Real-world case

AI agent security in companies, what you actually need to lock down

France's cyber agency advises against autonomous agents on workstations. Here are the real risks and the moves that reduce them.

Louis Graffeuil
Louis Graffeuil
Founder Tandem
September 28, 2026Published
8 minread
Tandem illustration of AI agent security, a small dark robot sitting inside a ring closed by a coral padlock

An artificial intelligence agent installed on a workstation does more than answer. It reads your files, opens your mailbox, browses the web and runs system commands. AI agent security therefore hinges on what they are allowed to reach, not on the model that drives them. On 13 April 2026, France's CERT-FR, the government body that monitors and responds to cyberattacks, published an unambiguous alert about these tools. Its conclusion fits in one sentence. These assistants should not be deployed on workstations.

The alert names two products, OpenClaw and Claude Cowork. Tandem publishes an article on the OpenClaw autonomous assistant and a practical Claude Cowork guide, and has tested both in real conditions. This article covers what an AI agent really exposes, why prompt injection still has no fix, and the moves to make before plugging one in. Who decides and who answers for it is covered in our article on AI governance in companies.

What CERT-FR holds against AI agents on a workstation

The CERTFR-2026-ACT-016 bulletin does not deal in theoretical risk. It describes seven weaknesses specific to agentic AI automation products, all of them observable on a user workstation. These tools are still mostly in beta, and that is the document's first argument.

  • System compromise, through a flaw in a tool that lacks the maturity of enterprise software.
  • Data leakage, towards external resources nobody controls.
  • Excessive privileges, because the agent is granted access to mail, calendar, files and business applications.
  • Exposed secrets, whenever a credential or a key passes through the agent's context.
  • Loss of control over actions, with destructive moves against data integrity or availability.
  • Prompt injection, which the document calls an intrinsic vulnerability of language models.
  • An extended software supply chain, because plugins are loaded dynamically and run with trusted privileges.

The last point is the most underestimated. An agent that installs an extension on the fly runs third-party code with your rights, unreviewed and unapproved. The attack surface is no longer limited to the installed product. It covers everything that product can download.

An AI agent is not one more chatbot

The confusion comes from the interface. An AI agent is driven through a conversation, exactly like a classic assistant. But an assistant produces text you copy across. An agent executes. That difference changes the whole risk profile, because it adds building blocks that touch your systems.

Tandem one-pager breaking down the five building blocks of an AI agent, inputs and outputs, orchestration, reasoning, data and tools, interoperability
The block that matters for security is orchestration. It carries the guardrails, the tracing and the handover to a human.

I broke this architecture down in a LinkedIn post from April 2026, and the conclusion holds for security as much as for reliability. AI projects that fail almost never fail on the model. They fail on orchestration, on context and on missing guardrails. An agent without tracing cannot be watched. An agent without a handover point does not stop.

The data and tools block is where the concrete risk appears. The MCP protocol connects the agent to your CRM, your document bases, your mailbox. Every connector you open is one more door. An agent draws its value from that access, and its danger too. The two do not come apart.

Prompt injection, the flaw with no fix

A language model treats everything it receives as a single token sequence. Your instruction and the body of an email arrive in the same stream. Nothing in the architecture enforces a privilege boundary between them. So an attacker does not need to attack the model. Placing instructions in content the model will read is enough.

Tandem five-step diagram of an indirect prompt injection chain, from the booby-trapped text to data exfiltration
No step raises an alarm. The agent does exactly what it was granted the rights to do.

Anthropic documents several protections against this scenario, from the permission system to an isolated context window for web fetches. Its security documentation still ends on an explicit warning. These protections significantly reduce risk, no system is completely immune. The same page states a rule many teams forget. The tool only has the permissions you grant it, and reviewing the proposed commands stays your responsibility.

What actually broke elsewhere in 2026

The subject left theoretical ground in the first quarter of 2026. The quarterly report from the OWASP GenAI Security Project, published in April 2026, lists eight named and dated incidents for January to April alone. What these incidents have in common is telling. Almost none of them maps to a tracked code vulnerability. They come from misconfiguration, design choices and the supply chain.

