AI

Exclusive: Martin Kraemer on the New Human Risk Equation in the Age of AI Agents

Bakhtawar Majid

By: Bakhtawar Majid

5 min read

Dr. Martin Kraemer, CISO Advisor at KnowBe4, helps organizations across Europe and the Middle East understand and mitigate cybersecurity risks. With more than 10 years of cybersecurity research and industry experience, his work focuses on human risk, security behavior, cyber risk management and systems security. He has held roles in research, innovation, technology consulting and thought leadership. 

[For more news, click here]

Artificial intelligence is changing one of cybersecurity's most familiar assumptions. The person using a system is not necessarily the person carrying out the action. 

AI agents can now query documents, book meetings, write code and interact with business systems with varying levels of human supervision. As these systems become more autonomous, they can also inherit the identity, permissions and access of the people who deploy them. 

Cybersecurity teams are consequently facing a different kind of human risk. An employee may authorize an agent without directly carrying out the resulting action, while an attacker may manipulate the information the agent processes and turn legitimate access into an unintended outcome. 

Ahead of GISEC 2026, Tech Revolt spoke with Dr. Martin Kraemer, CISO Advisor at KnowBe4, about how agentic AI is changing human risk, why AI agents need to be treated differently from traditional software and whether organizations are prepared to account for mistakes made by machines acting on their behalf. 

AI Agents and the New Human Risk Equation 

Q1. KnowBe4's model was built on training humans not to click the wrong thing. If agents are now doing the clicking, booking meetings, querying documents, writing code, how much of the human risk problem is still actually human, and how is that changing what KnowBe4 sells? 

The premise is slightly off. Agents don’t remove the human from the risk equation; they inherit the human’s identity, permissions and judgement gaps, and then act on them at machine speed. An employee still decides what an agent may access, approves what it does, and answers for the outcome. People will remain accountable for their actions just as much as for their AI agents. 

What has changed is that social engineering now works at one remove. The EchoLeak incident was the wake-up call for many: a single crafted email carrying hidden instructions was enough to make Microsoft 365 Copilot pull sensitive data from a user’s context and leak it through an allow-listed Microsoft Teams proxy, with no click at all. If an attacker can talk an agent into exfiltrating data, it is a small step to having the agent phish its owner. 

The human risk problem hasn’t shrunk or lightened but gained another layer. For KnowBe4 that means the product has moved from training people not to click towards managing human risk across people and the agents acting on their behalf: who can delegate what to an agent, how those delegations are monitored, how infosec can manage agent risk just as they are managing human risk, and how people recognise manipulation that arrives via a tool they trust. People, process and technology still apply while complexity and stakes have increased. 

Q2. “Digital colleague” is the framing you’re using for agentic AI. Does a digital colleague get the same access review, offboarding process, and audit trail as a human employee today, and if not yet, what’s actually in the way of that becoming standard? 

Not yet. But joiners–movers–leavers processes need to be defined for AI. An agent needs its own credentials, scoped permissions and a record of what it did. The problem is that in most organisations today the agent has none of those in its own name. It runs on a shared service account or on a borrowed human identity, so there is nothing distinct to review, nothing to revoke when it is retired, and its actions in the logs are indistinguishable from those of the person who deployed it. 

Another consideration is speed where access and departure processes are handled quietly. Governance built for human tempo can only ever reconstruct the damage afterwards. Standard practice for agents will need real-time monitoring and the ability to halt an action before it completes, not a review cycle. 

The principles are already written down. DIFC Regulation 10 puts accountability on whoever deploys an autonomous system, the EU AI Act demands logging and human oversight for high-risk uses, and the NIST AI RMF gives a workable structure for implementing them. What is missing is the plumbing between those principles and the identity systems most enterprises actually run. That gap, not the regulation, is what’s in the way. 

Q3. When an AI agent, not a human, makes the costly mistake, approves the wrong transfer, leaks the wrong document, is that logged and reported the same way as human error today, or does incident reporting still need to catch up to that? 

This breaks down inside the organisation, before anything reaches a regulator. When an agent approves the wrong transfer, it gets filed as a software defect and routed to engineering, not incident response. Nothing trips an alert, because, as EchoLeak showed, the agent is behaving exactly as designed. And the log records what the agent did, not the instruction that made it do so, which means you cannot tell an honest mistake from a manipulated one. 

Human error has a named person, a manager and a lessons-learned process behind it. An agent has none of that, so its mistakes get treated as technical noise. Incident reporting doesn’t need new rules; it needs organisations to treat an agent acting wrongly as an incident and instrument it accordingly. 

The Next Phase of Human Risk 

Agentic AI does not make human risk management less relevant. It expands the problem beyond the employee to the systems acting with the employee's identity, permissions and authority. 

Security leaders will need greater visibility into what these agents can access, what they are permitted to do and how their actions can be traced. As agents become more deeply embedded in business processes, incident response will also need to distinguish between a technical failure and an agent being manipulated into producing an unintended outcome. 

Human judgment will still matter, but organizations will also have to take responsibility for what their AI agents do. As these systems become more autonomous, knowing what they can access, what they can do and when something goes wrong will become just as important as knowing who deployed them.  


Related Articles 

GISEC Global 2026 Opens in Dubai with a Cyber First Agenda and a New Quantum Security Focus 

Delinea Takes AI Agent Security Beyond Access 

Most Organizations Were Hacked Through Stolen Identities Last Year, AI Is About to Make It Much Worse 


 


 

Share this article

Related Articles