Why AI agents need a new approach to privileged acces

Why AI agents need a new approach to privileged acces

As AI agents gain greater autonomy and access to critical enterprise systems, organisations must rethink how they govern the identities, permissions and actions of these increasingly powerful technologies. Mazhar Hamayun, Evangelist and Regional Security Architect, Check Point Software Technologies, tells us why AI agents should be treated as a new class of privileged non-human identity and how a ‘Least Agency’ approach can help organisations control their autonomy without slowing AI adoption.

AI agents are moving into the enterprise much faster than most security programmes were designed to handle.

They are no longer just answering questions or generating content. Agents can read email, access SaaS applications, query databases, invoke APIs, use MCP tools, modify records and execute business workflows. In other words, AI is moving from generating answers to taking actions.

For CISOs and C-level leaders, that changes the security conversation.

The question isn’t simply whether an organisation is using AI safely. A more important question is:

Can we confidently identify, govern, monitor and control every AI agent before it becomes our next privileged insider?

Why call an AI agent a potential ‘privileged insider’?

Think about what makes a privileged human identity risky.

It has access to important systems, sensitive information and business processes. That’s why we put controls around administrators, privileged accounts and service identities.

Now consider an AI agent connected to Microsoft 365, Salesforce, ServiceNow, a cloud environment and internal databases.

That agent may be able to read information, make decisions, call tools and change systems—potentially in seconds and without someone approving every individual action.

The agent doesn’t need malicious intent to become dangerous.

Too much access plus too much autonomy plus too little oversight can create insider-like risk.

Aren’t IAM and least privilege enough to control AI agents?

They are essential, but they aren’t enough on their own.

Traditional identity and access management (IAM) answers an important question:

What is this identity allowed to access?

Agentic AI forces us to ask another:

Should this agent be allowed to perform this particular action, in this context, right now?

This is the difference between access control and action—or outcome—control.

Who should be accountable for an AI agent?

A human.

Every production agent should have a clearly identified owner. For higher-risk agents, I’d argue for both a business owner and technical owner.

The business owner answers: Why does this agent exist and what authority should it have?

The technical owner answers: How is it configured, connected, authenticated, monitored and secured?

Agents can execute tasks autonomously. Accountability cannot be autonomous.

An agent without an identifiable owner should eventually be treated much like an orphaned privileged account.

What’s the bigger takeaway on AI agents for C-level leadership?

Agentic AI shouldn’t be viewed only as another application-security problem.

We’re creating a new class of non-human identities with decision-making authority.

For decades, cybersecurity has operated on the principle of least privilege: give an identity only the access necessary to perform its job.

Agentic AI may require us to go one step further—to what I would call Least Agency: Give an AI agent only the autonomy necessary to accomplish its authorised business purpose—and no more.

Some actions can be allowed. Some should require additional context or human approval. And some actions may simply be prohibited.

That’s how we get the benefits of autonomous AI without handing over unlimited authority.

The goal isn’t to slow AI adoption. It’s to make sure security evolves at the same speed

Browse our latest issue

Intelligent CISO

View Magazine Archive