Microsoft's 2026 Digital Defense Report calls for stronger governance of agent identities and sensitive data as AI expands both the targets available to attackers and their capabilities. Its account distinguishes attacks against AI systems from attacks on conventional systems that use AI to increase speed or scale.
The report identifies risks around manipulated instructions, exposed data, compromised privileges, excessive agent actions and operational integrity. Microsoft links these to controls including scoped credentials, limits on tool use and changes, and records that can withstand tampering. These are the company's recommendations, rather than proof that any particular product prevents all such attacks.
For financial institutions, the practical question is whether an agent's authority is visible and enforceable throughout a workflow. A user may be entitled to view customer records while still requiring separate approval to amend them or initiate a payment.
Security reviews should therefore follow a complete task, including tool calls and handoffs between agents. Testing only the model's final answer can miss the point at which an instruction becomes a consequential action. The report offers a useful framework for asking where that authority is granted, checked and withdrawn.
