Companies are moving quickly on autonomous software agents. Gartner says task-specific agents will show up in 40% of enterprise applications, up from about 5% just a year ago.
For a business, the bigger question is how those agents connect to the rest of the stack. When you tie autonomous software agents directly into legacy systems through databases, application programming interfaces (APIs), and automated workflows, they can slip past the approvals, visibility, and security controls your teams already rely on.
That’s why a lot of security teams now lean toward a user interface (UI)-first, “emulated human” approach. In that setup, agents sign in with standard credentials, work through the same interface employees use, and follow the usual workflows.
The upside is straightforward. Autonomous software agents stay inside your existing permissions, validation checks, approval chains, and audit trails. You don’t have to expose raw back-end data, add new integration points, or spend time rebuilding years of business logic and security rules in older, business-critical systems.
Finance is a simple example. An enterprise resource planning (ERP) agent could change a vendor’s bank details and release a payment without ever passing through the normal approval process.
And when an enterprise resource planning (ERP) agent acts outside that normal approval path, the record of who approved what, when, and why can get patchy fast. If you’re rolling out agents in legacy environments, a UI-first approach deserves a close look. 47% of organizations say they’ve already had an agent-related security incident. Meanwhile, 43% report that more than half their employees use these tools, and another 43% say they’re working across four or more platforms.