The Human Element Just Got an Automation Layer
Business email compromise was always a trust game. An attacker impersonates someone you know, manufactures urgency, and watches an employee wire money they shouldn't have. The FBI's Internet Crime Complaint Center logged 19,369 BEC complaints in 2020 alone, representing over $1.8 billion in adjusted losses. Barbara Corcoran nearly lost $400,000 to one. Traditional security software struggles here because there is no malware to catch — just a perfectly crafted message exploiting a perfectly human reflex to help your boss.
What's changed in 2026 isn't the psychology. It's the scale and precision. Attackers now have access to autonomous AI agents — the same class of tools enterprises are deploying for internal operations — and they're weaponizing them against the exact workflows organizations trusted to run without friction.
This isn't theoretical. Google Threat Intelligence Group has documented real campaigns. And if you're building AI security infrastructure right now, BEC via agentic platforms is not an edge case. It's the primary threat model for anything touching email, APIs, or payment rails.
What Is AI in Cyber Security? The Attacker's View
When most security teams hear "AI in cybersecurity," they think defense. Anomaly detection, phishing classification, automated triage. That's one side of the ledger.
The other side looks like this: APT45 sending thousands of repetitive prompts against known CVEs, recursively analyzing vulnerabilities and validating proof-of-concept exploits in ways that would be impractical for a human researcher working manually. GTIG observed this pattern tied to a distilled knowledge base of over 85,000 real-world vulnerability cases from China's WooYun bug bounty platform. The model approaches code analysis like a trained expert would, finding logic flaws the base model would miss.
Or look at PROMPTSPY, an Android malware family that contains an autonomous agent module called "GeminiAutomationAgent." It hardcodes a benign persona to bypass the LLM's safety filters, serializes the victim's visible UI hierarchy into XML via the Accessibility API, sends it to a Gemini model for spatial analysis, then executes the returned coordinates as physical gestures — clicks, swipes, pattern unlocks. It can even capture biometric data to replay authentication gestures. That's not phishing. That's an AI agent operating a phone on behalf of an attacker, without the attacker touching it.
So when someone asks "how is AI used in cybersecurity" — both of those sentences are the complete answer. Defensive and offensive. And the offensive side is industrializing fast.
How Agentic AI Adoption Created the Attack Surface
The Nylas 2026 State of Agentic AI report, based on survey data from over 1,000 developers and product leaders, paints a clear picture of where things stand. IT and internal operations lead agentic AI deployment, followed by customer support, sales workflows, and project management. These are exactly the systems BEC attackers target.
Here's the number that should concern security architects: only 4% of teams allow agents to act without human approval. That sounds reassuring until you understand what the other 96% actually looks like. Most organizations rely on graduated trust models. Agents handle routine, low-risk actions autonomously. Humans stay in the loop for decisions that matter. The line between "routine" and "matters" is where attackers operate.
An agent authorized to draft and send internal emails on a user's behalf, query vendor databases, or auto-approve small purchase requests is a BEC vector with elevated permissions and no human in the loop for the actions that matter most — the ones that look routine because they're pre-approved. The agentic ecosystem didn't just give defenders new tools. It gave attackers new identities to steal and new APIs to call.
AI Security Infrastructure Risks: Supply Chain and Skill Poisoning
Google's SAIF taxonomy names two categories that map directly to agentic BEC: Insecure Integrated Component (IIC) and Rogue Actions (RA). In practice, IIC means a compromised dependency or skill package embedded in your AI platform. RA means an AI system with elevated permissions executing unauthorized commands or exfiltrating credentials.
In early February 2026, VirusTotal researchers documented malicious packages masquerading as legitimate skills in the OpenClaw AI agent ecosystem. These contained hidden routines designed to execute unauthorized code, download additional payloads, and discover and exfiltrate local data. The key detail: OpenClaw agents receive elevated system access by design. A poisoned skill inherits those privileges.
The attackers behind this aren't bypassing frontier model safety guardrails — GTIG confirms that hasn't happened yet at scale. They're doing something older and uglier. Trojanizing configuration files. Poisoning integration libraries. Exploiting the orchestration layer, the wrapper code, the connector between your agent and its permissions.
This matters for BEC specifically because an agent with email access and a poisoned skill package is indistinguishable from a legitimate workflow to downstream recipients. No spam filter flags a message sent by your own approved assistant with your credentials.
The Prompt Injection Path to Business Email Compromise
Indirect prompt injection — where an attacker embeds malicious instructions in content an agent will read — is the most direct bridge between agentic AI and BEC. The mechanism is embarrassingly simple. An attacker sends an email containing hidden text. Your AI assistant reads it, interprets the hidden instructions as legitimate commands, and acts on them. The agent has the permissions your user gave it. The action looks internal. No one gets a suspicious-activity alert.
GTIG's PROMPTSPY case demonstrates this in a mobile context, but the architecture translates directly to enterprise email agents. The hardcoded prompt assigns a benign persona to bypass safety filters. The user goal is supplied as a separate routine rather than baked in, meaning one malware family can facilitate multiple types of interaction by swapping objectives. Strip the Android-specific parts and you have a blueprint for a BEC-automation framework that operates entirely through your own agentic infrastructure.
The McKinsey analysis on agentic AI security and governance for enterprises flags this class of risk under "Risks" specifically tied to autonomy and API exposure. IBM's threat research echoes the same concern: the more you automate decision-making, the more a single compromised permission becomes a multi-action attack chain rather than a single email sent.
What Defenders Should Do About It
If you run agentic workflows touching communications, payments, or vendor data, your AI security infrastructure needs to treat every permission grant as a potential BEC foothold. That means several concrete things:
Scope agent permissions to the narrowest possible action set. "Can send email" is too broad. "Can send email to these 12 recipients during business hours, CC the manager" is a control. The Nylas data shows teams are already adopting graduated trust — formalize it at the infrastructure layer, not just the policy layer.
Treat skill packages and connector libraries as software supply chain artifacts with the same scrutiny you'd give a kernel module. GTIG's documentation of the OpenClaw ecosystem compromise shows the difficulty defenders face in discerning malicious packages from legitimate ones. You need provenance tracking, not just scanning.
Build detection around agent behavior patterns, not message content. A BEC attack executed through your own agent produces messages that look legitimate by definition. The tell is behavioral: an agent suddenly querying payment systems it hasn't touched before, or drafting emails in an unusual tone or to an unusual set of recipients. The velocity-of-machine-threat problem is real — when the action surface is an AI agent, you need machine-speed anomaly detection on the action surface itself.
The existing guidance on securing autonomous AI agents in the enterprise covers governance frameworks. What BEC via agentic platforms adds is the social engineering multiplier. Your agent is your agent. The attacker doesn't need to fake your identity if they can drive yours.
The Uncomfortable Question
Every organization deploying agentic AI into email and workflow systems is building a new BEC delivery mechanism whether they intended to or not. The 4% figure from Nylas — only 4% operate with full autonomy — tells you where teams are today. But "graduated trust in production" means the boundary is already drawn, and the attackers are probing it.
The question isn't whether AI agents will be exploited for business email compromise. They already are. The question is whether your security architecture treats agentic permissions as a first-class attack surface or as an afterthought bolted onto email security that was designed for the world where the only AI involved was in the attacker's laptop.