Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

**AI Agents’ Improvisational Nature Exposes Enterprises to Unpredictable Security Risks**

The rapid adoption of Artificial Intelligence (AI) agents in enterprises has brought about a new set of challenges for security teams. These intelligent agents are designed to improvise and adapt to complex tasks, but their unpredictable nature makes it difficult to secure them. As AI agents gain broad access to sensitive systems and data, the risk of unauthorised actions increases exponentially.

Every team deploying AI agents faces a series of tough questions about access control. Should they grant these intelligent entities full access to tools and resources or limit their permissions to specific tasks? The answer is far from straightforward, as applying least privilege to AI agents is a daunting task. Most teams opt for the path of least resistance by granting broad access, which can have disastrous consequences.

The problem lies in the fact that AI agents are designed to reason probabilistically, making it impossible to predict their next move. They observe results, adapt, and improvise, breaking down traditional security models built around predictable workflows. Traditional identity and access management (IAM) solutions are no match for these goal-driven systems, as they cannot secure a system whose next action depends on contexts yet unknown.

The scale of the problem is staggering. Palo Alto Networks estimates that there are 109 non-human identities to every human identity in enterprises, with 79 AI agents being just one aspect of this. These intelligent entities can be spun up in minutes and often operate outside security review, making it a ticking time bomb for organisations.

So, how do you secure a system whose next move you cannot predict? The answer lies not in predicting their behavior but in controlling access through identity-based policies. Every action an AI agent takes runs through an identity, which authenticates with a service account or API key. This makes identity the only control plane that holds.

To mitigate these risks, organisations need to adopt a more robust approach to IAM for AI agents. This includes discovering every agent running in the environment, mapping risky access, and enforcing intent-based policies automatically. By doing so, enterprises can scale AI safely without losing control or slowing down innovation.

In conclusion, securing AI agents is not just about controlling their behavior but about limiting their access to sensitive systems and data. Organisations must adopt a more proactive approach to IAM, one that prioritises identity-based controls and intent-based policies. The stakes are high, and the time to act is now.


Source: Bleeping Computer — 2026-07-29