YOU DO NOT COPY PROFESSIONALISM. YOU ALIGN WITH IT.
HOME / SERVICES / AI SECURITY / OWASP TOP 10

ASI10 - ROGUE AGENTS

An analyst needed supplier documents summarised every Monday. The approved tool could not do it, procurement was six weeks out, and the work was due. So she ran something on her laptop, connected it to the shared drive with her own credentials, and solved the problem. It has run every Monday since. Nobody approved it, nobody logs it, and it holds her access rights. This is ASI10 on the OWASP Top 10 for Agentic Applications, published 9 December 2025. Shadow AI and rogue agents in South Africa are a POPIA and King V exposure long before they are a security incident, and the mechanism is almost never malice.

THE AGENTS THAT WILL HURT YOU ARE THE ONES NOBODY REGISTERED.

Agent ecosystem diagram with nine governed agents inside a policy boundary and one rogue agent operating outside it, unsupervised.
DEFINITION

WHAT THIS RISK ACTUALLY IS

ASI10 covers agents operating outside sanctioned processes: unregistered, unowned and unmonitored. They hold real credentials, touch real data and take real actions. The category also includes sanctioned agents that drifted, agents left running after a project closed, and agents created by other agents.

The scale is not marginal. KnowBe4 reports that 64% of South African organisations say their AI use is unapproved or ungoverned, with the caveat that the sample size is not published by the producer. The same body of work reports that 35% of employees source their own AI tools where approved options are unavailable, and that 48% of security leaders say unsanctioned software has affected their security posture. Read those together and the mechanism is visible. This is not a discipline problem. It is a supply problem. People solve real work with the tools available to them.

Project mortality feeds the same pool. Gartner forecasts that over 40% of agentic AI projects will be cancelled by the end of 2027. A cancelled project rarely revokes its service accounts, API keys and integration tokens on the day it is cancelled. The agent stops being anyone’s responsibility while remaining connected.

Then there is the detection problem, which is architectural rather than a matter of effort. Much of this runs locally on endpoints. Network proxies and cloud access brokers monitor the wrong layer for an agent executing on a device, reading local files, and reaching out over channels that look like ordinary application traffic. A security team can hold a complete picture of sanctioned cloud AI usage and still be blind to the majority of what is actually running.

Local execution also inherits component risk. In April 2026, OX Security published research on the Model Context Protocol identifying a design-level flaw rooted in unsafe defaults in the STDIO transport configuration, enabling arbitrary command execution. 10 CVEs issued and counting, per OX Security. Those defaults ship with components an unsupervised builder installs in an afternoon.

And when something goes wrong, attribution fails. Arkose Labs found in February 2026 that 26% of enterprises are very confident they could prove an AI agent was involved in an incident, in a survey with no African respondents. For an agent that was never registered, the number is zero.

DOCUMENTED CASE

WHAT IT LOOKS LIKE IN PRACTICE

The following is an illustration, not a client engagement.

WHAT THIS MEANS UNDER SOUTH AFRICAN LAW

DISCOVERY

NEWORDER connects to CI/CD pipelines to automatically discover and inventory every homegrown AI application, and integrates directly with AWS Bedrock, Google Vertex AI, Salesforce, and other cloud and third-party platforms for visibility into AI agents. Each AI system is profiled across its model, system prompt, tools, guardrails, policies, and configurations, and the inventory stays current on every change. You cannot secure what you cannot see; discovery is the non-negotiable first step.

AI SECURITY POSTURE MANAGEMENT (AI-SPM)

NEWORDER conducts a static analysis of every application’s configuration, policy coverage, and third-party dependencies and identifies any policy gaps. In addition, it maps each agentic application to its coverage of major frameworks, including NIST, OWASP, and MITRE. This gives you a clear, measurable view of your AI security posture before a single adversarial test is run, turning assumptions into evidence and compliance into a continuous output rather than a periodic exercise.

AI RED TEAMING

NEWORDER’s automated AI red teaming covers the complete kill chain from reconnaissance to exploitation. It proactively discovers exploitable vulnerabilities through automated reconnaissance and adversarial testing purpose-built for agentic applications. Static attacks draw from a 300K+ payload library with 100% MITRE and OWASP LLM and Agentic Top 10 coverage, running comprehensive sweeps of known jailbreak patterns, content moderation bypasses, and obfuscation techniques. Dynamic attacks use multi-turn and continuous probing to test how an application holds up across extended adversarial sequences, not just a single interaction. High-agency attacks deploy extremely customised, bespoke attack techniques through probing tailored specifically to the intent and design of each application.

