  • Prompts and responses involving sensitive workflows should be monitored within legal and privacy limits.

Boards and regulators should ask operational questions.

  • Can the organisation reconstruct an agent’s actions?
  • Does incident response cover an autonomous process acting through a valid identity?
  • Are new skills reviewed before installation?
  • Can security teams contain an endpoint without losing the evidence needed for investigation? These tests turn principles into readiness.

Path Forward – Secure Actions Where Agents Execute

African enterprises should treat agentic AI as privileged software, not merely another chat interface.

Inventory, scoped permissions, runtime monitoring and human approval for consequential actions are now basic controls.

The opportunity is significant, but trust will depend on evidence. Organisations that can explain what their agents did, why they did it and how exceptions were contained will adopt automation with greater confidence.

More Insights & Data

Start typing to search...