If everyone has the same models and the same tools, the edge in agentic AI goes to whoever can safely let their agents do the most. Capability is converging. What still differs is how much of that capability an organization can actually put to work without a person watching every step.

That makes security the most underrated advantage in the agentic landscape. Not security as a brake, but security as the thing that decides how much autonomy you can afford. The winning model is simple to state: humans set policy, goals and acceptable outcomes; a system turns that intent into guardrails, enforces them, and tells you the moment an agent drifts.

Everyone is asking where the edge went

The question is everywhere right now. Harvard Business Review argued in February that when every company can use the same models, organizational context becomes the differentiator. In May it went further, warning of an "agentic convergence trap": firms that feed the same tools the same data end up with the same strategies.

The popular answers are context, proprietary data and judgment. They are right, but incomplete. Context and data are only an edge if you can let an agent act on them. An agent that knows your business perfectly but needs a human to approve every step is a very well-informed intern.

The real question is not what your agents know. It is how far you can let them go.

The autonomy gap is where the value is

Financial services shows where the industry really stands. In a 2026 Cloud Security Alliance survey of 340 financial-services professionals, 62% said their organization already uses AI agents. Yet among those agent users, most still run the classic human-in-the-loop model, and only 5% let agents act independently on critical actions.

62%
already use AI agents
5%
let agents act alone on critical actions
65%
say agent payments need a new authorization model
41%
had a known AI security incident, or cannot say

Source: Cloud Security Alliance, The State of Cloud and AI for Financial Services (2026). Survey of 340 professionals, Jan to Mar 2026.

The same survey shows where the industry expects to go. 85% of respondents believe AI agents will initiate and execute payments on consumers' behalf, and 65% believe that will require an entirely new model for authorization. The existing controls were built around a human being present to confirm each step. Autonomous systems need a different trust model, not more approval screens.

This matters because the return on agents lives in the steps nobody has to sign off on. Every approval gate is a queue, and an agent waiting on a person is capacity you paid for, sitting idle. Autonomy does not make a model smarter. It lets you actually use the intelligence you already have.

Human-in-the-loop does not scale, and it is not as safe as it looks

The default answer to agent risk is to put a person in the loop. It feels responsible. In practice it fails in three ways.

It gets tired. People are poor at sustained vigilance over streams that are almost always fine. The classic Parasuraman experiments found that when automation was reliable, operators' ability to catch its failures fell sharply, and later reviews found experts were no more immune than novices. By the fortieth approval of the day, the reviewer is matching the shape of the dialog box, not reading it.

More approval can mean less safety. A June 2026 study, "Oversight Has a Capacity", modeled reviewers realistically, with attention that degrades under load. Realized safety followed an inverted U: past a certain escalation rate, adding more human checks made the system less safe.

The gate itself is attackable. Researchers recently documented "loopjacking", where what a human approved is not what runs. Real advisories include tool configurations that changed after approval and command arguments that changed between approval and execution.

None of this means humans should leave. It means humans are in the wrong place. Their judgment is being spent on individual actions, when it is worth far more upstream, on deciding what the agent is for and what it must never do.

Humans should set intent, not write guardrails

The fix is to move people up the stack. Nobody writes firewall rules packet by packet, and nobody should be hand-enumerating every tool call an agent might make. People are good at deciding what an agent is for, what outcomes count as success, and what must never happen. Systems are good at turning that into precise, consistent controls.

This is not a fringe view. In a VentureBeat conversation on why trust is the real bottleneck, a Cisco executive described the same order of operations: define the agent's intention first, let that define the policy, then translate the policy into what the agent can actually do.

The result is an agent that runs freely inside boundaries it cannot see past, with people kept informed rather than kept busy. Human judgment moves to where it changes outcomes: setting intent, and responding when reality deviates from it.

What this looks like in practice: a SOC triage agent

Security operations is a useful preview, because SOC teams have lived with alert fatigue for years. Picture an agent that triages incoming alerts, enriches them and takes first-response actions.

Its inputs are hostile by nature. Alert payloads, log lines and ticket text can all carry attacker-controlled content, which makes prompt injection a real path to the agent's tools. Approving every action would bury the analysts. Letting it run unchecked would hand an attacker a privileged operator.

Many teams may be underweighting this. Only 19% of CSA's financial-services respondents ranked prompt injection causing harmful actions as a top AI risk, while 33% flagged excessive permissions or weak authorization for agents. In an agent, those are the same problem: injected text is dangerous precisely because the agent holds permissions it can be talked into misusing.

The intent-first approach handles it differently:

  • The team states intent. Triage and enrich freely; contain a host only within a defined scope; never touch credentials or production configuration.
  • The system derives the controls. Analysis of the agent's code and runtime maps which untrusted inputs can reach which sensitive actions (source-to-sink reachability), and classifies each action by blast radius.
  • Traps are placed where abuse would show. Canary credentials that should never be used, and tripwires on arguments and budgets, turn a hijacked agent into a loud signal instead of a silent breach.
  • Humans see only what matters. Routine work runs. Out-of-policy behavior is blocked or escalated, with the path that led to it.

The analysts stop approving lookups and start reviewing the few events that actually need a decision.

"But who guards the guardrail builder?"

It is the right objection. If a system generates the controls, what stops it from getting them wrong in ways nobody sees?

It is also where most organizations are weakest today. In the CSA survey, 20% of respondents reported a known AI-related security incident, and another 21% could not say whether they had one. Nearly a quarter (23%) named lack of auditability or monitoring for AI-driven actions as a top AI risk. You cannot govern what you cannot see.

The answer is that generated guardrails must be more inspectable than hand-written ones, not less. Every control should trace back to the policy line it came from and the analysis that justified it. Every block, escalation and tripwire should leave a record a person can reconstruct. And deviation should be reported, not quietly suppressed, so the humans who own the policy see where reality and intent part ways.

For regulated industries, this is not optional. The CSA report is explicit that liability stays with the institution: delegating work to an AI agent does not transfer accountability to the model provider or the vendor. When something goes wrong, you will need to show what the agent was allowed to do, why, and what happened. The emerging view in finance is that autonomy grows only as agents' actions become controllable, explainable and reconstructable. Auditability is not a tax on autonomy. It is how autonomy gets approved.

The edge is the autonomy you can afford

Models will keep improving, and everyone will get the improvements at roughly the same time. Tools will keep standardizing. The organizations that pull ahead will be the ones that can hand those capabilities real work, and sleep at night.

The CSA report reaches the same conclusion from the finance side: the institutions that benefit most from AI will not be the slowest movers, but the ones that build controls fast enough to keep the trust of customers and regulators. As it puts it, in financial services "trust remains the business model."

That is a security problem, and it is solved by moving people up the stack: from approving actions to defining outcomes. Stop writing guardrails. Start writing intent.

Sources