CertiK Report: From Assistive Tools to "AI Employees," How Agentic AI Is Reshaping Security and Compliance Work
- Key Takeaways: According to the CertiK report, AI is shifting from an assistive analysis tool to a "team member" capable of autonomously conducting investigations and remediation within defined permission boundaries. While this shift enhances security and compliance efficiency, it also introduces new requirements for enterprise permission management, AI oversight, and accountability mechanisms.
- Key Elements:
- Accelerating attack and money laundering speeds, a shortage of specialized talent, and increasing regulatory requirements are collectively driving AI's transition from assistive analysis to autonomous execution.
- Agentic AI can perform multi-step reasoning, invoke tools, integrate evidence, and autonomously remediate—distinguishing it from traditional AI that merely flags anomalies.
- In the Web3 space, AI has already been applied to smart contract auditing and on-chain fund tracing, with final judgments still made by engineers.
- Within one month of the Bybit attack, 86.29% of the stolen ETH was converted into Bitcoin, involving mixers, cross-chain bridges, and over-the-counter trading.
- Autonomous execution may amplify the risk of misjudgment, and agents themselves can become targets of attacks such as prompt injection.
- Enterprises need to clearly define agent permission boundaries, retain audit records, conduct regular red team testing, and designate human owners.

On October 5, CertiK, the world's largest Web3 security company, released its Intel3D report titled "The Rise of the AI Security Workforce: How Agentic AI Is Redefining Cybersecurity, AML, and Compliance." The report notes that AI is shifting from an auxiliary tool that helps analysts identify problems to a member of the working team capable of conducting investigations, making judgments, and taking action within defined permissions. This shift is reshaping security and compliance processes in both traditional finance and Web3, and it raises new demands on how enterprises supervise AI, define permissions, and allocate responsibility.
From Assisted Analysis to Autonomous Execution
The report argues that the speed of attacks and money laundering, the shortage of specialized talent, and increasingly stringent regulatory requirements are jointly driving this transformation. In the digital asset space, an attack can be completed within a single transaction, and stolen funds can be moved through multiple addresses and cross-chain bridges in a short period. At the same time, security and compliance teams face a continuously growing volume of alerts and transactions, and simply scaling up headcount is no longer sufficient to meet real-time monitoring and investigation needs.
Compared with traditional AI tools that can only flag anomalies or generate text, agentic AI can perform multi-step reasoning, call external tools, integrate evidence from different sources, and decide on next steps based on execution results. For example, after detecting an anomalous login, the system can combine device information, historical login locations, and threat intelligence to conduct an investigation, take action within established permissions, and leave a record for human review.
Security Auditing and AML Investigations Are Being Redivided
This trend is already reflected in traditional security and anti-money laundering work. CertiK explains that agentic systems can correlate logs across different systems, conduct preliminary triage of alerts, and hand off events requiring attention to human staff. In AML investigations, AI can aggregate transaction histories, customer profiles, and entity relationships to produce risk explanations and drafts of suspicious activity reports. Compliance personnel then shift more toward reviewing evidence, handling complex cases, and confirming whether reports should be filed.
In the Web3 space, smart contract auditing and on-chain fund tracing are key applications discussed in the report. AI-assisted audit agents can map cross-contract call relationships, analyze state changes, and help identify issues such as misconfigured access controls and insecure upgrade designs. Drawing on CertiK's security practice, the report notes that senior auditors' time allocation is changing: verifying AI findings, researching complex attack paths, and assessing the coverage and blind spots of AI tools have become more important, while final judgments remain the responsibility of engineers.
Cross-chain fund flows are also driving changes in investigation methods. Citing CertiK's previous research, the report states that within one month after the Bybit attack, 86.29% of the stolen ETH was converted into Bitcoin, involving mixers, cross-chain bridges, and over-the-counter trading channels. Such paths require investigation tools to continuously connect clues across multiple chains. The role of agentic AI in this scenario is to follow the investigation as funds move, rather than merely reconstructing transaction paths after the fact.
AI Enters Compliance Processes, and Its Own Behavior Must Also Be Audited
Compliance work is beginning to cover more pre-transaction and day-to-day operational stages: AI agents can assess counterparty addresses and transaction risks before settlement, continuously compare system configurations against control requirements, and assist in preparing regulatory reports. This gives compliance teams the opportunity to detect risks earlier and shorten the time between an anomaly occurring and human intervention.
As agents begin to directly hold and trade digital assets, execute trading strategies, or manage organizational funds, supervising AI itself has become a new compliance topic. Enterprises need to audit its on-chain behavior and retain the data it uses, the basis for its judgments, and its actual operations for subsequent review and forensics. The report emphasizes that having AI perform compliance work and determining whether AI itself is compliant are two different tasks, and deploying organizations remain responsible for the behavior of their agents.
Autonomous Execution Brings New Risks of Misjudgment and Attack
Autonomous execution capabilities can also amplify the impact of errors. CertiK warns in the report that models may misclassify a real intrusion as a harmless event, generate incorrect fund paths, or give unreliable security judgments about smart contracts. The more stable a system performs on routine tasks, the more likely human reviewers are to relax their verification, making rare but severe errors more likely to be missed.
Attackers can also use AI to accelerate vulnerability discovery, social engineering attacks, and reconnaissance. Security and compliance agents with access to sensitive data and tool-calling permissions may themselves become attack targets. Prompt injection or input manipulation could induce agents to approve fraudulent transactions or disable effective controls. Evaluating the security of AI therefore also requires testing its performance when faced with malicious inputs.
Permission Boundaries and Accountability Mechanisms Need to Be Established in Tandem
In response to these risks, CertiK recommends that enterprises clarify agents' responsibilities, permissions, and escalation paths at the deployment stage, specifying which operations can be executed autonomously and which must be approved by humans; retaining complete audit records for major decisions; and conducting regular red team testing. Each agent should also have a clearly designated human owner responsible for its performance and mistakes. The scope of work AI undertakes can expand, but the responsibility of the deploying organization and relevant personnel for the outcomes still remains.
Agentic AI is putting pressure on enterprises to advance adoption and governance in tandem. Teams lacking relevant capabilities may fall behind in processing speed, cost, and coverage, while enterprises that deploy autonomous systems without corresponding oversight mechanisms may introduce new operational and compliance risks. As AI takes on more critical tasks, enterprises need to adjust the division of labor accordingly, define permission boundaries, and implement oversight and accountability. The rise of the "AI workforce" is changing how security and compliance work is organized, and whether enterprises can continue to benefit from it will depend on whether their governance capabilities can keep pace with AI's execution capabilities.


