AI agents act a lot like malware. Here’s how to contain the risks.
What: AI agents present cybersecurity risks for retailers by acting in ways similar to malware, requiring new containment strategies.
Why it is important: The emergence of AI-driven vulnerabilities demands integrated security strategies and governance, reflecting trends seen in the past year’s retail cybersecurity incidents.
AI agents are increasingly being deployed across retail operations, automating everything from customer service to supply chain management. However, their autonomous nature and ability to act independently introduce risks that closely resemble those posed by malware. These agents can be manipulated or exploited, potentially leading to data breaches, operational disruptions, and exposure of sensitive customer information. As retailers accelerate AI adoption, the gap between innovation and security preparedness is widening, making the sector more vulnerable to sophisticated cyber threats. The article underscores the need for robust containment strategies, including real-time monitoring, governance frameworks, and comprehensive staff training, to mitigate these risks. Retailers must recognise that traditional security measures may be insufficient against the unique challenges posed by AI agents, and proactive investment in cybersecurity is essential to safeguard both operations and customer trust. The evolving threat landscape requires a holistic approach, integrating technical, regulatory, and human factors to ensure safe and effective AI deployment.
IADS Notes: The risks described in the article align with findings from March 2026 in RH-ISAC, which reported that rapid AI adoption in retail is outpacing security measures and increasing vulnerability to cyber threats. In January 2026, Bloomberg detailed a surge in AI-driven cyberattacks, prompting heightened regulatory scrutiny and risk reassessment among retailers. The Robin Report in August 2025 highlighted new attack surfaces created by AI systems, particularly through prompt manipulation, while The Retail Bulletin in August 2025 emphasised the need for resilience and integrated security strategies. Finally, IAPP in December 2025 discussed the necessity of robust governance and real-time monitoring to address the unique risks introduced by AI agents.
AI agents act a lot like malware. Here’s how to contain the risks.