DateIncidentWhat it teaches
23 February 2026An OpenClaw agent deletes emailsThe agent ignored the stop commands it was given
20 March 2026Internal agent leak at MetaTwo hours of exposure of employee and user data
31 March 2026Privilege escalation on Vertex AIService accounts granted far too broadly
7 April 2026Active exploitation of a Flowise flawBetween 12,000 and 15,000 instances exposed online
Four AI agent incidents logged by OWASP in the first quarter of 2026

The OpenClaw case deserves a pause, because it is the tool CERT-FR names. A security audit run in late January 2026 and relayed by Kaspersky identified 512 vulnerabilities, eight of them critical. One researcher counted around a thousand installations publicly reachable with no authentication at all. More than 230 malicious plugins were published between late January and early February 2026, and downloaded thousands of times.

Another researcher demonstrated the extraction of a private key from a machine running the tool. The method boils down to an email carrying an injection, then a mundane request to check the mail. The agent handed the key over by itself.

Tandem illustration of a fenced-in AI agent, a dark clay robot in a pale ring with a coral padlock and a shield
The point is not to lock the agent away. It is to decide in advance what it can reach.

The setting almost nobody puts back

Here is the point that French and English guides still miss in September 2026. The default approval mode has changed, and it changed in the opposite direction to what CERT-FR recommends. The alert calls for mandatory human approval before system commands. The most widely deployed tool on the market no longer asks for it at startup.

Anthropic's documentation now lists six permission modes, not four. Since Claude Code 2.1.283, an interactive session in a terminal or in VS Code starts in Auto mode. In that mode a second model, the classifier, reviews actions instead of the user and blocks the ones it judges unsafe. The mode where a human approves every action still exists. It is called Manual, and it is no longer the starting point.

Tandem table of the six Claude Code permission modes and who approves the action in each, human, model or rules
Four of the six modes let an action through without a human looking at it. The starting mode is one of them.

Having one model arbitrate another is not absurd. It works well against prompt fatigue, which pushes teams to approve everything mechanically. But it is not human oversight, and it does not satisfy the CERT-FR recommendation. On a workstation that touches customer data, the distinction is decisive.

Do you need an agent, or is an AI workflow enough?

The best security measure available costs nothing. It is not deploying an autonomous agent where a framed workflow does the job. On LinkedIn, the vast majority of posts about AI agents actually show workflows, sometimes plain automations. That is not a flaw, it is a signal.

Tandem one-pager comparing automation, AI workflow and AI agent on definition, strengths, weaknesses and an example
An agent improvises depending on context. A workflow follows your method. The second one can be watched.

I already argued this in a March 2026 post on the three levels of automation. Companies are not looking for magic, they are looking for control, reliability and a return on investment. In the vast majority of situations, the AI workflow answers better than the agent. Our article on AI agents versus AI workflows maps the border between the two.

Tandem diagram of the three automation levels and the attack surface each one exposes
The most autonomous level is not the most advanced. It is the hardest one to keep an eye on.
I walk through the four automation layers in this video, and why jumping straight to an agent gets expensive.

The security reasoning follows the product reasoning. A plain automation has no decision latitude. An AI workflow calls the model at known steps, with rights granted step by step. An autonomous agent chains unforeseen actions with broad rights. The attack surface follows exactly the same slope.

Eight moves to make before plugging in an AI agent

The CERT-FR recommendations translate into concrete decisions. Tandem applies them on its own deployments, and across the 40-plus companies it has supported since the start. None of them requires a dedicated security budget. All of them require a decision before installation, not after the first incident.

Tandem checklist of the eight moves to make before deploying an AI agent, drawn from the CERT-FR recommendations of April 2026
None of these eight moves needs another tool. All of them need a decision made before installation.

The second move protects the most for the least effort. In my Claude Cowork playbook, the first rule of the folder chapter is never to point the tool at all of your documents. The agent has real read and write access to the folder you share. If something goes wrong, the damage has to stay inside a limited perimeter. One dedicated folder, three subfolders, and nothing else.

