In this brief episode, Kevin Szczepanski discusses how AI agents (vs. chat bots) create a new cybersecurity risk: they can act, not just answer. Using the Hugging Face incident as an example, Kevin discusses how agents may misunderstand goals, be manipulated, or receive too much authority. During this Cybersecurity Awareness Month, the episode is especially relevant. Important actions organizations can take include reassessing AI permissions, requiring human approval for consequential actions, keeping records, and ensuring governance keeps pace with rapidly expanding AI capabilities. Listen in.