Goran Listicevic, APAC Executive Vice President and Managing Director at Cloudflare, speaks during a media education session at the Westin Josun Seoul Parnas in Gangnam-gu, Seoul, on the 25th./Courtesy of Lee Ho-joon

"Traffic generated by artificial intelligence (AI) agents increased by more than 1,700% from a year earlier. About 60% of all traffic on the network is coming from AI agents. While building the foundation for an agentic internet, we also need to apply AI security at the pace of innovation."

Goran Risticsevich, Cloudflare's executive vice president and managing director for Asia-Pacific (APAC), stated accordingly at a media education session on the 25th at the Westin Seoul Parnas in Gangnam District, Seoul. As the use of AI agents rapidly increases, the network infrastructure and security systems to support them must be established simultaneously.

Risticsevich said, "The internet was originally built for people, but now traffic is being generated by AI agents that move at machine speed," and added, "While a person might look at four or five websites to research or plan a trip, an AI agent can connect simultaneously to thousands of websites and servers to perform the same task."

As AI agents access multiple services and systems on behalf of people at the same time, the targets that corporations must manage are also increasing. Developers and employees want to quickly leverage AI models and services, while corporations must understand which AI is accessing which data and systems and prevent leaks of sensitive information or unnecessary access.

A representative case is "shadow AI." This is when employees use AI services for work that corporations have not approved, and in such cases, sensitive in-house information can be sent to external AI models. On top of this, with the rapid spread of the model context protocol (MCP), which connects AI applications with external tools and internal systems, "shadow MCP," which uses MCPs not approved by corporations, is also emerging as a new security challenge.

Annika Garbers, Head of GTM for Cloudflare One, speaks during a media education session at the Westin Josun Seoul Parnas in Gangnam-gu, Seoul, on the 25th./Courtesy of Lee Ho-joon

Cloudflare said corporations should first identify which AI tools are being used internally and then control data and network access. If prompts sent to AI models contain sensitive information, they should be blocked in advance, and a "zero trust" policy should be applied to MCP server access so that users can access only the necessary applications based on their identity and permissions.

With AI being used for cyberattacks, there was also an explanation that existing security response methods need to change. Cloudflare participated in the security consortium "Project Glasswing," conducted with Anthropic, obtaining early access to the AI model Mythos to conduct tests by the internal security team. The company said the results showed that AI's ability to chain multiple vulnerabilities has become more sophisticated, and the speed at which it discovers new vulnerabilities is also increasing.

Anika Gabers Gabers, head of Cloudflare One GTM, said, "There are limits to responding by applying patches one by one every time a security vulnerability is found," and added, "We need to strengthen the foundation of the security framework and apply zero-trust principles."

The importance of a security framework prepared for quantum computers was also emphasized. Gabers explained that the industry expects the so-called "Q Day," when quantum computers capable of breaking existing cryptography emerge, to come around 2030. Cloudflare currently supports Quantum-resistant Encryption (PQC) and plans to fully support quantum-resistant authentication by 2028.

※ This article has been translated by AI. Share your feedback here.