Certik Urges Web3 Firms to Integrate AI Agents as Workforce Members
A new report from Web3 security firm Certik urges companies to treat AI agents as part of their workforce, given their evolving role from passive tools to autonomous actors. The shift reflects AI's growing capability to perform multi-step reasoning, integrate external APIs, and execute live remediation actions with minimal human oversight. Certik emphasizes that organizations must govern these AI agents with explicit roles, bounded authority, and strict human supervision, as deploying entities retain full legal and operational liability.
The call for workforce integration comes amid rising threats, including machine-speed attacks and a global cybersecurity talent shortage. Anti-money laundering penalties surged past $900 million in the first half of 2025, highlighting the need for robust defenses. While AI enhances cybersecurity, attackers are leveraging similar technologies, accelerating the frequency and sophistication of exploits. The report warns that defenders must evolve security systems to match the speed of continuous threats.
Certik’s senior blockchain investigator, Natalie Newson, argues that defenders retain a critical advantage, home-field advantage. By reviewing code before deployment and monitoring on-chain activity, automated systems can detect and pause exploits in real time. Newson advocates for real-time, 24/7 on-chain circuit breakers and mandatory audits for AI logs to shift the threat economics against attackers.
The report concludes that adopting agentic AI without proportional governance risks swapping manual constraints for systemic risks. It urges organizations to delineate AI execution from human oversight and make the auditing of AI reasoning logs a mandatory compliance practice.