In short
Executive Summary
- AI introduces attack vectors your cybersecurity framework wasn't built for: prompt injection, data poisoning, model theft, and agentic browser exploits
- We stress-tested agentic AI browsers and found 4,500 public dashboards exposed, proving that AI agents browsing without guardrails create massive security holes
- The 5 Categories of AI Risk include misuse for destruction and misuse for power, both of which have direct cybersecurity implications for your organisation
- Traditional security controls must be adapted for AI-specific threats. Bolt-on security for AI systems is like fitting a screen door to a submarine.
Detail
Overview
Your cybersecurity framework was built for a world where humans click links and open attachments. AI changes the threat model fundamentally.
We ran a stress test on agentic AI browsers (the Moltbot test) and found 4,500 public dashboards exposed. That's 4,500 instances where an AI agent browsing the web without guardrails could access sensitive business data, customer information, or operational intelligence. No hacking required. Just an AI agent doing what it was told to do, with no boundaries on where it could go.
This is why we developed the Agentic Browser Governance Framework. AI agents that can browse, click, fill forms, and extract data need the same controls you'd put on a human employee, plus additional controls for speed and scale. An employee might stumble across one exposed dashboard. An AI agent will find all 4,500 in an afternoon.
The threat categories are broader than browser exploits. Prompt injection: attackers manipulate AI inputs to extract data or change outputs. Data poisoning: corrupting training data to make AI produce wrong results. Model theft: extracting proprietary AI models through API abuse. Supply chain attacks: compromised vendor AI updates pushing malicious code.
The 5 Categories of AI Risk framework applies directly here. Misuse for destruction: AI-powered cyberattacks are faster, more targeted, and harder to detect than manual attacks. Misuse for power: organisations (or nation states) that control AI capabilities can concentrate surveillance and intelligence-gathering power. Your organisation is both a potential target and a potential user of these capabilities.
Traditional controls need adaptation. Access controls for AI systems and training data. Input validation to block prompt injection. Encryption for AI workloads in transit and at rest. Monitoring and logging of AI system usage. Vendor security assessment that covers AI-specific risks, not just standard SOC 2 checkboxes. Every month you delay adapting these controls, the attack surface grows.
Commercial impact
Why It Matters for Organisations
AI is the number one business risk in Australia for 2026. Cybersecurity is a major component of that risk, and the intersection of AI and cyber creates threats that neither domain handles well in isolation.
As AI systems make business-critical decisions and process sensitive data, they become high-value targets. A compromised customer service AI can extract personal data at scale. A poisoned pricing model can destroy margins before anyone notices. A stolen proprietary model hands your competitive advantage to a rival.
The agentic browser risk is particularly urgent because it's already here. Organisations deploying AI agents to research competitors, monitor markets, or process web data are creating autonomous systems that interact with the internet. Without the Agentic Browser Governance Framework, those agents operate without boundaries. They'll access whatever they can reach, store whatever they find, and create data trails that violate privacy laws across jurisdictions.
Vendor security adds another layer. Your organisation's security depends on third-party AI vendors whose practices may be opaque. When a vendor breach exposes client data from multiple organisations, clients who negotiated strong contractual security provisions and practised data minimisation have limited exposure. Those who didn't are fully exposed.
For boards, AI security isn't a separate agenda item. It's a component of enterprise risk that needs integration into your existing cybersecurity governance. The board should be asking: have we adapted our security controls for AI-specific threats? Have we assessed agentic AI risks? Are our vendor contracts covering AI security obligations?
Podcast
Listen to how Australian executives are applying AI
Use the podcast to pressure-test the ideas in this article against real operator conversations. Each episode focuses on what leaders are shipping, where the friction is, and what actually lands.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
In practice
Examples or Practical Context
The Moltbot stress test (our agentic browser security assessment) found 4,500 publicly accessible dashboards across Australian organisations. These included real-time sales data, customer databases, operational metrics, and internal KPIs. None required authentication. An AI agent with a simple instruction to "gather competitive intelligence" would have scraped all of them without triggering a single security alert. That test led directly to the Agentic Browser Governance Framework: mandatory URL allowlists, data classification before extraction, audit logging of all agent browsing activity, and human approval gates for sensitive domains.
A customer service AI at a financial institution was compromised through prompt injection. Attackers crafted inputs that made the AI return customer account details in its responses. The AI had legitimate access to customer data for service purposes, but no input filtering to prevent extraction attacks. Post-incident controls included input validation, output screening, and rate limiting that would have prevented the breach.
An AI vendor breach exposed training data from 12 client organisations. Three clients had negotiated data minimisation (only sending essential fields to the vendor) and contractual breach notification within 24 hours. They contained exposure quickly. Nine clients had sent complete customer records to the vendor with standard terms. Their exposure was 10 times larger and took months to assess.
A manufacturer deployed AI predictive maintenance with default vendor access credentials. Internal audit found the vendor could access production data, equipment diagnostics, and operational schedules through the AI system. The credentials were shared across 40+ client installations. Any breach at one client exposed all of them.
What to do
Key Takeaways
- Deploy the Agentic Browser Governance Framework for any AI agents that interact with the web: URL allowlists, data classification, audit logging, human approval gates
- Adapt your cybersecurity framework for AI-specific attacks: prompt injection, data poisoning, model theft, and supply chain compromise
- Assess every AI vendor for security practices that go beyond standard SOC 2: AI-specific threat controls, data minimisation, breach notification
- Map AI security risks against the 5 Categories of AI Risk to ensure board discussions cover the full threat surface
- Integrate AI security into enterprise risk management with board-level reporting, not as a standalone technology concern
Newsletter
Get the Executive Brief each week
Stay ahead of the next board question with short, practical analysis built for Australian executives. It cuts past recycled AI news and focuses on the decisions that matter now.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Assessment
Run the AI Readiness Assessment
Check whether policy, accountability, and compliance are keeping pace with deployment. The assessment scores governance and decision control alongside four other dimensions.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Read next
Behind this page
Where this thinking came from
Where this sits
Explore This Pillar
Next step