Understanding the failed gate
The Greeks didn't storm Troy's walls. They built an enormous wooden horse and let the Trojans do the rest. Years later, it remains the single most effective hack in recorded history, for the same reason most hacks still work today. Something inside the walls decided the thing outside was fine and didn't look any closer before opening the gate. The uncomfortable truth about Agentic AI is that it didn't coin a new category of risk. It amplified a proven one.
Cympire made this point in April, tracing how supply chain attacks exploit trust the way that horse exploited an open gate. We agree, though the old horse needed a soldier hiding inside it and the soldier only got one shot. Today's version needs no soldier, only an agent spun up in an afternoon, granted access nobody fully audited and left running indefinitely. The original Trojan Horse was a single, clever deception; this iteration restocks itself every time someone clicks "allow."
That distinction points at the real fault line in today's AI risk conversation. Forbes ran a piece in May built around a sharp observation from Aaron Portnoy, Mindgard's CPO: for most of cybersecurity's history, the central question was access, whether the attacker could get in. That's no longer sufficient on its own. The sharper question, Portnoy argues, is authority. What the thing already inside can actually do. He's spot on and he's rediscovering something third-party risk teams have been asking, in different language, for years.
Asking the right questions
Security questionnaires attempt to answer that authority question before access is granted. What data can you touch? What can you do with it? Who's accountable if something goes wrong? Agentic AI didn't expose that distinction. It handed it to something that can't sign a contract, attend a review or be onboarded at any normal pace. Watching the AI security world rediscover "agency versus authority" only proves third-party risk practitioners had the right instinct all along. What's missing is the will to widen who counts as a third party.
That reframe is where a real strategy starts. Too many organizations treat agentic AI risk as needing an entirely new department, a new tool category and a governance model built from scratch. It doesn't. Third-party risk already built the discipline for this exact question, who has access, what can they do, how do we know, what happens when it fails, then applied it to vendors instead of agents by accident. The mistake isn't a lack of imagination about AI. It's a failure of memory about what security already knows.
The four-question framework
AI agents are becoming the fastest-growing attack surface most security teams aren't watching. The fix is the same one you'd apply to any vendor risk program. Know what exists, who owns it, how it's governed and what happens the day it's compromised. Four questions. Nothing exotic about them. What's exotic is that almost nobody can currently answer all four about the agents already running inside their own environment.
That's the strategic bet worth making now. Organizations that treat agents as a new class of vendor, subject to the same intake and accountability, will spend the next few years quietly ahead of those still treating agents as a productivity feature and nothing more. Give it a few years and a questionnaire that skips how many AI agents run in an environment will look as incomplete as one that never asked about SOC 2. Give it longer and breach disclosures will start naming a compromised agent ID the way they now name a vendor.
The gate still needs a guard
None of this requires abandoning what already works, only refusing to let automation quietly absorb decisions that were never its to make. An agent can execute a task faster than any human. It cannot decide on its own, whether it should have been given that task and pretending otherwise is how every version of this story, ancient or agentic, ends the same way. Saying that plainly, in public, turns out to be a stranger competitive advantage than it should be. Most vendors talk about responsible AI as a value statement. Fewer show what they're automating, what they're deliberately not and why a human is still the one signing off when it counts.
We're not the first to draw these parallels and we won't be the last. Cympire saw the pattern in the metaphor. Portnoy saw it in the permissions. Our own team of cybersecurity experts has been saying versions of it out loud all year. What we'd add is this: the parallel isn't a metaphor anymore. It's a governance problem with a known shape, decades of institutional memory behind it and, for the organizations willing to treat it that way, an answer that already exists.