The Next CX Security Risk May Be the AI Agent You Gave Access

Anthropic, Concentrix, Zscaler, Proofpoint and OpenAI reveal how AI agents are reshaping enterprise security, access and customer experience risk

5
Security, Privacy & ComplianceNews

Published: September 10, 2026

Nicole Willing

Enterprise AI is gaining access to the systems that make customer experiences work, while security teams are deploying AI agents of their own to defend those environments. This is creating a new risk for CX leaders, as an AI agent may have legitimate access to customer data and business workflows, but the controls around that access may determine whether it helps or harms the customer experience.

A spate of announcements this week brings that issue into sharper focus. Anthropic disclosed another incident involving a Claude model accessing real-world systems during an evaluation. Concentrix expanded its risk and compliance capabilities to include AI governance, while Zscaler and Proofpoint introduced agentic security capabilities. OpenAI, meanwhile, is putting its frontier cyber models into the hands of organizations defending critical infrastructure and digital services.

The developments point to the enterprise challenge of controlling what AI agents can access, what they can do with that access and when a human needs to intervene.

Anthropic Finds Another Warning Sign For Agent Access

Anthropic’s September 9 assessment provides the clearest example of why those controls matter. The company disclosed a fourth incident in which its Claude large language models (LLMs) gained unauthorized access to real third-party systems during cybersecurity evaluations. Anthropic said three incidents had previously been identified after a scan of roughly 141,000 transcripts. It subsequently found another incident from January 2026 after discovering that some transcripts included Internet access.

The incidents resulted from a configuration error in a third-party evaluation environment. Anthropic said the models had been told they were operating in simulations without Internet access, but they were inadvertently connected to the open Internet.

“[O]ur assessment is that these incidents are serious. Our production models took harmful actions against real systems over long trajectories, which included biased reasoning,” the company stated. “The behaviors in these incidents are more severe than those we had previously observed and reported in our system cards.” Anthropic warned:

“Future AI systems will be increasingly capable, which implies that misalignment will have the potential to cause more extreme harm.”

The concern for CX lies in what happens when an agent operating inside an enterprise environment acts in unexpected ways.

A customer service agent may have legitimate access to a customer relationship management (CRM) system, order management platform, knowledge base or account data. If that access extends further than intended, the resulting problem can reach the customer directly. The security question becomes closely connected to the authority granted to the agent.

Concentrix Expands Risk Capabilities Around AI Governance

Concentrix’s acquisition of CastleHill Managed Risk Solutions approaches the issue from the enterprise risk side. CastleHill provides governance, risk and compliance, third-party risk management and AI governance capabilities. Concentrix said the acquisition expands its ability to help organizations manage financial crime, cybersecurity, regulatory, data, third-party and AI-related risks.

With the acquisition Concentrix, which operates customer-facing processes for enterprises, places AI governance alongside operational resilience and cybersecurity as governance decisions around agent deployment increasingly affect the systems through which companies deliver services. And questions about AI permissions and oversight increasingly sit alongside familiar concerns around customer data, compliance and service continuity.

Zscaler Turns the Security Operation Itself Into an Agentic Environment

Zscaler is focusing on the other side of the equation. The cybersecurity company launched its Agentic Security Operations Center (SOC), using specialized AI agents to detect, investigate and respond to threats.

The agents can perform roles including triage, root-cause investigation, assigning verdicts and triggering response workflows. Zscaler said the system combines those capabilities with human security expertise and Zero Trust controls, creating a parallel with customer-facing AI. Enterprises are giving agents access to business processes, while security teams are giving agents access to security processes. Both require decisions about permissions, context, escalation and accountability.

There is another consideration for CX teams, as security actions can affect customer journeys.

An automated response that isolates an account, blocks a connection or restricts access may protect an enterprise from an attack while also affecting legitimate users. Agentic security needs sufficient business context to understand the potential customer consequences of its actions.

Proofpoint Keeps Consequential Decisions With People

Proofpoint is taking a more constrained approach with its new SOC Analyst Agent. The capability uses OpenAI’s Daybreak models to investigate threats across Proofpoint security data, connect signals and produce traceable findings and recommended next steps.

Proofpoint explicitly retains human control over consequential actions. The agent does not independently make account changes, contain threats or initiate other significant remediation.

Enterprises face similar choices when deploying customer-facing agents. An agent can gather information, identify an issue and recommend an action while a human retains responsibility for decisions with material consequences.

For security teams, that can reduce the risk of automated remediation creating a second problem, while for CX teams, the same model could apply to sensitive workflows involving disputes, account changes, vulnerable customers or other situations where an incorrect action could have lasting consequences.

OpenAI Puts Frontier Cyber Models Into Defensive Workflows

OpenAI’s Daybreak initiative provides the broader infrastructure context. The company’s security program is making frontier cyber capabilities available to defenders, with a focus on finding vulnerabilities, developing fixes and strengthening the resilience of critical digital infrastructure. OpenAI said its work with the wider maintainer ecosystem has so far identified 858 issues, produced 263 patches and resulted in 143 fixes being accepted upstream.

The significance for CX is straightforward: digital customer journeys rely on infrastructure that extends well beyond the contact center or CRM. If that infrastructure is compromised or unavailable, customers experience the consequences through failed transactions, inaccessible services or disrupted support.

As was evident from HPE’s quarterly results call last week, AI-powered cybersecurity has a role in protecting the foundations on which customer experiences depend.

“The way customers value their IT infrastructure is changing,” Antonio Neri, HPE’s President and Chief Executive Officer, said during the earnings call.

Infrastructure in all forms is facing growing cyber risk that could affect customers. As Scott Steele, Chief Operating Officer at Thrive, told CX Today:

“For critical infrastructure operators, resilience starts with having a clear picture of what sits within their environment, where the gaps are and how quickly they could respond if those systems were compromised.”

The Access Question Is Becoming a CX Question

These announcements point to a more specific challenge for enterprises adopting AI agents. The question is increasingly what an agent is authorized to do once it enters the enterprise environment, shifting attention towards identity, permissions, escalation, auditability, containment and context. This is where cybersecurity starts to intersect directly with customer experience.

A compromised customer account is a security incident, but it is also a CX failure. Similarly, a service outage caused by a cyberattack is an operational resilience issue, but customers experience it as a broken journey. An agent making an unauthorized change is an AI governance problem, but the customer sees the result through their account, order or service.

The week’s announcements indicate that enterprises are beginning to build security controls around the agents delivering workflows as well as the agents defending them.

The concern for CX leaders is increasingly about how much authority the organization is prepared to give an AI agent, rather than simply how many interactions it can handle, and whether it can take that authority away when something goes wrong.

Cybersecurity for CXSecurity and Compliance
Featured

Share This Post