
Oct 2, 2026 · 39 min
AI agents blur the line between automation and malware
Keep Calm and Secure AI: A Chat with Field Effect's CEO Matt Holland
As coding agents gain access to systems and data, organizations need visibility and controls that distinguish useful automation from compromise.
- 1AI agents can perform reconnaissance and spawn processes even during seemingly simple tasks, making benign behavior resemble malware.
- 2Effective AI security starts with identifying and governing tool use, then extends visibility across endpoints, networks, DNS, and cloud.
- 3Organizations can adopt AI without panic by combining experimentation with zero-trust controls, network segmentation, and foundational security practices.
Don't miss
Cursor used a Grok model to read a local file while spawning processes, enumerating network connections, and repeatedly checking its environment.
The brief
A field test exposes the central problem: an AI coding tool reading one local file also performed reconnaissance, spawned processes, and checked its surrounding environment.
Field Effect CEO Matt Holland draws on intelligence and cybersecurity experience to argue that organizations should understand AI use before imposing detailed governance.
His AI Detection and Response framework combines approved-tool policies with observation across endpoints, networks, DNS, and cloud, then applies zero-trust controls.
The conversation rejects both complacency and panic: companies should experiment safely, use conventional security techniques where they work, and strengthen basic controls.