An artificial intelligence agent installed on a workstation does more than answer. It reads your files, opens your mailbox, browses the web and runs system commands. AI agent security therefore hinges on what they are allowed to reach, not on the model that drives them. On 13 April 2026, France's CERT-FR, the government body that monitors and responds to cyberattacks, published an unambiguous alert about these tools. Its conclusion fits in one sentence. These assistants should not be deployed on workstations.
The alert names two products, OpenClaw and Claude Cowork. Tandem publishes an article on the OpenClaw autonomous assistant and a practical Claude Cowork guide, and has tested both in real conditions. This article covers what an AI agent really exposes, why prompt injection still has no fix, and the moves to make before plugging one in. Who decides and who answers for it is covered in our article on AI governance in companies.
What CERT-FR holds against AI agents on a workstation
The CERTFR-2026-ACT-016 bulletin does not deal in theoretical risk. It describes seven weaknesses specific to agentic AI automation products, all of them observable on a user workstation. These tools are still mostly in beta, and that is the document's first argument.
- System compromise, through a flaw in a tool that lacks the maturity of enterprise software.
- Data leakage, towards external resources nobody controls.
- Excessive privileges, because the agent is granted access to mail, calendar, files and business applications.
- Exposed secrets, whenever a credential or a key passes through the agent's context.
- Loss of control over actions, with destructive moves against data integrity or availability.
- Prompt injection, which the document calls an intrinsic vulnerability of language models.
- An extended software supply chain, because plugins are loaded dynamically and run with trusted privileges.
The last point is the most underestimated. An agent that installs an extension on the fly runs third-party code with your rights, unreviewed and unapproved. The attack surface is no longer limited to the installed product. It covers everything that product can download.
An AI agent is not one more chatbot
The confusion comes from the interface. An AI agent is driven through a conversation, exactly like a classic assistant. But an assistant produces text you copy across. An agent executes. That difference changes the whole risk profile, because it adds building blocks that touch your systems.

I broke this architecture down in a LinkedIn post from April 2026, and the conclusion holds for security as much as for reliability. AI projects that fail almost never fail on the model. They fail on orchestration, on context and on missing guardrails. An agent without tracing cannot be watched. An agent without a handover point does not stop.
The data and tools block is where the concrete risk appears. The MCP protocol connects the agent to your CRM, your document bases, your mailbox. Every connector you open is one more door. An agent draws its value from that access, and its danger too. The two do not come apart.
Prompt injection, the flaw with no fix
A language model treats everything it receives as a single token sequence. Your instruction and the body of an email arrive in the same stream. Nothing in the architecture enforces a privilege boundary between them. So an attacker does not need to attack the model. Placing instructions in content the model will read is enough.

Anthropic documents several protections against this scenario, from the permission system to an isolated context window for web fetches. Its security documentation still ends on an explicit warning. These protections significantly reduce risk, no system is completely immune. The same page states a rule many teams forget. The tool only has the permissions you grant it, and reviewing the proposed commands stays your responsibility.
What actually broke elsewhere in 2026
The subject left theoretical ground in the first quarter of 2026. The quarterly report from the OWASP GenAI Security Project, published in April 2026, lists eight named and dated incidents for January to April alone. What these incidents have in common is telling. Almost none of them maps to a tracked code vulnerability. They come from misconfiguration, design choices and the supply chain.
| Date | Incident | What it teaches |
|---|---|---|
| 23 February 2026 | An OpenClaw agent deletes emails | The agent ignored the stop commands it was given |
| 20 March 2026 | Internal agent leak at Meta | Two hours of exposure of employee and user data |
| 31 March 2026 | Privilege escalation on Vertex AI | Service accounts granted far too broadly |
| 7 April 2026 | Active exploitation of a Flowise flaw | Between 12,000 and 15,000 instances exposed online |
The OpenClaw case deserves a pause, because it is the tool CERT-FR names. A security audit run in late January 2026 and relayed by Kaspersky identified 512 vulnerabilities, eight of them critical. One researcher counted around a thousand installations publicly reachable with no authentication at all. More than 230 malicious plugins were published between late January and early February 2026, and downloaded thousands of times.
Another researcher demonstrated the extraction of a private key from a machine running the tool. The method boils down to an email carrying an injection, then a mundane request to check the mail. The agent handed the key over by itself.

