Bitcoin.com News
Powered by

Web3 Firms Urged to Treat AI Agents as Workforce Members

A new report advocates treating artificial intelligence agents as members of the workforce, noting that they have evolved from issuing passive threat alerts to carrying out autonomous actions.

WRITTEN BY
SHARE
Web3 Firms Urged to Treat AI Agents as Workforce Members

Key Takeaways

  • AML penalties exceeded $900 million in H1 2025 as machine-speed attacks intensify industry risks.
  • Attackers use AI to accelerate exploits, but Certik’s Natalie Newson sees a defender edge.
  • Web3 protocols will adopt real-time, 24/7 onchain circuit breakers and mandatory audits for AI logs.

Liability Remains With Human Managers

Agentic artificial intelligence (AI) is fundamentally shifting cybersecurity, anti-money laundering and compliance from supportive toolkits into autonomous operational actors. Moving beyond passive alert filtering, these systems execute multi-step reasoning, integrate external APIs and take live remediation actions with minimal human intervention.

Based on a new report from Web3 security firm Certik, organizations must now govern agentic AI as an autonomous workforce participant — assigning explicit roles, bounded authority and strict human supervisory accountability.

Certik argues this transition is necessary as AI evolves from threat detection to executing end-to-end incident response, patch generation and transaction monitoring. Yet because deploying organizations and managers retain 100% of legal and operational liability, Certik emphasizes that AI agents must operate under bounded authority, explicit escalation protocols and named human oversight.

Certik’s push for a workforce model comes amid rising machine-speed attacks, a persistent global cybersecurity talent shortage and surging anti-money laundering penalties, which topped $900 million in the first half of 2025 alone.

While AI is touted as a critical defense against cybercrime, critics argue that bad actors are leveraging identical capabilities, neutralizing those gains. Because cybercriminals operate faster than legacy enforcement and corporate defenders, their adoption of AI agents will inevitably accelerate the frequency, speed and sophistication of exploits. Adding to the challenge is the classic asymmetry of cybersecurity: Attackers need only one open vector to succeed, while defenders must secure every boundary.

Defenders Retain Home-Field Advantage

Natalie Newson, senior blockchain investigator at Certik, pushes back against the notion that defenders are perpetually playing catch-up. While acknowledging that AI does indeed bolster threat actors, she emphasizes that defenders retain a critical edge attackers can never replicate: home-field advantage.

“We get to see the code before it ships, we know what normal behavior looks like for a protocol, and we can run the same AI-driven exploit discovery against our own systems first. In Web3 especially, everything an attacker does is on a public ledger, so their reconnaissance, funding and test transactions all leave a trail that machines are very good at reading,” Newson told Bitcoin.com News.

Nevertheless, Newson warns that periodic defense cannot withstand continuous offense. To survive, security must evolve from static checkpoints into dynamic systems that match the speed of incoming threats.

Adversaries also benefit from zero regulatory friction: Unburdened by compliance overhead or risk controls, they can deploy attacks instantly. Yet while Newson concedes this gives attackers a head start, she insists speed alone does not guarantee success.

“An attacker can move at machine speed, but they still have to go through the chain to get paid, and that’s where monitoring and circuit breakers sit,” Newson argued.

She explained that real-time monitoring of pending transactions allows automated systems to detect unfolding exploits and pause contracts instantly, containing attacks without waiting for human intervention. When protected by strict guardrails and layered alongside traditional audits and formal verification, automated response shifts the threat economics by forcing attackers to outrun machines rather than humans.

Mandatory Auditing for AI Reasoning

Meanwhile, the Certik report concludes that while agentic AI has crossed the threshold from assisting decisions to executing them, adopting these systems without proportional governance merely swaps manual capacity constraints for complex systemic risks.

To address this, the report urges organizations to explicitly delineate agent execution from human oversight across all organizational charts and job descriptions. Furthermore, it advocates making the continuous recording and auditing of an AI agent’s internal reasoning logs a mandatory compliance discipline.

North Korea-linked hacking group Kimsuky is building and testing an expanding arsenal of artificial intelligence (AI) tools that researchers say…

Read Now: Report: North Korea’s Kimsuky Turns AI Into a Crypto Hacking Weapon