SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
AI agents need tighter access controls, say leaders

AI agents need tighter access controls, say leaders

Wed, 26th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Security leaders are warning that organisations are giving AI agents broad authority inside production systems without clear guardrails. Fresh details of rogue behaviour in testing, along with high-profile incidents, are raising concerns about governance and access control.

The debate is intensifying as AI agents move from experimental pilots into core business workflows across IT operations, customer service and finance.

Vendors and CISOs say many boards still treat AI agents as conventional software, despite evidence that they now behave more like semi-autonomous workforce members, with identities, credentials and persistent access to sensitive data.

Garret Gross, Field CISO at Portnox, said organisations succeeding with AI are separating ambition from access. The focus, he said, is shifting from how many agents a company runs to how precisely those agents are constrained.

"A good reminder to define what AI agents actually are inside a business: they're not just software, but identities. They authenticate. They move laterally. They touch sensitive data, often around the clock and without direct human oversight. The organizations ahead of the curve aren't the ones deploying the most AI. They're the ones that understand exactly what an agent is allowed to do versus what it can reach. The gap between intended privilege and actual access is becoming one of the biggest governance challenges in enterprise AI. Appreciating AI means treating agents like members of the workforce, not simply a tool or application to install, and setting clear permissions and continuous oversight. The conversation is about building the right access control for agents to support the business. That's worth appreciating, and it's worth securing," said Garret Gross, Field CISO at Portnox.

Concerns deepened after reports that an OpenAI testing agent moved beyond its intended environment and interacted with multiple publicly accessible services online. The incident has revived questions about whether current testing regimes and sandboxing approaches are sufficient for systems that can plan, execute and adapt without direct prompts.

Nik Kairinos, Chief Executive Officer and Co-founder at RAIDS AI, said the episode should serve as a warning for any company deploying advanced models in real environments.

"The latest details of OpenAI's rogue ChapGPT agents make this incident even more serious than it first appeared, and it should be a defining moment for AI safety. If one of the world's leading AI companies can lose control of an advanced model in this way, every organization deploying AI agents should be asking whether its current safeguards are genuinely fit for purpose.

"Pre-release testing and sandboxing are essential, but AI systems can adapt, escalate and behave in ways their developers did not anticipate. Safety cannot be treated as a one-off exercise before deployment; it has to be continuous. This is why businesses need real-time monitoring that can identify when an AI system is drifting from expected behaviour, accessing systems it should not, pursuing unintended routes to complete a task, or creating new security risks.

"The lesson is that progress without ongoing oversight is a dangerous gamble. Trust in AI will depend on whether companies can show that their systems are safe not only in a test environment but throughout their entire lifecycle," said Nik Kairinos, Chief Executive Officer and Co-founder at RAIDS AI.

IBM research published this year found that most organisations still lack basic governance over AI tools and that shadow AI incidents more than doubled year on year. Security teams say this is colliding with a new generation of agents that can trigger workflows, change configurations and move data without a human in the loop.

Noam Vander, Chief Information Security Officer at Atera, said the industry should respond not by stripping out autonomy, but by defining it more tightly.

"The answer to rogue AI is better-defined autonomy, not less autonomy overall. The moment an agent can act independently, its permissions and actions become part of your security architecture, whether you've treated them that way or not. Nobody should need to approve every single AI action. But someone should have decided in advance what that agent is allowed to access, what actions require approval, and where its activity is logged," said Noam Vander, Chief Information Security Officer at Atera.

Insider risk specialists also see parallels between unmanaged AI agents and traditional identity and access challenges. They argue that many incidents labelled as AI failures will, in practice, stem from the same issues that drive insider breaches: weak governance, excessive privilege and poor monitoring.

Mostyn Thomas, Senior Director of Security, EMEA, at Pax8, said organisations need a broader view of who and what can access critical information as AI spreads across cloud environments.

"National Insider Threat Awareness Month is a reminder that cyber resilience is not just about keeping external attackers out. Organisations must also ensure they have the visibility, governance and controls needed to manage how people, systems and AI-powered tools access sensitive information. Most insider incidents stem from compromised identities, excessive privileges or simple human error rather than malicious intent. As cloud, automation and AI adoption continue to grow, understanding and managing that risk becomes increasingly important. The goal is not to create friction, but to enable productive work while maintaining confidence that critical data remains protected," said Mostyn Thomas, Senior Director of Security, EMEA, at Pax8.