RUNTIME PROTECTION

NEWORDER offers policy enforcement and AI threat protection at the proxy, API, or AI Gateway layer. Protection adapts as the applications evolve and as new capabilities are added. When an attack hits production, whether a jailbreak, a prompt injection, or any other AI threat, it is blocked in real time and an immediate alert is sent with full context, including what happened, which application was targeted, what the impact is, and what to do next. Key performance metrics include 98.6% threat detection accuracy, 1.4% false positive rate, sub-200ms time to detect, sub-50ms real-time blocking, and immediate mean time to respond.

King V

, effective for financial years beginning on or after 1 January 2026, holds the governing body accountable for the effective, compliant and ethical acquisition, development, use and distribution of technology, with demonstrable accountability for decisions, actions, outputs and outcomes, human oversight and override mechanisms proportionate to risk, and periodic assurance.

Read that phrasing carefully. It says acquisition, development, use and distribution. An agent an employee builds on a laptop was acquired, developed, used and distributed to two colleagues. The governing body is accountable for it whether or not anyone told the board it exists, and a governing body cannot give periodic assurance over an estate it has not enumerated.

POPIA sections 19 to 22

cover security safeguards, operator obligations and notification. Notification of a compromise goes to the Information Regulator and to affected data subjects.

An unapproved tool processing customer records on your behalf is an operator relationship with no contract, no security assessment and no notification path. Section 21 does not stop applying because procurement was never involved.

POPIA section 71

restricts decisions based solely on automated processing that have legal consequences for a person or substantially affect them. An unregistered agent that filters, scores or prioritises people is making exactly that kind of decision outside every control designed to govern it.

The Cybercrimes Act 19 of 2020, section 2

, makes unlawful access an offence. An agent operating with inherited credentials beyond the purpose for which access was granted puts the organisation in an uncomfortable position, and puts a well-meaning employee in a worse one.

Joint Standard 2 of 2024

, in force 1 June 2025 for banks, insurers, asset managers, retirement funds and credit rating agencies, requires a board-approved cyber risk charter, documented evidence of control testing including vulnerability scans, penetration tests and simulated incidents, a maintained testing calendar, and notification of material incidents to the FSCA or Prudential Authority potentially within 24 hours.

You cannot test a control over an asset you have not identified. An agent inventory is the precondition for every piece of evidence the standard asks for, and the 24 hour clock does not pause while you work out what the thing on the analyst’s laptop was connected to.

The SARB, FSCA and Prudential Authority joint report of 24 November 2025 set out the supervisory direction: explainability, model risk management, data governance and board-level oversight. Model risk management over models nobody registered is a contradiction, and supervisors will treat it as one.

South Africa has no dedicated AI legislation. The National AI Policy was gazetted in April 2026 and withdrawn on 26 April 2026 after fabricated citations were found in its reference list, with a revised draft targeted for January 2027. Nobody should read that delay as breathing room. The obligations above are already in force.

QUESTIONS TO ASK BEFORE YOUR NEXT AGENT GOES LIVE

  • Do we have a current inventory of every agent running against our data, including the ones on employee workstations?
  • Which approved capability is missing, such that a competent employee would reasonably build their own?
  • Does any agent authenticate as a person rather than holding its own identity, and can we tell the difference in our logs?
  • When a project is cancelled or an employee moves on, what process revokes the agents and tokens they created?
  • What visibility do we have into AI running locally on endpoints, given that our proxies and cloud brokers monitor a different layer?
  • If an unregistered agent accessed customer records last night, how long would it take us to establish that, and could we do it inside 24 hours?
FREQUENTLY ASKED QUESTIONS

FAQ

Because much of it runs locally on devices. Network proxies and cloud access security brokers monitor traffic and sanctioned cloud services, which is the wrong layer for an agent executing on an endpoint, reading local files and using credentials already issued to the user. Detection has to start from identity behaviour and endpoint inspection. KnowBe4 reports 64% of South African organisations describe their AI use as unapproved or ungoverned, though the sample size is not published.

Usually not. The reported pattern is people solving real problems with unapproved tools because approved ones do not exist. Research attributed to KnowBe4 records 35% of employees sourcing their own AI tools where approved options are unavailable. Treating it as misconduct drives it further out of sight. Treating it as a supply gap surfaces the inventory you need for King V assurance and Joint Standard 2 evidence.

The hub page, The OWASP Agentic Top 10 for South Africa, carries the regulatory mapping across all ten risks. Read this with ASI03 Identity and Privilege Abuse, which covers what happens when an agent borrows a person’s credentials. The Agentic Red Team page describes how our operators build an agent inventory from identity and endpoint evidence.

WHERE TO GO FROM HERE

TAKE ACTION

TEST IT BEFORE SOMEBODY ELSE DOES

Thirty minutes on your agent estate and what this risk looks like in your environment.