AI usage has grown exponentially over the past few years, moving beyond basic chatbots and assistants to become an integral, often autonomous, part of core business workflows. Organisations are finding real value in agentic AI systems that can handle complex tasks and support decision making with minimal human input, and the productivity case is compelling.
Whilst these benefits are significant, the real concern is how much decision-making authority organisations are handing to systems with little to no human involvement. This level of autonomy raises fundamental security questions: how much access is too much access? And when does security risk outweigh productivity gain?
These questions have already been explored, and recommendations defined, by the National Cyber Security Centre (NCSC) recently. New guidance, released in early 2026, encourages organisations adopting agentic AI to create more effective policies and principles such as least-privilege access, time-limited credentials, clear ownership and meaningful human oversight. In June 2026, the Five Eyes cyber agencies released a statement echoing these sentiments. The statement urges organisations to “review and strengthen identity and access controls.”
In practice, neither is straightforward. Many systems now have access to applications, company data and business systems to carry out tasks for employees, but at what cost? In improving productivity for employees, organisations are also, willingly or unwillingly, introducing a whole new set of security risks. What’s clear is that agents, or Non-Human Identities (NHIs) must have security controls like any human user.
Agentic AI Is Expanding the Attack Surface
Unlike a traditional Large Language Model (LLM) where users ask questions and receive answers, agentic AI is designed to take autonomous action. AI agents are often introduced to reduce the need for time-consuming menial jobs and admin tasks, like scheduling meetings, taking notes, generating reports and updating records.
Granting an AI agent permission creates a pathway into an organisation’s systems. This is especially concerning with third-party agents, as a breach of a supplier may provide unfettered access to an organisation’s entire ecosystem if access controls are not properly scoped. If access controls are too broad, the data exposure can be significant. If an AI agent can access more than it needs to complete a specific task it is no longer merely a productivity tool. It becomes an unmanaged attack surface.
Boards want AI deployed yesterday while security teams want it deployed correctly. That tension is where most of the risk lives. Discussions around AI have mostly centered on what the technology can do, but there should be more focus on how it is being monitored and secured when connected to business-critical systems. The more urgent question is whether security teams are even in the conversation when these decisions get made.
Keeper Security’s 2026 research found that 40% of UK organisations already identify AI-related NHI management as a major security gap, and 52% reported that AI-driven attacks have increased security pressure on their organisation over the past 12 months. The gap between adoption and governance is exactly what attackers are counting on.
Least Privilege Is Not Optional When the Agent Has Admin Rights
The principle of least privilege is not new. What is new is how badly it gets overlooked when the “user” in question is an AI agent rather than a human user. Enforcing this through Privileged Access Management (PAM) has long been a cybersecurity best practice, but it becomes even more critical when organisations are deploying autonomous systems.
An AI agent given a task to analyse customer feedback does not need access to financial records, nor should a workflow automation tool automatically receive administrative permissions. With greater access comes greater risk.
Organisations should view AI security through the lens of identity management. Every AI agent needs only the access its task requires, time-limited credentials and a complete audit trail. This is PAM, just applied to a new class of identity.
The Increased Challenge of NHIs
For many organisations, managing human users is an already difficult task. Adding machine identities into the mix makes it even harder. NHIs include service accounts, APIs, automation tools and, increasingly, AI agents. Unlike employees, these identities do not complete security awareness training or raise concerns when something looks suspicious. Yet they often have access to sensitive systems and data. As agentic AI becomes standard in daily operations, the number of NHIs to manage will grow, and many organisations have no clear picture of how many they already have.
Organisations should know who owns the identities and what permissions they have. Without that oversight, AI adoption creates the same problem as any unmanaged identity sprawl: new systems and credentials accumulate faster than anyone is tracking them. Ultimately, organisations remain responsible for any AI system that operates autonomously on their behalf.
Governance Cannot Be an Afterthought
Many businesses are under pressure to move quickly with AI adoption. The risk is that security controls are addressed later, once gaps have already been exploited. Good security is always proactive, as opposed to reactive. Too much permission could continue to create opportunities for privilege increases and lateral movement. These risks do not disappear because the identity using the access is a machine rather than a person. If anything, agentic AI tends to expose weaknesses that were already there..
The difference is scale. AI systems can operate faster, interact with more systems and perform more actions than a typical user. That means poor security decisions can have a much larger impact. For organisations deploying agentic AI, the priority is building security and governance in from the start, with access management at the core. Organisations should start small and apply existing governance from the outset. That means defining ownership, monitoring activity, reviewing permissions regularly and maintaining audit trails. It also means planning for failure, including the mistakes AI systems will inevitably make, and closing the weaknesses cybercriminals will move to exploit.
Building Secure AI From the Start
The NCSC’s guidance, as well as the guidance from its international Five Eyes allies, is a reminder that the future of AI security is not just about protecting models but also the permissions and credentials that allow AI systems to operate. It is about prioritising security alongside productivity as a single objective.
Security teams are already managing more with less. Adding AI governance to that list without additional resource, tooling or mandate is a recipe for the same sprawl that has made identity management so difficult in the first place. The answer is not to slow AI adoption. It is to build governance in from day one, before the permissions stack up and before the first incident makes the case for you. The agents are already running. The question is whether anyone is watching.

