Faster attacks and growing workloads are pushing firms to automate more security tasks, but the shift also brings new risks.
AI agents are moving beyond support tools in cybersecurity and financial-crime investigations, according to a new Intel3D report by blockchain security firm CertiK. The paper, shared with CryptoPotato, says newer systems can reason through steps, use tools, gather evidence, act in live environments, and review results with limited human input.
For years, machine-learning systems mainly supported analysts by flagging unusual logins, scoring transactions, and preparing reports. CertiK says newer agents can perform wider tasks, shifting their role from identifying problems to helping execute responses.
AI Agents Take on More Security Tasks
In a security operations center, an agent could investigate a suspicious login by checking device records, location data, and threat feeds before acting. It could suspend an account and record its steps for human review.
CertiK says similar systems are emerging across Web3 security, including contract triage, transaction risk scoring and tracing stolen funds. The firm expects humans to focus more on supervision as agents handle routine investigations.
One reason for this shift is the speed of some attacks. Flash-loan exploits can drain protocols within seconds, while stolen crypto can move across bridges and mixers within hours. This leaves human teams with little time to investigate and respond.
A shortage of cybersecurity and compliance professionals is another factor, while regulatory pressure is increasing workloads. The security firm cites more than $900 million in AML penalties during the first half of 2025, showing the consequences firms can face when controls fail.
AI Autonomy Raises New Risks
CertiK argues that companies should treat autonomous agents as workforce participants rather than ordinary software. Their actions do not remove human accountability, so deploying companies remain responsible for outcomes.
You may also like:
That accountability becomes more important as agents take on tasks across financial and crypto operations. In finance, agents could handle AML tasks, while in crypto, they could detect exploits, trace funds, and monitor transactions.
However, the report highlights risks from incorrect outputs, weaker human scrutiny, and deliberate attacks against AI systems. CertiK recommends records of inputs and actions, clear limits on autonomous decisions, adversarial testing, and a named owner for every agent.
As AI systems gain greater authority over security and compliance tasks, firms will need controls that match their expanded role. CertiK says that without strong oversight, automation could replace familiar problems with failures that are harder to explain.