On October 5, CertiK, the world’s largest Web3 security company, released its Intel3D report (The Rise of AI Employees: How Agentic AI Is Reshaping Cybersecurity, Anti-Money Laundering, and Compliance). The report notes that AI is shifting from an assistive tool that helps analysts identify issues to a member of the workforce capable of carrying out investigations, making judgments, and taking action within defined permissions. This shift is reshaping security and compliance processes in traditional finance and Web3, while also raising new

requirements.

From Supporting Analysis to Autonomous Execution

The report says this shift is being driven by the combined pressures of increasingly fast attacks and money laundering, a shortage of skilled professionals, and growing regulatory requirements. In digital assets, an attack can be completed in a single transaction, and stolen funds can move through multiple addresses and cross-chain bridges in a short time. Meanwhile, security and compliance teams face a growing volume of alerts and transactions, making it difficult to meet real-time monitoring and investigation needs simply by increasing headcount.

Unlike traditional AI tools that can only flag anomalies or generate text, agentic AI can reason through multiple steps, call external tools, combine evidence from different sources, and decide what to do next based on the results. For example, after detecting an unusual login, a system can investigate by combining device information, historical login locations, and threat intelligence; take action within its defined permissions; and leave a record for human review.

Security auditing and anti-money laundering investigations are being redefined

This trend is already evident in traditional security and anti-money laundering work. CertiK explains that agentic systems can correlate logs across different systems, perform initial triage of alerts, and route events requiring attention to human staff. In anti-money laundering investigations, AI can compile transaction histories, customer information, and entity relationships to produce risk explanations and draft suspicious activity reports. Compliance staff are increasingly focused on reviewing evidence, handling complex cases, and deciding whether to submit reports.

In Web3, smart contract auditing and on-chain fund tracing are among the applications highlighted in the report. AI-assisted audit agents can map cross-contract calls and analyze state changes to help identify issues such as misconfigured access controls and unsafe upgrade designs. Drawing on CertiK’s security practices, the report notes that senior auditors are allocating their time differently: verifying AI findings, investigating complex attack paths, and assessing the coverage and blind spots of AI tools are becoming more important. Engineers remain responsible for the final judgment.

Cross-chain fund flows are also changing investigative methods. Citing its earlier research, the report says that in the month following the Bybit hack, 86.29% of the stolen ETH was converted to Bitcoin, involving channels such as mixing services, cross-chain bridges, and over-the-counter trading. Tracing these paths requires investigative tools to continually connect leads across multiple chains. In this context, agentic AI can follow an investigation as funds move, rather than merely reconstructing transaction paths after the fact.

As AI enters compliance workflows, its own actions must also be audited

Compliance work is increasingly extending to pre-transaction and day-to-day operations: AI agents can assess counterparty addresses and transaction risks before settlement, continuously compare system configurations against control requirements, and help prepare regulatory reports. This gives compliance teams the opportunity to identify risks earlier and reduce the time between an anomaly occurring and human intervention.

As agents begin to hold and trade digital assets directly, execute trading strategies, or manage organizational funds, overseeing AI itself is becoming a new compliance challenge. Businesses need to audit its on-chain behavior and retain records of the data it uses, the basis for its decisions, and the actions it takes for subsequent review and forensic investigation. The report stresses that using AI to perform compliance work and determining whether AI itself is compliant are two different tasks; the deploying organization remains responsible for the agent’s actions.

Autonomous execution introduces new risks of misjudgment and attack

Autonomous capabilities can also magnify the impact of errors. CertiK cautions in the report that models may misclassify a real intrusion as harmless, generate an incorrect flow of funds, or make unreliable security assessments of smart contracts. The more consistently a system performs on routine tasks, the more likely human reviewers are to relax their scrutiny—making rare but consequential errors easier to miss.

Attackers can also use AI to accelerate vulnerability hunting, social engineering attacks, and reconnaissance. Security and compliance agents with access to sensitive data and the ability to call tools may themselves become targets. Prompt injection or input manipulation could trick an agent into approving a fraudulent transaction or disabling effective controls. Assessing AI security therefore also requires testing how it responds to malicious inputs.

Boundaries of authority and accountability mechanisms must be established in tandem

To address these risks, CertiK recommends that businesses define agents’ roles, permissions, and escalation paths from the outset of deployment, specifying which actions they can take autonomously and which require human approval; maintain complete audit records for significant decisions; and conduct regular red-team testing. Each agent should also have a clearly designated human owner who is accountable for its performance and mistakes. The scope of work assigned to AI can expand, but the deploying organization and relevant personnel remain accountable for the outcomes.

Agentic AI is putting pressure on businesses to advance adoption and governance in tandem. Teams without the relevant capabilities may fall behind in processing speed, cost, and coverage; businesses that deploy autonomous systems without appropriate oversight mechanisms may introduce new operational and compliance risks. As AI takes on more critical tasks, businesses need to adjust how work is divided, define the boundaries of authority, and put oversight and accountability in place. The rise of “AI employees” is changing how security and compliance work is organized, and whether businesses can continue to benefit will depend on their ability to keep governance apace with AI’s execution capabilities.

Report link: https://www.certik.com/certik-report/intel3d/certik-intel3d-the-rise-of-the-ai-security-workforce-how-agentic-ai-is-redefining-cybersecurity-aml-and-compliance