CertiK says security and compliance teams are beginning to deploy AI systems that can investigate incidents and take limited response actions, moving beyond tools that merely summarize data or flag suspicious activity. The change could reshape how digital-asset firms handle hacks, money-laundering alerts and smart-contract risks, while placing greater weight on permission controls, audit logs and named human accountability.
In its Oct. 5 Intel3D report, The rise of the AI security workforce: how agentic AI is redefining cybersecurity, AML, and compliance, the blockchain-security firm describes “agentic AI” as software that can work through multistep tasks, gather evidence from external tools and select follow-up actions within pre-set limits.
That model differs from conventional AI assistants that identify anomalies, answer questions or produce draft text for a human operator. An agent can be configured to investigate an unusual login, collect device information and historical location data, compare the event against threat-intelligence feeds, and then take approved steps such as escalating the case or restricting access. The system would also create records for human review.
CertiK’s central argument is that AI is shifting from an analytical support tool into a supervised operational layer for security and compliance teams. The report does not suggest that firms can remove human decision-makers from sensitive processes. Instead, it presents a division of labor in which agents handle repetitive investigation and data correlation while staff retain responsibility for high-impact judgments and formal approvals.
Faster attacks are straining existing response models
Digital-asset security presents a particularly difficult operating environment because an exploit can be completed in a single blockchain transaction. Once funds are stolen, they may move through many wallets, bridges, mixers and other routes across multiple networks within a short period.
That pace can overwhelm teams working through manual alert queues. CertiK said its report identifies three forces behind the adoption of more autonomous systems: faster attacks and laundering methods, a limited supply of specialized security and compliance staff, and expanding regulatory requirements.
The proposed role for AI is therefore less about replacing a security operations center than reducing the time between an alert and an initial investigation. In a conventional workflow, an analyst may need to open separate tools for authentication records, blockchain transactions, address intelligence and internal account information. An agent can pull together those sources and prepare a case file before a human reaches it.
In anti-money-laundering work, CertiK said agents can combine transaction histories, customer records and known entity relationships into risk narratives and draft suspicious activity report documentation. Compliance personnel would be expected to test the evidence, assess whether the activity meets reporting thresholds and make the final filing decision.
That arrangement could be useful for compliance teams facing high alert volumes, but it also makes the quality of the underlying data and rules more consequential. A system that draws incorrect links between addresses or entities could send staff down the wrong investigative path, particularly where blockchain activity includes layered transfers across multiple networks.
Smart-contract reviews move toward AI-assisted investigation
CertiK also sees agentic systems taking a larger role in smart-contract security. Audit agents can map relationships among contracts, track state changes and inspect cross-contract calls, helping reviewers identify potential access-control failures, unsafe upgrade mechanisms and other technical weaknesses.
The report frames this as a change in the work of senior auditors rather than an automation of final audit judgments. Experienced engineers would spend more time verifying an agent’s findings, examining complex attack paths and testing whether the tooling missed relevant contract behavior.
Smart-contract analysis has long involved a trade-off between broad automated scanning and careful manual review. Automated tools can examine extensive code bases quickly, but they may struggle with application-specific logic or multi-contract interactions. CertiK’s model would give AI a more active role in connecting those pieces while leaving engineers responsible for deciding whether a suspected issue is exploitable and severe enough to report.
Cross-chain tracing is another area where the report expects agents to be used. CertiK cited its earlier research into the Bybit attack, which found that 86.29% of the stolen ETH had been exchanged into Bitcoin within one month through routes involving mixing services, cross-chain bridges and over-the-counter trading.
Such movements require investigators to maintain links among addresses and transactions as funds travel, rather than attempting to rebuild the trail only after assets have dispersed. Automated agents could continually update those links and flag route changes that merit immediate human review.
Autonomous tools create a new control problem
Giving software the ability to act introduces risks that go beyond faulty alerts. CertiK warned that an autonomous system could misclassify a genuine intrusion as harmless, construct an inaccurate fund-flow path or reach an unreliable conclusion about a smart contract’s security.
The risk increases when an agent is permitted to execute actions. A bad recommendation in an internal report can be corrected before use; an incorrect automated restriction, approval or transaction can have immediate consequences. The report argues that firms need to define which activities are safe for autonomous handling and which must require a human sign-off.
CertiK also highlighted a human-factors concern: reliable performance on routine cases can lead reviewers to pay less attention. That creates the possibility that a rare but serious mistake passes through a process in which people have grown accustomed to accepting an agent’s work.
Threat actors may target the agents themselves. The report identifies prompt injection and malicious input manipulation as possible methods for trying to influence an AI system into approving fraudulent activity, disclosing sensitive information or disabling safeguards. Security testing therefore needs to examine model behavior under adversarial inputs, not only whether the system works under normal conditions.
Firms are being urged to build governance into deployment
CertiK recommended that organizations define each agent’s duties, permission boundaries and escalation routes before deployment. The report calls for full audit trails covering significant decisions, regular red-team exercises and a named human owner who is accountable for each system’s performance and failures.
The governance challenge could grow if agents begin directly holding or trading digital assets, running trading strategies or managing company funds. In that scenario, a firm would need records not only of the resulting on-chain transaction but also of the data used by the agent and the decision process that produced it.
CertiK’s report places agentic AI in a practical middle ground: capable of moving investigations and routine controls forward at machine speed, but operating inside explicit limits designed by people. For security and compliance teams, the test will be whether those limits remain effective during the fast-moving incidents that make automation attractive in the first place.
Explore how autonomous agents transform markets and risk control in crypto—read Web3, AI, and Crypto: Breaking the Internet next.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
