The risky part of your AI agent is not the model. It is what the agent is allowed to change
An agent that can read your CRM and also send emails is a very different risk from a chatbot.
What happened
In a VentureBeat piece published September 26, Adithyan RK, co-founder and CEO of Hyring, argues that in production AI systems "the model is rarely the weak point. The workflow is." Agents now read live data, call tools and APIs, write to databases and trigger downstream automations.
He lists five weak spots:
- Prompt injection through connected data. An attacker does not need your model, only a source it reads, such as a CRM note, a ticket, an email or a review.
- Over-permissioned tool calls, often using broad API keys granted at development speed.
- Fragile trust boundaries, where outputs pass between tools without being validated again.
- Missing observability, since tool call sequences vary from run to run.
- No circuit breaker, so one bad decision can repeat without a rate limit, approval gate or kill switch.
His checklist: least privilege access, sandboxing before autonomy, human approval for high consequence actions like refunds, decision level logging, treating third party data as untrusted input, and explicit circuit breakers. As he puts it, "A more capable model doesn't make an over-permissioned integration safer."
Earlier VentureBeat research, from a June 2026 survey of 107 enterprises, found that 54% had already had a confirmed agent security incident or a near miss, 69% had credential sharing somewhere in their agent fleet, and only 32% gave every agent its own scoped identity.
My take
A common setup in small business stacks is one admin API key for HubSpot or GoHighLevel, shared by every workflow, including the new AI step that reads inbound form messages. That form field is now an input channel to your agent.
The fixes are not exotic:
- Give the agent its own user or private app with read only scopes unless a write is the point of the workflow.
- Split read and write into separate steps, and put a human approval or a hard rule in between for anything touching money, deletions or bulk sends.
- Log what the agent read and which tool it called, in a sheet or a table you actually look at.
- Add a cap: no more than N records changed per run, or the workflow stops and pings someone.
You can set all of this up in n8n, Make or Zapier today. Upgrading the model does not replace any of it.
More posts
- AI proposed, humans decided: what 700+ task logs from an AI lab say about human in the loop designSep 28, 2026
- Simon Willison's 2026 recap has one lesson for automation builders: defining the job is the skillSep 28, 2026
- Nvidia's free diarization model labels up to eight speakers live. Better call notes for your CRMSep 28, 2026
