CertiK’s ‘AI Security Workforce’ Report: Agentic AI Set To Reshape Cybersecurity, AML And Compliance
In Brief
CertiK’s new report finds agentic AI is reshaping crypto cybersecurity, AML and compliance by automating security, monitoring and regulatory tasks.

CertiK says agentic AI is moving cybersecurity, anti-money laundering (AML) and compliance toward increasingly autonomous operations, as human professionals shift from performing routine investigative tasks to supervising AI-driven systems. The blockchain security firm outlined the trend in its new report, “The Rise of the AI Security Workforce: How Agentic AI Is Redefining Cybersecurity, AML & Compliance,” which examines how autonomous AI systems are changing security and compliance functions across Web2 and Web3.
According to CertiK, agentic AI differs from conventional AI tools by being capable of handling multi-step processes, retrieving and synthesizing information, interacting with external systems and taking actions with limited or no human intervention. In cybersecurity, for example, an agent can investigate an anomalous login, correlate device and threat-intelligence data, determine that an account poses a risk and execute a suspension while maintaining a record of its actions.
The report identifies the growing speed of cyberattacks and money laundering, persistent shortages of cybersecurity and financial-crime professionals, and expanding regulatory requirements as key drivers of adoption. CertiK notes that AML penalties exceeded $900 million in the first half of 2025, increasing pressure on organizations to scale compliance operations without relying solely on additional personnel.
In traditional Web2 security, agentic systems can autonomously triage alerts, assess vulnerabilities, monitor identity and access behavior and continuously check systems against cybersecurity controls. In AML, they can re-evaluate transaction alerts, conduct customer due diligence, build relationship graphs and prepare suspicious activity reports for human review. Compliance teams can also deploy AI agents to monitor regulatory changes, identify affected internal policies and perform continuous audits rather than relying on periodic reviews.
Web3 Applications Raise Both Capabilities and Risks
CertiK identifies Web3 as an area where agentic AI can have a particularly significant impact because blockchain transactions are irreversible and security responses often need to occur within minutes or even seconds. AI systems can assist with smart-contract auditing, detect exploit patterns in real time and, in advanced deployments, trigger protective measures such as contract pauses or circuit breakers. They can also reconstruct complex attack paths after an exploit and generate technical post-mortems.
The report also highlights autonomous on-chain AML capabilities, including real-time fund tracing, dynamic address clustering and cross-chain analysis. Compliance systems are increasingly moving toward pre-settlement Know-Your-Address and Know-Your-Transaction risk scoring, allowing potential exposure to illicit activity to be identified before transactions are completed.
At the same time, CertiK warns that greater autonomy introduces new risks. AI agents can produce incorrect assessments, attackers can exploit or manipulate agentic systems, and questions around liability remain unresolved when autonomous actions cause harm. The report recommends defined authority limits, comprehensive audit trails, regular adversarial testing and a named human owner responsible for each AI agent.
CertiK ultimately argues that organizations should treat agentic AI as a workforce role rather than simply another software tool. As AI systems take on more operational responsibilities, overseeing their behavior and preserving evidence of their decisions is itself emerging as a distinct compliance function.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



