
What Is Agentic AI in Security? Risks, Reality, and the Problem with AI-Washing
Artificial intelligence continues to reshape the security industry, but not every new AI label represents a genuine technological advancement. One of the latest terms gaining traction is "agentic AI" - a concept that is increasingly being applied to security products, often without a clear understanding of what it means or whether it is appropriate for life-safety applications. For security professionals responsible for protecting people, assets, and critical infrastructure, distinguishing between meaningful innovation and marketing hype is essential.
In this article, we examine what agentic AI actually is, why many claims of "agentic" security solutions are misleading, and the legal, operational, and ethical concerns that arise when autonomous decision-making is introduced into high-consequence security environments. For additional perspective on this growing trend, we also recommend reading Albert Stepanyan's recent article, “The Dirty Secret of Agentic Security AI You Probably Wouldn't Like” which explores many of the same concerns surrounding autonomy, accountability, and trust in security technology.
In most cases, this is AI-washing - overstating the role of artificial intelligence in a product when the underlying technology doesn’t justify this. The “agentic AI” version of AI-washing takes a fixed workflow and describes it as agentic.
There is also real agentic AI, which represents a different and deeper issue.
How do you make sense of these claims and what is the reality of agentic AI in our industry?
What is agentic AI?
Agentic AI has a specific definition. It is AI that can be given an outcome and can use different tools and approaches without supervision or direction to achieve that outcome.
Natural language footage search, automatic incident summaries, rules-based processes and detection of critical events are AI features offered by many vendors including Scylla but are not “agentic AI”.
Agentic AI is typically found in AI that can perform simple repeated tasks such as research or write code. Claude Cowork and Claude Code are examples of agentic AI. Less successful examples of agentic AI are found in recent cases where AIs have been given vending machines or cafes to manage and have made bizarre decisions such as stocking the vending machine with tungsten cubes.

AI snake oil alert: "Agentic AI" in video security
Every AI video analytics vendor suddenly claims to be "agentic," but most security systems remain traditional detection and automation pipelines wrapped in new marketing language. Learn how to spot AI snake oil, evaluate vendor claims, and separate genuine innovation from hype before making a security technology investment.
Read moreWhy you should be wary of “agentic AI” security products
There are two broad areas of concern, firstly where agentic AI is claimed and isn’t there, and secondly where agentic AI is used in an unsuitable or legally risky way. This last area has multiple implications.
Marketing hype
Integrity is everything with products that security professionals depend upon to protect human life. Unless you can exhaustively test the entire product, you are reliant on the vendor’s representations. False claims of agentic AI undermine any credibility about other aspects of the product.
If a vendor can’t accurately market key aspects of the solution without resorting to exaggeration and untrue claims, what else are they misrepresenting? Can you trust any claims of someone who adds a feature that doesn’t exist?
Consequences, irreversibility and oversight
Agentic AI should not make vital decisions that someone needs to be responsible for. The consequences of security decisions are often life changing and require human accountability and judgement.
Agentic AI applied to security is different from agentic AI applied to software development or informal research. These areas have low consequences and can be reversed whilst security decisions have high consequences and are irreversible.
If there is a fire and an AI locks all the doors to contain the fire but stops people from escaping, that is a different degree of consequence than leaving some software improperly formatted until someone gets back to their desk with a coffee. If a heavily armed SWAT team is incorrectly called out to an elementary school by an agentic AI, the potential impact is different to an agentic AI missing out a cafe in a restaurant guide.
Agentic AI is suitable only where the consequences are minor, where the result is reversible and where there is a human in the loop to check the results at each critical point. However, agentic AI is specifically marketed with claims of autonomy, without continual human oversight. This is completely mismatched to the needs of the security environment.

Beyond AI snake oil: Red flags in vendor claims
Not every ‘self-learning’ or anomaly detection company is telling the truth. Many hide behind buzzwords, fake metrics, and overblown claims of perfection. This article from Scylla AI cuts through the noise, revealing how to identify real-world performance and spot snake oil before it costs you.
Read moreDefensible processes
Security has defined processes precisely because the way that an incident is responded to is just as important as the final outcome. In any regulated area, processes are established and followed to ensure a defensible result. Agentic AI that can achieve an outcome by multiple means is the opposite to what is needed for security.
An agentic AI finding its own way to an outcome is the same as getting someone off the street without any training or procedures and expecting them to adequately respond to security events. No security professional would try this because it would be inexcusable if something went wrong.
In any legal issue or security audit, an agentic AI would be equally unacceptable precisely because it does not follow approved standard operating procedures to get to an outcome. Even if the outcome is correct, the process to get there is not repeatable, is inexplicable and can’t be audited or defended. How comfortable would you be in court to defend a solution that arrives at a result by an unknown, nonprocedural approach.
Failure rates
Good AI retains human oversight and supports decision making. For example, Scylla accurately identifies critical events across huge camera networks, eliminating cognitive overload and presents this selected information to a security officer, who can then make a decision based on context, documented procedures and their own judgement. This leverages the strengths of both humans and AI.
Agentic AI for security removes humans as a check even though agentic AI is a new and unproven technology with relatively poor accuracy and repeatability. This works only for low consequence work.
A good AI may have 95% accuracy, which sounds very high but isn’t compared to what we expect in daily life, or from security operations. If you drove your car to work and were 95% safe, you would expect to have a serious crash 1 day out of every 20, or once per month. There are about 100,000 commercial flights per day carrying over 10 million passengers. A 95% success rate would result in 5,000 crashes and 500,000 air crash fatalities per day.

Final Takeaway
Most marketing talk about “agentic AI” is hype rather than a technology breakthrough. But even if agentic AI was in a security product, you wouldn’t want it. This technology is fundamentally at odds with the need for accurate, repeatable and responsible security decisions. Agentic AI has very profound legal and ethical implications in situations where protecting human life is paramount.
Scylla is committed to developing highly usable security products and marketing these accurately and ethically. We continue to empower human judgement by identifying critical events and highlighting these, using AI to help streamline security workflows without removing vital human oversight.
About the Author

Graeme Woods
Global Business Analyst
Graeme Woods is a Global Business Analyst specializing in AI video analytics market intelligence, technology trends, and the strategic implications of AI adoption in different spheres of technology. He has authored numerous widely-read industry articles covering topics from edge-cloud architecture and VMS consolidation to LLM applications in video analytics, and has been published in international security industry outlets including Defense & Security Middle East. His writing bridges the gap between technical AI capability and the practical decisions facing security directors, enterprise leaders, and system integrators worldwide.
Learn MoreStay up to date with all of new stories
Scylla Technologies Inc needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.
Related materials

Beyond AI snake oil: Red flags in vendor claims
Not every ‘self-learning’ or anomaly detection company is telling the truth. Many hide behind buzzwords, fake metrics, and overblown claims of perfection. This article from Scylla AI cuts through the noise, revealing how to identify real-world performance and spot snake oil before it costs you.
Read more
AI snake oil alert: "Agentic AI" in video security
Every AI video analytics vendor suddenly claims to be "agentic," but most security systems remain traditional detection and automation pipelines wrapped in new marketing language. Learn how to spot AI snake oil, evaluate vendor claims, and separate genuine innovation from hype before making a security technology investment.
Read more
What All Security Directors Should Understand About AI Bias and Surveillance Compliance
Explore the regulatory landscape surrounding AI surveillance to better address AI bias and ensure your video surveillance systems are both effective and compliant with global standards.
Read more
