CertiK Report Highlights AI Agents Expanding Role in Cybersecurity
AI agents are increasingly taking on larger roles in cybersecurity and financial-crime investigations, according to a new report by blockchain security firm CertiK. The Intel3D report highlights how newer AI systems can now reason through steps, use tools, gather evidence, act in live environments, and review results with minimal human input. This shift marks a significant evolution from traditional machine-learning systems, which primarily supported analysts by flagging unusual logins, scoring transactions, and preparing reports.
In security operations centers, AI agents can now investigate suspicious logins by checking device records, location data, and threat feeds before taking action, such as suspending an account. Similar systems are emerging in Web3 security, including contract triage, transaction risk scoring, and tracing stolen funds. CertiK expects humans to focus more on supervision as agents handle routine investigations. The urgency for this shift is driven by the speed of some attacks, such as flash-loan exploits that can drain protocols within seconds, and the rapid movement of stolen crypto across bridges and mixers.
A shortage of cybersecurity and compliance professionals, combined with increasing regulatory pressure, is another factor driving the adoption of AI agents. The report cites over $900 million in AML penalties during the first half of 2025, underscoring the consequences firms face when controls fail. As AI agents take on more tasks across financial and crypto operations, CertiK argues that companies should treat them as workforce participants rather than ordinary software, emphasizing that human accountability remains crucial.
However, the report also highlights risks associated with AI autonomy, including incorrect outputs, weaker human scrutiny, and deliberate attacks against AI systems. CertiK recommends maintaining records of inputs and actions, setting clear limits on autonomous decisions, conducting adversarial testing, and assigning a named owner for every agent. Without strong oversight, automation could replace familiar problems with harder-to-explain failures, the report warns.