The Problem: Agents Are Getting Access Faster Than Anyone Is Reviewing It
An AI assistant that answers questions is one thing. An AI agent that reads your documents, calls your systems and takes actions with a service account is another. The second kind needs the same discipline you apply to any employee or contractor with system access, and in many organizations it is not getting it yet.
An Okta-sponsored survey of 306 CISOs and cybersecurity executives (six markets, published 31 July 2026) found that 81% worry about "AI agents running with access no one is reviewing". Only 47% said they can identify every agent in their environment, 46% said they can control agent access to corporate resources, and 45% said they can authorize agent permissions. Roughly 20% allow agents to use shared credentials or over-permissioned service accounts, and only 25% use a dedicated access framework for agents.
Grant Thornton's 2026 AI Impact Survey (950 business leaders, February to March 2026) points the same way from the business side: 73% grant agentic AI access to data or processes, yet only 20% have tested their incident response plans. It also found a perception gap inside the C-suite, with 54% of COOs worried about agentic AI compliance risk against 20% of CIOs and CTOs.
Two cautions. Okta sells identity governance and Grant Thornton sells advisory services, so both have an interest in the gaps they describe. And both are self-reported surveys, mostly weighted toward the US. Even so, the pattern is consistent with what independent incident reports show.
The Solution: Treat Every Agent as an Identity With an Owner, a Scope and an Off Switch
OWASP's Q1 2026 GenAI exploit round-up logged 8 major AI-related incidents between January and April 2026. The recurring patterns were "excessive agency" (agents given more permission or autonomy than is safe), prompt injection, supply-chain compromise and identity and privilege abuse. Among the cases it lists: an internal AI agent at Meta gave flawed engineering guidance that an employee followed, which broadened access to sensitive user and company data for two hours, and researchers showed how over-privileged service agents on Google's Vertex AI could abuse default permissions to reach credentials and internal resources. These are reported incidents summarized by a community project, not a complete count, but they show where the failures cluster: permissions, not clever model tricks.
The demand side is moving too. Gartner's May 2026 survey of 1,600 CISOs made "Enabling and Protecting AI" a new top functional priority, and its Q2 2026 emerging-risk survey (316 senior executives and risk managers) lists agentic AI, described as autonomous systems operating beyond organizational oversight, among the AI risks it highlights. The framing matters: the goal is to enable agents safely, not to block them.
The Approach: Five Controls Before an Agent Goes Near Production Data
1. Find every agent. Include agents built by your teams, agents embedded in SaaS products you already license, and agents employees connected themselves. If you cannot list them, you cannot review them.
2. Give each agent its own identity and a named human owner. No shared credentials, no borrowed personal accounts. The owner is accountable for what the agent can reach and do.
3. Apply least privilege to data and actions. Start from the narrowest scope that lets the agent do its job. Separate read access from write access, and treat anything that can send, delete, approve or pay as a higher tier.
4. Require human approval for irreversible actions, and build a kill switch. You should be able to suspend an agent's access quickly, and logs should show what it did and on whose authority.
5. Rehearse the failure. Run a tabletop exercise: an agent has exfiltrated data or taken a wrong action. Who notices, who decides, who is called? With only 20% of surveyed organizations having tested their incident response plans, this is where most of the learning is.
The question to ask about any agent is the same one you would ask about a new contractor: who is it, who vouches for it, what can it reach, and how do we switch it off?
How ANG Associates Can Help
ANG Associates offers an Agent Access Review for organizations that are giving AI agents access to real data and systems. We build the agent inventory with your IT, security and business teams, map each agent's identity, permissions and data reach, and identify where access exceeds need. You receive a prioritized remediation plan, a design for approvals, logging and shut-off, and a facilitated incident tabletop so your response is tested before it is needed.
We work with the identity, security and monitoring tools you already own, and can help you judge where a gap genuinely needs a new tool and where it needs a process or an owner. In regulated Life Sciences environments, we also align agent changes with the change-control and validation practices you already run. ANG is an advisory firm, not a security product vendor, which means our recommendations are not tied to selling you a platform.
This is one of six services in our ANG AI Trust Compass offering.
Sources
- Cybersecurity Insiders, report on the Okta-sponsored CISO survey (306 CISOs and cybersecurity executives, published 31 July 2026; sponsor is an identity-governance vendor)
- Grant Thornton, "2026 AI Impact Survey" (950 business leaders, February to March 2026)
- OWASP GenAI Security Project, exploit round-up report for Q1 2026 (14 April 2026)
- Gartner via Evanta, top 3 CISO priorities in 2026 (1,600 CISOs, May 2026 Leadership Perspective Survey)
- Gartner press release on the Q2 2026 emerging risk survey (316 senior executives and risk managers, 25 August 2026)