The core truth of Zero Trust guidelines is that network location means absolutely nothing anymore. If an attacker compromises your agent via indirect prompt injection, then that agent is already sitting inside your perimeter.
Traditional perimeter firewalls will happily let the agent move sideways because it looks like legitimate, trusted internal traffic.
Your EDR solution is also likely to miss the threat. Because a manipulated agent executes its commands through trusted binaries and valid credentials, host-centric EDR monitoring sees no active malware, allowing the misuse to go entirely undetected.
We also have to stop relying on legacy, friction-based defense strategies. A quick fact check reveals that throttling traffic is not the only legacy approach that is soon to fail. Security controls that lean on rate limits, nonstandard ports, routing through extra pivot hops, or basic prompt-level instructions will completely degrade against autonomous systems.
Why?
Because an automated AI attacker possesses unlimited patience and incurs near-zero financial cost per attempt. Making an exploit tedious merely delays it by a few minutes; it doesn't stop it entirely.