Substrate
finance

Enterprise AI Agents Require Continuous Red Teaming for Security

Joan Vendrell of NeuralTrust said traditional security testing cannot keep pace with autonomous AI agents that interact with live data. He outlined five steps for continuous red teaming to address dynamic attack surfaces and adversarial reasoning.

Forbes
1 source·May 22, 10:45 AM(7 days ago)·1m read
|
Enterprise AI Agents Require Continuous Red Teaming for SecurityForbes
Audio version
Tap play to generate a narrated version.

Joan Vendrell, NeuralTrust CEO and cofounder, said traditional penetration tests provide only a snapshot in time while agentic AI systems operate continuously and interact with live data. He described a conversation with a CISO preparing for a production rollout of an autonomous customer service agent who had passed conventional tests but could not explain how the agent would respond to an evolving multi-step prompt injection attack.

Vendrell stated that AI agents are non-deterministic, meaning their behavior changes based on context, memory, and available tools. This creates opportunities for what he called adversarial reasoning, where attacks target the agent's logic rather than its input.

He noted that the OWASP Top 10 for LLM Applications has evolved to include agentic hijacking and indirect prompt injection. Gartner predicts that by 2028 more than 50 percent of enterprises will use dedicated AI security platforms to manage these risks.

Vendrell said traditional red teaming, which typically involves a human team spending two weeks testing a system, cannot match the speed of AI development.

Vendrell recommended deploying adversarial agents to operate 24/7 and stress-test production agents using the MITRE ATLAS framework. He said red teaming must focus on insecure output handling and simulate scenarios where agents receive malicious commands through trusted tools such as compromised email or poisoned database entries.

He stated that continuous red teaming should align with the NIST AI risk management framework, specifically its Measure and Manage functions. Vendrell added that red teams should continuously feed agents poisoned data to test resilience against indirect prompt injection and should track identity lineage to ensure accountability remains traceable even when an agent's reasoning is compromised.

Key Facts

Gartner prediction
Over 50% of enterprises will use AI security platforms by 2028
OWASP Top 10 evolution
Now includes agentic hijacking and indirect prompt injection
Traditional red teaming limit
Human teams spend two weeks testing systems

Potential Impact

  1. 01

    Enterprises may adopt dedicated AI security platforms to manage agent risks.

  2. 02

    Security teams may shift from periodic audits to continuous automated testing.

Transparency Panel

Sources cross-referenced1
Confidence score75%
Synthesized bySubstrate AI
Word count281 words
PublishedMay 22, 2026, 10:45 AM

Related Stories

SEC Chair Paul Atkins Says Congress Will Pass Crypto Legislationibtimes.com
finance1 hr agoDeveloping

SEC Chair Paul Atkins Says Congress Will Pass Crypto Legislation

SEC Chair Paul Atkins stated he is confident Congress will pass crypto market structure legislation. He added that President Trump will sign the bill into law.

WA
BI
2 sources
Iran Says Strait of Hormuz Management Belongs to Iran and Omanasiaone.com
finance1 hr agoDeveloping

Iran Says Strait of Hormuz Management Belongs to Iran and Oman

Iran's Foreign Ministry spokesperson stated that control of the Strait of Hormuz must be decided solely by Iran and Oman. The spokesperson also said no agreement has been reached with the United States and that current focus remains on ending the war.

DE
LI
ZE
IN
4 sources
Fed Official Highlights Regulatory Barriers to AI Productivity Gainscnbc.com
finance1 hr agoDeveloping

Fed Official Highlights Regulatory Barriers to AI Productivity Gains

A Federal Reserve official stated that productivity growth remains key to economic expansion and that regulatory hurdles are the main obstacle to sustained gains from artificial intelligence.

FI
FI
2 sources