Agentic AI
,
Artificial Intelligence & Machine Learning
,
Governance & Risk Management
Sumitomo’s Sawant on the Internal Risks of Autonomous AI Agents
Autonomous artificial intelligence agents are shifting the nature of insider threats by operating at machine speed and mimicking human-level access and privilege. These synthetic entities can act independently within systems and carry out actions traditionally reserved for human users, introducing new security risks.
See Also: OnDemand | Transform API Security with Unmatched Discovery and Defense
“These agents are not passive tools. They are autonomous actors,” said Shilpa Sawant, vice president at Sumitomo Mitsui Banking Corporation. “They have access to systems, they have access to data, they have access to everything a normal human staff would have. And they have the privileges to perform some actions, which can be abused in a way that gets very hard to detect.”
To defend against these risks, organizations must shift from one-size-fits-all policies to tailored, role-based security practices. Targeted communication and hyper-personalized awareness programs can build a deeper understanding of threats and embed security into daily workflows. Sawant said uniform monitoring of both human and AI behavior is also key, along with least-privilege access, zero trust principles and data-centric controls that prioritize sensitive information over systems.
In this video interview with Information Security Media Group, Sawant also discussed:
- The shifting nature of insider threats in the age of hybrid work;
- How agentic AI expands the scope of internal risk by automating malicious actions;
- Metrics as indicators of insider threat program maturity.
Sawant has more than 17 years of cybersecurity experience across diverse sectors in Asia, including global banking and conglomerates. She specializes in creating robust, business-aligned security frameworks and developing adaptive strategies that navigate complex threat landscapes. Her expertise encompasses advanced ransomware defense implementation, software supply chain security and risk mitigation for emerging technologies. Sawant focuses on enhancing organizational cyber maturity and fostering risk-aware cultures while embedding “Security by Design” principles.

