01

Access without governance creates risk

Agentic AI can retrieve sensitive data, call APIs, execute workflows and change business systems. That capability creates value, but it also creates a new attack surface when permissions and behaviour are not controlled.

  • Excessive identity permissions.
  • Prompt injection through untrusted content.
  • Malicious tools and MCP servers.
  • Sensitive-data exposure.
  • Autonomous actions with a large blast radius.
  • Limited visibility into agent activity.

02

The minimum control baseline

  • Give the agent a dedicated identity.
  • Apply least-privilege and read-only access by default.
  • Restrict the agent to approved tools and explicit allowlists.
  • Require human approval for high-impact actions.
  • Log every material action, decision and failure.
  • Continuously monitor and score risk.
  • Provide immediate revocation and containment paths.

03

Ask the operational question

The important question is no longer whether an organisation uses AI. It is whether leaders know what each agent can access, which actions it can perform and how those actions are governed.

Ownership should be explicit across identity, security, data, technology and the business process the agent serves.

04

Match autonomy with accountability

Agentic AI can transform organisations, but autonomy must be matched with identity security, observability and governance. A secure deployment makes the agent useful without allowing convenience to become uncontrolled authority.

References

Primary sources