
A new report from Certik suggests viewing artificial intelligence agents as part of the workforce: they have evolved from passive alerts to autonomous actions. Such systems perform multi-step reasoning, integrate external APIs, and take live corrective actions with minimal human intervention. According to the report, organizations should manage agent AI as an autonomous workforce participant: assign explicit roles, limited authority, and strict human supervisor accountability. As managers retain 100% legal and operational responsibility, agents must operate within limited authority, with escalation protocols and designated oversight. This shift is necessary amid machine-speed attacks, a cybersecurity workforce shortage, and money laundering fines exceeding $900 million in just the first half of 2025.
Natalie Newson, a senior blockchain researcher at Certik, disagrees that defenders are constantly playing catch-up. She acknowledges that AI enhances attackers but emphasizes the defenders' advantage: home-field advantage. “We see the code before release, know what normal protocol behavior looks like, and can run the same AI exploit search against our own systems first. In Web3, everything an attacker does is on a public ledger, so their reconnaissance, funding, and test transactions leave a trail that machines read well,” Newson said. She warns that periodic defense will not withstand continuous assault: security must become dynamic.
Attackers benefit from the lack of regulatory friction, but according to Newson, speed does not guarantee success: “An attacker can move at machine speed, but they still need to go through the chain to get paid, and that's where monitoring and kill switches are.” Real-time monitoring of pending transactions allows automated systems to detect exploits and instantly pause contracts. Combined with audits and formal verification, this changes the threat economy, forcing attackers to outpace machines, not humans. The report also calls for a clear separation between agent execution and human oversight and making the audit of internal AI reasoning logs a mandatory discipline.
This material is prepared solely for informational purposes and does not constitute financial advice or a recommendation.




