Engineering brief
Social Engineering Won’t End; It’s Shifting to Your Agents
At a glance
- Relevance
- Practical value
- Warnings
- None
Most teams think LLMs will reduce social engineering risks. But attackers will pivot from tricking humans to manipulating AI agents, turning every agent into a potential authenticated insider threat that few IAM systems are ready for.
As AI agents gain autonomy, social engineering will target agent interfaces, not humans. Identity and trust architectures need a fundamental rethink.
Summary
Social engineering isn’t about to end. The real shift is who gets targeted. As LLMs become embedded in operating systems and identity systems, attackers will pivot from exploiting human trust to manipulating AI agents—the new weakest link.
The conversation reveals a deeper problem: agentic identity. Estonia’s proposal for AI agents to get personal IDs hints at future IAM, but also amplifies the risk of authenticated malicious agents. More agents means more attack surface, not less, unless identity architectures evolve.
Engineering leaders should watch how authentication moves from static credentials to behavioral patterns. The idea of an LLM learning your habits to verify you is promising, but randomness and false positives remain unsolved. You can’t steal a pattern, but you can trick the model that reads it.
The immediate takeaway: governance for non-human identities is now a red-team priority. The IBM–OpenAI partnership on appsec is noise unless your team is a direct consumer. Focus on securing agent-to-agent interactions before AI agents make trust decisions in production.
Watch the video
This video is blocked due to your privacy settings. To watch this video, please accept YouTube marketing cookies.
Related breakdowns
Anthropic's safety layering creates hidden non-determinism for agent workflows
Anthropic's safety-layered models create hidden non-determinism when classifiers silently swap engine behavior. The OpenAI Hugging Face escape shows…
The AI Security Trilemma: Speed, Smarts, Security – Pick Two
AI agents face a trilemma: smart, fast, secure – pick two. Learn how to prioritize and where a security proxy fits.
Five patterns for agent-tool connections: security grows, complexity follows
A security-minded ranking of five agent-to-tool connection patterns, from direct API calls to vault-backed short-lived credentials. The security gains are…
Get TL;DW
Too Long; Didn't Watch.
A concise breakdowns of the AI and devtools videos that actually matter for engineering leaders.
Free. Weekly. No hype.
Video and thumbnails remain the property of their respective creators. tldw.news provides editorial analysis, commentary, and discovery links to original content.