Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Druva: Agentic AI Is Already Your Biggest Attack Surface

Druva
09/01/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


It's not a future set statement. It's a current statement. And let me walk you through how. A lot of enterprises have integrated AI technologies. In an agentic world, where you have a level of autonomy given to an AI-based bot. And an agentic world means that there's a sense of act in the AI that it can act on your behalf. And if you've already given an email access, you're practically given the AI bot access to your two-factor authentication, which is the genesis of an access to any application in enterprise. Any attack in that particular equation has a massively large surface area. Now it may not happen because those applications are highly secure and tightly managed, but security is all about risk mitigation. From a risk mitigation perspective, the surface area is extremely large. And in the world where autonomy is becoming more and more obvious and the world is going towards, how can I use AI to be doing more for me? The risk factor amplifies quite a bit.

TL;DR

  • Agentic AI systems that act autonomously on behalf of users already have broad enterprise access — this is a present-day risk, not a future concern.
  • Granting an AI agent access to email effectively grants it access to two-factor authentication, which is the gateway to every enterprise application.
  • Even in well-secured environments, the sheer size of the attack surface created by AI agent permissions represents a significant risk management challenge that grows as AI adoption increases.

Summary

In this short executive clip, Druva CEO Jaspreet Singh delivers a pointed warning about agentic AI and the enterprise attack surface it creates today — not in some hypothetical future. Singh explains that as organizations integrate AI agents capable of acting autonomously on behalf of users, they are inadvertently granting those agents access to email inboxes. Because email is the delivery channel for two-factor authentication codes, that single permission effectively unlocks every application in the enterprise environment. The attack surface this creates is not incremental — it is exponential. Singh acknowledges that well-secured, tightly managed applications reduce the likelihood of exploitation, but frames the issue through a risk mitigation lens: the surface area is already extremely large, and as enterprise adoption of autonomous AI accelerates, the risk factor amplifies rather than stabilizes. The message is a clear call for security leaders to reassess how AI agent permissions are scoped and governed before autonomous access becomes an unmanageable liability.

Chapters

0:00 - AI Access Is Already Here
0:09 - How Agentic AI Works
0:26 - Email, 2FA, and Full Enterprise Exposure
0:49 - Risk Amplification as AI Autonomy Grows

Key Quotes

0:00 "I think AI already has access to all the applications. It's not a future set statement. It's a current statement."
0:26 "If you've already given an email access, you're practically given the AI bot access to your two-factor authentication, which is the genesis of an access to any application in enterprise."
0:49 "Security is all about risk mitigation. From a risk mitigation perspective, the surface area is extremely large."

FAQ

Why is email access so dangerous to grant an AI agent?

Email is the delivery channel for two-factor authentication codes. If an AI agent can read your email, it can intercept 2FA tokens, which effectively gives it authenticated access to any enterprise application that relies on email-based verification.

Does this mean enterprises should stop using agentic AI?

Singh does not advocate for halting AI adoption. Instead, he emphasizes risk mitigation — acknowledging that tightly managed applications reduce exploitation likelihood, but stressing that the attack surface is already very large and grows as AI autonomy increases.


Categories:
  • » Webinar Library » Druva
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Cloud Security
  • Identity & Access
  • Threat Intelligence
  • Executive Briefing
  • Short Form
  • Agentic AI security
  • Enterprise attack surface
  • Two-factor authentication risk
  • AI governance
  • Privileged access management
  • Risk mitigation
  • AI autonomy
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Druva: Agentic AI Is Already Your Biggest Attack Surface

              XStreaminars (watch here)

              • Sep
                03

                Verge.io: Can You Afford Your Next Storage Refresh?

                09/03/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Sep
                  17

                  Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                  09/17/202610:00 AM ET
                  • Sep
                    17

                    Unveiling the AI-Driven Underworld of Automation's Rapid Rise

                    09/17/202601:00 PM ET
                    • Sep
                      23

                      Unseen Data: The Blind Spot in Your Protection Strategies

                      09/23/202601:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/03/2026
                        01:00 PM
                        09/03/2026
                        Verge.io: Can You Afford Your Next Storage Refresh?
                        https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                      • 09/17/2026
                        10:00 AM
                        09/17/2026
                        Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                        https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                      • 09/17/2026
                        01:00 PM
                        09/17/2026
                        Unveiling the AI-Driven Underworld of Automation's Rapid Rise
                        https://www.truthinit.com/index.php/channel/2108/unveiling-the-ai-driven-underworld-of-automations-rapid-rise/
                      • 09/23/2026
                        01:00 PM
                        09/23/2026
                        Unseen Data: The Blind Spot in Your Protection Strategies
                        https://www.truthinit.com/index.php/channel/2087/unseen-data-the-blind-spot-in-your-protection-strategies/
                      • 09/29/2026
                        12:00 PM
                        09/29/2026
                        Embracing AI Adoption While Ensuring Robust Security Measures
                        https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      • 11/19/2026
                        01:00 PM
                        11/19/2026
                        360View: Govern, Secure & Recover Your Microsoft 365 Environment
                        https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version