SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
Abnormal AI launches cloud security for rogue agents

Abnormal AI launches cloud security for rogue agents

Tue, 8th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Abnormal AI has launched AI Cloud Security, a product designed to detect and respond to risky or malicious AI-agent behaviour in cloud environments.

The offering extends Abnormal AI's behavioural security system beyond email, identity and insider threat into cloud infrastructure. It is in private preview for selected customers.

The launch comes as security vendors and corporate defenders assess how increasingly autonomous AI agents could expose cloud systems to new forms of attack. Abnormal AI pointed to a recent OpenAI-Hugging Face incident, disclosed as part of an internal cybersecurity evaluation, in which AI agents found paths beyond their intended environment and accessed third-party production infrastructure.

That episode has intensified debate over whether existing cloud security tools can handle software agents that act quickly, chain together weaknesses and generate activity that may not match established threat signatures. Behaviour-based detection is emerging as one answer because it focuses on deviations from normal activity rather than relying only on known indicators of compromise.

Cloud focus

Abnormal AI says its cloud product builds behavioural models for identities across a customer's environment, including human users, service accounts, API keys and AI agents. The goal is to establish a baseline for normal behaviour and flag unusual actions for investigation.

The product can also take predefined response steps when certain conditions are met. Those actions can include isolating a workload, revoking a credential and containing affected resources. Customers can choose between automatic action and human review depending on an incident's severity.

A third element of the launch centres on investigation. Abnormal AI is using OpenAI Daybreak models to analyse logs and behavioural signals so incident responders can better understand what happened, assess the scope of a security event and decide on response measures.

This tie-up places the product within a broader push by security suppliers to use generative AI in defensive workflows, even as they warn that similar systems may be used offensively. In this case, Abnormal AI is applying OpenAI models at the investigative stage rather than presenting them as the detection engine.

Growing market

Over the past year, cybersecurity companies have expanded beyond conventional endpoint, network and identity controls to address risks associated with AI deployment inside large organisations. Those risks range from data leakage and model misuse to autonomous agents taking unintended actions across applications and cloud services.

For security teams, the challenge is not only technical but operational. Human analysts often investigate cloud alerts manually, yet an AI agent can generate or execute actions at a pace that outstrips those workflows. That has increased interest in systems that can automatically triage anomalies and, in some cases, trigger a response without waiting for an analyst.

Abnormal AI says it now protects more than 4,500 organisations, including more than 25% of the Fortune 500. The company built its business around behavioural analysis, particularly in email security, and is now using that approach to widen its reach in enterprise security operations.

Greg Brockman, President and Co-Founder of OpenAI, recently commented on the OpenAI-Hugging Face episode in a separate blog post. "The OpenAI-Hugging Face incident was a watershed moment for cybersecurity because it gave a peek into how the capabilities of a typical threat actor will evolve in upcoming months. I've spoken with many organizations over the past few weeks, and one theme is clear: they know they need to fundamentally uplevel their cybersecurity practices with unprecedented speed," Brockman said.

Abnormal AI framed its new service as a response to that shift in the threat landscape, arguing that malicious or misbehaving AI agents, like human attackers, can produce detectable behavioural signals when they deviate from established patterns in a cloud estate.

Evan Reiser, Founder and CEO of Abnormal AI, said the recent incident showed why organisations need to prepare for agent-led threats. "The Hugging Face incident was a warning shot. It showed what capable agents can already do when they go off-script, and why security teams need to prepare for similar techniques being used intentionally by attackers," Reiser said.

"Our platform already detects behavioral anomalies from human and non-human identities and I'm excited for us to extend these capabilities to protect enterprise cloud environments," he added.