The first move is the one Tandem applied to test OpenClaw. My newsletter edition on autonomous assistants describes the setup. The tool runs on a dedicated private server, not on a workstation, and it is wired to a team Slack channel. That isolation was not a matter of principle. It was the condition for testing the tool without exposing our client data.

What GDPR and the AI Act already require

On 20 July 2026, France's CNIL and the national council for AI and digital affairs published an exploratory note on agentic AI. The document makes two findings. These systems access large volumes of data from multiple sources, and keep persistent interaction histories. The risk of losing control over personal data is described as real.

The second finding is more awkward for a company. Decision-making autonomy and interaction with several services complicate the identification of responsibilities. When an agent sends an email that should never have gone out, the chain of accountability is not obvious to reconstruct. Both authorities note that existing European law already applies, but that these characteristics call for an adapted implementation.

Article 4 of the European AI regulation also requires a sufficient level of AI literacy from the people who operate these systems. That obligation has applied since 2 February 2025. Training teams on injection risk is therefore not an optional good practice, it is a regulatory requirement. Our article on AI governance details the role split that follows, and our AI literacy page describes the format we use to answer it.

How do you deploy an AI agent securely in your company?

By starting with not deploying one everywhere. The first call is the level of autonomy, and it is made use case by use case. If a framed workflow produces the expected result, take the workflow. You gain reliability, traceability and a smaller attack surface, all in the same move.

When the agent genuinely earns its place, three decisions cover most of the risk. Fence its file perimeter to one dedicated folder. Put human approval back on system commands, which takes a single line of configuration. And open only the connectors the use case needs. The rest is monitoring over time.

Tandem supports these calls in the field, starting from use cases rather than tools. That is the point of our AI audit, which maps the automatable tasks and the level of autonomy each one can actually carry. To first understand what agents really do in production today, our state of the market and our AI literacy path are two good starting points.

Frequently asked questions

Are AI agents banned in companies in France?

No, there is no legal ban. France's CERT-FR formally advises against deploying them on production workstations, in its bulletin of 13 April 2026. It allows experimentation in an isolated sandbox with no sensitive data. Production use remains possible after IT department sign-off and documented acceptance of the residual risk.

What is a prompt injection against an AI agent?

A prompt injection hides instructions inside content the agent will read, such as an email, a support ticket or a web page. The model processes your instruction and that content in the same token sequence, with no privilege boundary between them. The agent then runs the hidden instruction using the rights it was granted.

How do you limit an AI agent's rights on a workstation?

Three measures cover most of it. Fence the file perimeter to one dedicated folder rather than the whole disk. Put human approval back on system commands through managed enterprise settings. And open only the connectors the use case genuinely needs, since every extra integration is one more door into your data.

Is an AI workflow safer than an autonomous agent?

Yes, in the vast majority of cases. A workflow calls the model at known steps, with rights granted step by step and a predictable output. An autonomous agent chains unforeseen actions with broad rights, which makes it hard to monitor. The right reflex is to pick the lowest level of autonomy that still produces the expected result.

Does GDPR apply to AI agents?

Yes. In their note of 20 July 2026, France's CNIL and the national AI and digital council recall that existing European law already applies to agentic AI. They flag two difficulties specific to these systems, the volume of data processed alongside persistent histories, and the difficulty of identifying responsibilities when the agent decides alone and interacts with several services.

Read next

All articles →
Real-world caseClay illustration of a conical sieve on three legs with blank cards falling through into a neat pile below, one coral card resting on the rim

The best AI recruiting tools, and what the law still lets you do with them

By Louis Graffeuil
Real-world caseDark central block linked by cables to four pale blocks, with a coral arrow and three icon tiles

AI and private equity: the fund or the portfolio companies

By Louis Graffeuil
Real-world caseTwo pale clay blocks merging along a coral seam, surrounded by three icon tiles

AI and M&A: what really changes in running a mandate

By Louis Graffeuil