As organizations race to move from AI chatbots and copilots toward autonomous AI agents, security leaders are being forced to answer a harder question than “should we adopt AI?” — it’s “can we trust AI to make security decisions?” To unpack this, The Cyber Express sat down with Adarsh Kant Sinha, Founder and CEO of ANVE.AI.
With expertise spanning AI architecture, Agentic AI, AI automation, and secure AI infrastructure, Adarsh brings a practitioner’s and builder’s perspective to the rapidly evolving AI landscape.
He has built a community of more than 25,000 ethical hackers, mentored startups, trained enterprise teams, advised organizations on AI strategy, and currently leads the development of AI products focused on agentic systems and voice-first human-computer interaction.
Watch the Full Podcast:
Adarsh Kant Sinha Explains Why AI Agents Could Become a New Cybersecurity Risk
Adarsh challenges the idea that the biggest AI security concern is simply whether an AI model can be manipulated. In his view, the bigger question is what happens when AI agents are given the ability to act independently across business systems.
An AI agent with access to Slack, email, CRM platforms, financial systems, and cloud infrastructure could potentially do far more than generate an incorrect answer. If compromised or manipulated, it could potentially use legitimate access to perform unauthorized actions — creating a new class of cybersecurity risk.
The shift from AI assistants to autonomous agents therefore changes the security equation. “Everyone wants AI agents,” but the more independence an organization gives an AI system, the more important it becomes to define what that system can access, what decisions it can make, and where human oversight remains necessary.

Not Everything Called an “AI Agent” Is One
Adarsh flags a separate problem before the trust question even applies: most of what founders and enterprises are calling “AI agents” isn’t agentic — it’s automation with better branding.
- Teams are still defining rigid workflows, not work goals — scripting the steps rather than giving the system an objective and letting it choose the path
- The label shifted industry-wide this year, but the underlying architecture in many deployments didn’t
- Business understanding is mixed — some are cautiously testing what can actually be automated; others have already rebranded existing automation as “agentic”
The distinction matters for security teams specifically: a system executing a fixed script has a bounded, auditable action space. A system pursuing a goal with discretion over how to get there does not. Conflating the two scopes assigns governance to the wrong risk category — writing oversight policy for autonomous decision-making when what’s running in production is deterministic automation, or the reverse.
Also Read: AI Won’t Replace Cybersecurity Jobs, It’ll Replace the Toil – Harsha Reddy Explains What’s Next
The conversation also explores why businesses may be moving faster with AI adoption than they are with AI governance. While organizations are investing heavily in AI capabilities, questions around permissions, accountability, data protection, and responsible deployment can sometimes come later.
Adarsh argues that AI security needs to move beyond protecting the model itself. Organizations need to consider the entire ecosystem around AI — including agents, data, identities, integrations, tools, and the actions AI systems are authorized to perform.
The conversation also digs into new risks around Voice AI. A realistic synthetic voice could create new opportunities for impersonation, social engineering, and fraud. As voice becomes more natural, it could also become another significant attack surface.
The discussion turns to another important question: should CISOs be more concerned about dramatic AI-generated attacks, or about AI systems quietly making the wrong decisions? Adarsh explores why excessive permissions, manipulated inputs, insecure integrations, and insufficient governance could become more significant risks as AI becomes embedded into enterprise workflows.
He also shares how he would approach red-teaming an AI-powered enterprise, why prompt injection may not be the only threat security teams should focus on, and what “enterprise-ready” AI should actually mean from a security perspective.
The conversation that leads to Express Shots, a new rapid-fire-styled questionnaire by The Cyber Express. Adarsh shares his take on AI Copilots vs. AI Agents, open-source vs. closed-source models, passwords vs. Passkeys, and the technology he believes is being overhyped.

