While the momentum surrounding AI and agents has been nearly unstoppable, the Hugging Face Attack has forced the industry and enthusiasts to take a step back and reevaluate. We all see tons of value in AI assistants, chatbots, LLMs, agents, and many of the other new platforms and products based off this new paradigm in technology. It's likely the individuals who read this post will continue to use them more and more. How, then, do we actually use them without opening ourselves up to real dangers?
In our case, we foresaw and are continuing to see week by week that the agentic commerce space is going to be a real use case of agents. When agents are tasked with making purchases, the danger is immediately obvious: you don't want a machine to have access to your actual payment credentials. Even with payment credentials that are for a specific amount and have a purpose with the request, a responsible owner of an agent would want to manually approve transactions over a certain amount. Companies with well-defined spending policies maintain a similar protocol of large transactions requiring an approval from someone who didn't propose the purchase. Protocols like these are useful and exist within companies for good reason. There's every reason to see that this control and other external ones ought to extend to agentic work too.
In agentic commerce, external safeguards like Authoryze can handle a wide array of vulnerabilities, but what about the safeguards within the agent itself? Risks still exist from attack avenues as complex as prompt injection and agent swarms or as simple as stolen login credentials and social engineering of the agent's owner. Some of these have simple fixes such as strong passwords, passkeys, and segregated access, however, some of these require advanced solutions. Tactics such as segregating responsibilities across a larger number of agents can keep individual agents siloed and reduce the risk of a swarm spawning that can run wild. External risk mitigation was what drove us to build Authoryze, but internal risk mitigation from the owner is as important.
We're in the infancy of this still. Risks will only become more sophisticated and expansive. This means the external solutions will continue to evolve and properly reflect the market's need. On the owner's end, the setup of the agent or agents for specific tasks will need to have good logic behind their structure and implementation too. While the threat landscape will certainly be completely different not long from now, external controls like Authoryze and owner best practices will mitigate those risks and allow this technology to be a safe and massive output multiplier.