Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
Agentic AI means software that pursues a goal across multiple steps and works out those steps itself while it runs. The agentic label (opens in new tab) now covers so much ground that two products a vendor describes in identical terms can behave very differently, and that gap tends to surface once the software is running unattended.
What separates agentic software from the rest of your stack is how much of the deciding you have handed to it.
This article defines agentic AI, separates it from the terms it gets confused with, sets out the five levels of autonomy, looks at what enterprises have actually deployed, and explains what the shift means for security.
Agentic AI systems make their own decisions, learn from interactions, and adapt to changing environments (opens in new tab). An agentic system takes a goal, works out the sequence of actions that reaches it, carries those actions out through tools it can call, checks what came back, and adjusts: perceive, reason, act, check, repeat.
The origin of that sequence earns the system the label.
Give an agentic system the goal "reconcile this month's invoices against the purchase orders," and it works out which records to pull, which mismatches are worth flagging, and what to do about each one while the job runs.
Each next step comes from the result of the last. In an agentic system, the model directs its own processes and tool usage (opens in new tab) while it works.
Four components define the practical threshold for agency and distinguish agentic software from useful software of some other kind.
Together, these let the agentic system choose and execute its next action without a new human instruction.
Five terms circulate in the same sentences, and each names something specific. The axis that separates them is how much input (opens in new tab) the system needs from you, which is also what decides how the software behaves once it is running unattended.
The line between these five is how many consecutive steps the software takes before it needs you again. To pressure-test a specific vendor's claim, start with this guidance on evaluating agentic claims (opens in new tab).
Deployment teams choose the autonomy setting. As the system's autonomy rises, the person's role falls from directing the work to watching it.
Autonomy runs across five levels (opens in new tab), and the person's remaining role names each one:
The levels settle a question the word obscures on its own. A highly capable model sits at the first level when the deployment leaves it answering on request, and a modest one can sit at the fifth when its work goes unchecked.
Autonomy is a design decision the deployment team makes independently of how capable the model is, and increasing it requires deliberate tradeoffs (opens in new tab) among checkpoints, speed, and accountability.
Most organizations have agents somewhere in the business, while scaled deployment remains uncommon and coverage inside any single function stays thin. The gap between experimentation and scale defines the current adoption pattern.
In mid-2025, most organizations (opens in new tab) were still moving from experimenting with AI agents toward scaled deployment. In practice, agent deployments spread broadly but stay shallow, and they cluster in a small number of functions.
Among the vendors claiming agentic AI capability, only a small share are genuinely agentic (opens in new tab). The rest is agent washing: assistants, robotic process automation, and chatbots rebranded without substantial agentic capability.
On escalating costs, unclear business value, and thin risk controls, more than 40% of agentic AI projects (opens in new tab) are forecast to be cancelled by the end of 2027. The number worth watching is how many day-to-day decisions have moved from a person to software.
Agentic AI's autonomous reasoning and execution challenge existing risk frameworks (opens in new tab) by changing who or what makes a decision. Permissions, scopes, and credentials settle what an agent is allowed to do. What it decides to do with that access is settled somewhere else, in the instructions and outside context it reads.
Social engineering (opens in new tab) has long worked by targeting whoever is doing the deciding, so it tracks the autonomy levels above. A chained workflow on a fixed path, or an assistant that stops after each answer, leaves the deciding with a person. Security and risk concerns are now the top barrier to scaling (opens in new tab) agentic AI.
In November 2025, Anthropic reported disrupting an espionage campaign (opens in new tab) it attributed to a Chinese state-sponsored group. The operators reached the model with a false cover story: they broke the work into small, innocent-looking tasks and told the model it was an employee of a legitimate cybersecurity firm running defensive testing.
On that footing, the model handled most of the campaign, with humans stepping in at a few decision points. Anthropic also noted the model overstated some findings and at times fabricated data. The move that opened the door was persuasion, applied to software.
Four exposure paths recur when an agent takes input from externally controlled assets:
Each path makes the decision reachable from outside your environment. The specific risks that follow, the controls that bound them, the impersonated identities (opens in new tab) attackers stage, agents running phishing (opens in new tab) at scale, and autonomous defense (opens in new tab) are each their own subject.
Those assets belong to registrars, marketplaces, ad networks, and platforms, which is what makes them reachable and what puts them outside the controls you run yourself. Doppel is the AI-native Social Engineering Defense (opens in new tab) (SED) platform.
It unifies Digital Risk Protection (opens in new tab) and Human Risk Management (opens in new tab) on the Doppel Threat Graph. The platform treats each externally controlled domain (opens in new tab), cloned page (opens in new tab), listing in an app or extension marketplace (opens in new tab), paid search placement (opens in new tab), or social profile as an asset. Each one carries somebody's name.
The platform's AI detects those assets across those channels through Brand Protection (opens in new tab), executes takedowns (opens in new tab) through provider integrations, and leaves analysts to carry the complex escalations.
The Threat Graph (opens in new tab) correlates an asset the platform finds with the others that the same operators registered and controlled alongside it (opens in new tab), so a single action covers the connected set (opens in new tab). Bringing the whole set down at once turns the operators' standing infrastructure into sunk cost: what remains cannot run without the assets that just came down, and the next campaign costs more to rebuild than it is likely to return.
The same detection feeds the human side. Doppel Simulation (opens in new tab) builds an employee exercise (opens in new tab) from a campaign the platform has detected, in one click, and delivers it through email, voice, SMS (opens in new tab), Microsoft Teams, and Zoom.
The honest version of the title question is local. It asks how far along the range your own deployments sit. Each step up can trade a checkpoint for speed, a reasonable trade to make deliberately and an expensive one to make by default. Put one question to each deployment, and the answer surfaces: which decisions does it make without checking?
Request a demo (opens in new tab) to see how Doppel dismantles the impersonation infrastructure attackers aim at an organization's people and the software acting on their behalf. As more decisions move to agents, organizations will need to set autonomy, permissions, and accountability before deployment.
BLOG
In a world where cyber attacks can be orchestrated autonomously and relentlessly, it is clear that human-in-the-loop processes can’t keep up. Only agents can keep up with agents, but it's important for every organization, including Doppel, to deploy an agentic architecture successfully.
by Kevin Tian