2026년 10월 5일

CertiK Intel3D The Rise of the AI Security Workforce: How Agentic AI Is Redefining Cybersecurity, AML & Compliance

Agentic AI is moving from assisting analysts to doing the work itself. Across Web2 and Web3, autonomous systems now triage threats, trace illicit funds, and draft regulatory filings, making governance and human accountability the new prerequisites for adoption.

다음 언어로도 제공됩니다: Chinese, Korean

CertiK Intel3D The Rise of the AI Security Workforce: How Agentic AI Is Redefining Cybersecurity, AML & Compliance

Executive Summary

Agentic AI is taking on more of the work behind cybersecurity, anti-money laundering (AML), and compliance: investigating alerts, tracing funds, assessing vulnerabilities, and preparing regulatory reports. Drawing on CertiK’s experience in smart contract auditing, formal verification, and on-chain forensics, this report examines how that shift is unfolding across Web2 and Web3. Its central argument is that organizations should manage AI agents as workforce participants with defined roles, bounded authority, and human supervision. As AI performs more operational work, organizations must strengthen the controls that make its decisions reviewable and its actions accountable.

Introduction

From AI-Assisted to AI-Led: Earlier AI systems flagged anomalies or summarized information for human analysts. Agentic systems can investigate an issue across multiple steps, retrieve evidence, call external tools, and take action within their assigned authority. Machine-speed attacks, persistent talent shortages, and expanding regulatory obligations are accelerating this transition, with human experts increasingly focusing on supervision, complex cases, and final decisions.

AI as an Autonomous Workforce Participant: An AI agent needs a defined role, explicit permission limits, an escalation path, and a named human owner. The scope of work it performs may expand, but accountability remains with the deploying organization and the people who configure and supervise it. Workforce planning and governance must reflect this division of responsibilities.

Web2 Traditional Domains

Cybersecurity

Operations and Monitoring: Agentic AI correlates signals across security logs, endpoint systems, network telemetry, and cloud environments to investigate alerts and prioritize threats. More advanced deployments can execute authorized containment actions, such as isolating an endpoint or revoking a session, while preserving evidence for human review.

Vulnerability Management: AI agents can continuously examine code and infrastructure, assess realistic exploitation paths, and prioritize remediation by business impact. Some systems also draft and test candidate patches, giving engineers a proposed fix to review alongside the vulnerability finding.

Identity and Access Management and Data Security: Continuous behavioral monitoring helps identify privilege changes, dormant-account activity, and unusual data transfers. As AI agents receive access to sensitive systems, their own permissions and behavior become part of the identity risk organizations must monitor.

Compliance Auditing: AI agents can map live configurations against control frameworks such as SOC 2, ISO 27001, and NIST CSF, flagging deviations between assessment cycles. This supports continuous audit-readiness by making control changes visible before the next scheduled review.

Anti-Money Laundering

Transaction Monitoring: Agentic systems use behavioral, relational, and historical context to reassess transaction alerts. Within defined controls, they can resolve straightforward low-risk cases and escalate ambiguous activity, allowing human investigators to concentrate on cases that require deeper judgment.

Customer Due Diligence and Sanctions Screening: AI agents can assemble information from sanctions lists, adverse media, politically exposed person databases, and corporate registries into a sourced risk assessment. Higher-risk or uncertain profiles can reach human reviewers with an investigative file already prepared.

Link Analysis and Reporting: Agentic tools can build relationship graphs connecting accounts, beneficial owners, and counterparties, then summarize the findings in plain language. This reduces the manual work required to reconstruct networks and prepare an investigation for review.

Regulatory Submission: AI can synthesize transaction histories, entity relationships, prior alerts, and supporting evidence into a Suspicious Activity Report (SAR) draft. Human compliance officers retain responsibility for reviewing the narrative, checking its evidence, and certifying the filing.

AI on Both Sides of the Ledger: Attackers can use the same capabilities to accelerate reconnaissance, exploitation, and evasion. AML controls therefore need to connect transaction monitoring with internal access controls and network security. When funds leave a platform, rapid cross-chain tracing supports investigation and regulatory reporting.

Compliance

Policy Interpretation: AI agents can monitor regulatory updates, identify affected internal policies and controls, and flag gaps for legal or compliance review. This shortens the process of translating a rule change into an operational response while preserving human judgment over its interpretation.

