CrowdStrike Warns AI Agents Are Reshaping Cyber Attacks in the GCC
Zeta42 · 21 September 2026
CrowdStrike's Roland Daccache says over-privileged AI agents and near-instant attacks mean GCC organisations adopting AI must rethink identity and security operations.
AI agents need identities, and most have too much access
As organisations across the Gulf Cooperation Council accelerate AI adoption, CrowdStrike is warning that the same technology is changing how cyber attacks are launched and how security teams must respond. "AI has dramatically expanded the attack surface," said Roland Daccache, CrowdStrike's director of sales engineering for the Middle East and Africa, according to Computer Weekly. Threats, he said, now target models, infrastructure, large language models, cloud assets and identity assets.
The sharpest point concerns identity. AI has moved, in Daccache's words, "from being an information provider via chat to full autonomy and agency". An AI agent sitting on a machine, he said, can execute scripts, run commands, move laterally to other assets and browse the internet. In security terms, that makes an agent look less like a piece of software and more like a colleague with a login, and it has to be managed that way.
"Today, most AI agents are over-provisioned with privileges, and this creates a huge exposure gap for organisations," Daccache said. "One of the biggest challenges organisations face is how to grant identities to AI agents safely and securely." His prescription is a security strategy that covers "everything from the endpoint and browser traffic to cloud assets and – most importantly – identity".
Attacks at machine speed
The second shift is speed. CrowdStrike tracks breakout time: how long an attacker takes to move laterally through a compromised environment after gaining initial access. Daccache said the fastest breakout time in the company's last Global threat report was around 27 seconds, and that CrowdStrike chief executive George Kurtz recently said the concept of breakout time is dying, with attacks becoming instant.
"Most traditional security operations were designed around human analysts, where response processes could take minutes or even hours," Daccache said. His advice to CISOs is to stop trying to retrofit traditional technologies such as DLP or firewalls to protect against modern attacks, and to slowly retire traditional solutions in favour of genuine AI-powered technologies.
That advice comes from a security vendor, and it should be read with that in mind. Replacing security tools is a big commitment, and "AI-powered" is an easy label to put on a product. Daccache draws a similar line himself, urging organisations to back technologies that are "actually using AI within their technology stack" and not "simply using AI as hype". The core argument holds either way. A security team built around human response times will struggle against software that acts in seconds.
What it means for AI adoption in the GCC
Computer Weekly notes that governments and enterprises across the region are investing heavily in AI while facing a growing volume of cyber threats fuelled by geopolitical tensions. "We all know that at the moment we live in a period of geopolitical tensions," Daccache said. "That means cyber attacks are becoming more frequent and more destructive." He pointed to repeated warnings from UAE Cyber Security Council chairman Mohamed Al Kuwaiti about the large number of cyber attacks targeting the country's digital infrastructure each day.
For organisations rolling out agents, the practical lesson is to treat access as part of the design. Each agent should get only the permissions its task needs, and someone should be accountable for what it does. Zeta42 believes anyone learning to build with AI agents should learn to scope their permissions from the start, whether or not they work in security. Adoption in the GCC is moving quickly, and the skills to deploy agents safely have to keep pace with it.
Source: computerweekly.com
