AI & Cyber

AI Security Agents for IoT Devices

October 1, 2026·8 min read

The Internet of Things has a patching problem that will never be solved. Cameras, sensors, building controllers, and medical devices ship with firmware that is updated rarely, audited never, and expected to live on the network for a decade or more. We have spent years trying to protect these devices from the outside — segmentation, NAC, anomaly detection at the gateway. The interesting question now is whether we can put a defender inside the device itself: a small AI security agent that watches its own host.

The numbers explain the urgency:

- 81% of security leaders say their organizations experienced an IoT-focused attack in the past year. - Organizations hit by IoT-targeted breaches were significantly more likely to face costs between $5M–$10M than those hit by traditional IT attacks. - 46% of organizations still struggle to gain visibility into their IoT devices, making risk management extremely difficult.

— Palo Alto Networks & Starfleet Research, The 2024 Benchmark Report on IoT Security

Why the perimeter answer is not enough

Traditional IoT security assumes the device is a black box and defends the network around it. That works until it doesn't: a compromised camera that behaves normally at the network layer is invisible to your NDR. Lateral movement between devices on the same VLAN, protocol abuse that looks like legitimate traffic, firmware implants that only activate on a schedule — all of these live below the resolution of perimeter tooling.

An on-device agent changes the vantage point. It can see process behavior, syscall patterns, memory anomalies, and configuration drift that no network sensor will ever observe. The trade-off is that the device is resource-constrained, often running a real-time OS or a stripped Linux with a few hundred megabytes of RAM. Your agent has to be a polite guest.

What an on-device agent actually looks like

In practice, the viable designs are small and boring rather than large and clever. A lightweight eBPF or auditd-based collector for behavioral telemetry. A compact model — think quantized classifiers, not LLMs — that scores behavior locally against a baseline learned during a trusted provisioning window. A signed policy bundle pushed from a central control plane, so detection logic can be updated without a firmware release. And a fail-safe posture: if the agent dies, the device keeps doing its job, and the control plane notices the silence.

The local model matters more than people expect. Sending raw telemetry off-device is often impossible — bandwidth, privacy regulation, and air-gapped deployments all rule it out. Inference has to happen at the edge, with only verdicts and rare escalations travelling upstream.

The attack surface you just created

Here is the part the vendor decks skip: the agent is itself new attack surface. It runs with elevated privileges on a device you already struggle to patch. Its model can be poisoned during the learning window. Its update channel is a remote-code-execution path wearing a trench coat. Its telemetry can be lied to by an attacker who got there first.

Defending the defender means hardware-rooted identity for the agent, signed models and policies, a learning window that is cryptographically bounded to provisioning time, and the humility to assume the agent will sometimes be blind. The agent should be one signal among several — never the sole basis for an automated response that can take a device, or a building, offline.

Where this is going

The near-term wins are unglamorous: detecting cryptominers on cameras, catching configuration drift on industrial controllers, flagging a device that suddenly starts talking to a new peer. The longer-term vision — fleets of agents that coordinate, share indicators, and quarantine themselves — is real but depends on standards for agent identity and attestation that do not exist yet.

My working rule: deploy the agent where the device is high-value and unpatchable, keep the model small and the policy signed, and never let an autonomous defender take an action you would not let a junior analyst take unsupervised. The goal is not a self-defending network. It is a network where the smallest devices finally have a witness.

— A.P.W.

The Dispatch

New essays, straight to your inbox.

Occasional letters on network defense, AI risk, governance, and the life around the work. No spam, unsubscribe any time.