The setting almost nobody puts back
Here is the point that French and English guides still miss in September 2026. The default approval mode has changed, and it changed in the opposite direction to what CERT-FR recommends. The alert calls for mandatory human approval before system commands. The most widely deployed tool on the market no longer asks for it at startup.
Anthropic's documentation now lists six permission modes, not four. Since Claude Code 2.1.283, an interactive session in a terminal or in VS Code starts in Auto mode. In that mode a second model, the classifier, reviews actions instead of the user and blocks the ones it judges unsafe. The mode where a human approves every action still exists. It is called Manual, and it is no longer the starting point.

Having one model arbitrate another is not absurd. It works well against prompt fatigue, which pushes teams to approve everything mechanically. But it is not human oversight, and it does not satisfy the CERT-FR recommendation. On a workstation that touches customer data, the distinction is decisive.
Do you need an agent, or is an AI workflow enough?
The best security measure available costs nothing. It is not deploying an autonomous agent where a framed workflow does the job. On LinkedIn, the vast majority of posts about AI agents actually show workflows, sometimes plain automations. That is not a flaw, it is a signal.

I already argued this in a March 2026 post on the three levels of automation. Companies are not looking for magic, they are looking for control, reliability and a return on investment. In the vast majority of situations, the AI workflow answers better than the agent. Our article on AI agents versus AI workflows maps the border between the two.

The security reasoning follows the product reasoning. A plain automation has no decision latitude. An AI workflow calls the model at known steps, with rights granted step by step. An autonomous agent chains unforeseen actions with broad rights. The attack surface follows exactly the same slope.
Eight moves to make before plugging in an AI agent
The CERT-FR recommendations translate into concrete decisions. Tandem applies them on its own deployments, and across the 40-plus companies it has supported since the start. None of them requires a dedicated security budget. All of them require a decision before installation, not after the first incident.

The second move protects the most for the least effort. In my Claude Cowork playbook, the first rule of the folder chapter is never to point the tool at all of your documents. The agent has real read and write access to the folder you share. If something goes wrong, the damage has to stay inside a limited perimeter. One dedicated folder, three subfolders, and nothing else.
The first move is the one Tandem applied to test OpenClaw. My newsletter edition on autonomous assistants describes the setup. The tool runs on a dedicated private server, not on a workstation, and it is wired to a team Slack channel. That isolation was not a matter of principle. It was the condition for testing the tool without exposing our client data.
What GDPR and the AI Act already require
On 20 July 2026, France's CNIL and the national council for AI and digital affairs published an exploratory note on agentic AI. The document makes two findings. These systems access large volumes of data from multiple sources, and keep persistent interaction histories. The risk of losing control over personal data is described as real.
The second finding is more awkward for a company. Decision-making autonomy and interaction with several services complicate the identification of responsibilities. When an agent sends an email that should never have gone out, the chain of accountability is not obvious to reconstruct. Both authorities note that existing European law already applies, but that these characteristics call for an adapted implementation.
Article 4 of the European AI regulation also requires a sufficient level of AI literacy from the people who operate these systems. That obligation has applied since 2 February 2025. Training teams on injection risk is therefore not an optional good practice, it is a regulatory requirement. Our article on AI governance details the role split that follows, and our AI literacy page describes the format we use to answer it.
How do you deploy an AI agent securely in your company?
By starting with not deploying one everywhere. The first call is the level of autonomy, and it is made use case by use case. If a framed workflow produces the expected result, take the workflow. You gain reliability, traceability and a smaller attack surface, all in the same move.
When the agent genuinely earns its place, three decisions cover most of the risk. Fence its file perimeter to one dedicated folder. Put human approval back on system commands, which takes a single line of configuration. And open only the connectors the use case needs. The rest is monitoring over time.
Tandem supports these calls in the field, starting from use cases rather than tools. That is the point of our AI audit, which maps the automatable tasks and the level of autonomy each one can actually carry. To first understand what agents really do in production today, our state of the market and our AI literacy path are two good starting points.