Data Compliance: Agentic systems can classify and track data across cloud and on-premise environments, helping identify potential breaches of residency, transfer, or retention requirements as they occur.

Internal Auditing: Automated testing can extend audit coverage beyond manually selected samples to larger populations of transactions and controls. Continuous review can help organizations detect policy deviations earlier and direct human attention to exceptions.

Web3 Emerging Domains

Cybersecurity

Smart Contract Auditing: AI agents can examine contract interactions and state transitions to identify potential vulnerabilities, including access-control errors, oracle manipulation paths, and unsafe upgrade patterns. They can also assist with developing formal specifications. Human auditors remain responsible for validating findings, assessing novel attack scenarios, and reviewing the tooling’s coverage.

Real-Time On-Chain Transaction Monitoring: Agentic systems can monitor pending and confirmed transactions for exploit patterns and abnormal activity. In advanced deployments with appropriate controls, detection can trigger responses such as pausing a supported contract function or activating a circuit breaker, reducing the delay between identifying a threat and acting on it.

Root Cause Analysis: Following an exploit, AI agents can reconstruct attack paths across contracts and transactions and prepare structured technical findings. This accelerates the investigation and allows security experts to devote more time to validating conclusions, remediation, and disclosure.

On-Chain Anti-Money Laundering

On-Chain Tracking: AI agents can follow funds through intermediary addresses, mixers, and bridges as transactions unfold. Continuous tracing helps investigators maintain visibility as attackers fragment funds and move them through increasingly complex routes.

Address Clustering: Behavioral signals such as transaction timing, counterparty overlap, and gas-fee patterns can help identify addresses likely controlled by the same entity. Agentic systems can update these clusters as new activity emerges, supporting investigations beyond static address lists.

Cross-Chain Analysis: Agentic systems can connect activity across blockchains into a continuous investigative view. CertiK’s research into DPRK-linked laundering illustrates why tracing across bridges, swaps, and other transfer routes is essential when stolen funds move between ecosystems.

Compliance

Automated Regulatory Reporting: AI can help reconcile blockchain activity with off-chain records and prepare reporting materials for obligations such as Travel Rule processes and reserve-related disclosures. Automating reconciliation and formatting reduces manual work, while human review remains necessary to validate the evidence and submission.

KYA and KYT Screening: Know-Your-Address (KYA) and Know-Your-Transaction (KYT) screening can use AI-driven risk scoring to assess counterparties and transactions before settlement where the workflow permits. This supports earlier identification of potential exposure to illicit funds.

AI Agent Behavior Auditing and Evidence Preservation: As autonomous agents hold and transact digital assets, their own behavior becomes a subject of compliance review. Organizations need to preserve what information an agent used, how it reached a decision, and what action it took. The deploying organization remains accountable for those actions.

Risks and Limitations

Model Misjudgment and Hallucination: Agentic systems can produce confident but incorrect findings, including misclassified threats, inaccurate transaction narratives, or flawed formal specifications. Automation bias can compound the problem if human reviewers become less critical as routine performance improves. Consequential outputs therefore require evidence checking and proportionate review.

Adversarial Exploitation: Attackers can use AI to accelerate vulnerability discovery and social engineering, while targeting defensive agents themselves. Prompt injection or manipulated inputs can cause an agent with broad permissions to approve a harmful action or disable a legitimate control.

Liability and Accountability: Wrongful freezes, inaccurate reports, and disruptive contract pauses raise questions about responsibility that remain unsettled across jurisdictions. Organizations need clear records of who owns an agent, what authority it has, when escalation is required, and whether human approval preceded a consequential action.

Governance Recommendations: Maintain audit trails of consequential inputs, reasoning, and actions; define which actions require human approval; regularly test agents against adversarial manipulation; and assign a named human owner. These controls should be established before agents receive operational authority.

Conclusion

Agentic AI is changing how cybersecurity, AML, and compliance work is performed across Web2 and Web3. Organizations need to define which tasks agents execute and which decisions humans supervise, then build staffing and governance around that division. Auditing the behavior of AI agents is also becoming a distinct responsibility as they gain access to systems and digital assets. Adoption can expand speed and coverage, but those gains depend on clear authority boundaries, reliable evidence, and human accountability. Building these controls alongside the technology is essential to making the AI security workforce effective and governable.