← Back to All Articles
AI Governance & Security

AI Agents With Access Nobody Reviews: The CISO's New Blind Spot

A
ANG Associates
Life Sciences & AI Consulting
Sep 2026 7 min read

The Problem: Agents Are Getting Access Faster Than Anyone Is Reviewing It

An AI assistant that answers questions is one thing. An AI agent that reads your documents, calls your systems and takes actions with a service account is another. The second kind needs the same discipline you apply to any employee or contractor with system access, and in many organizations it is not getting it yet.

An Okta-sponsored survey of 306 CISOs and cybersecurity executives (six markets, published 31 July 2026) found that 81% worry about "AI agents running with access no one is reviewing". Only 47% said they can identify every agent in their environment, 46% said they can control agent access to corporate resources, and 45% said they can authorize agent permissions. Roughly 20% allow agents to use shared credentials or over-permissioned service accounts, and only 25% use a dedicated access framework for agents.

Grant Thornton's 2026 AI Impact Survey (950 business leaders, February to March 2026) points the same way from the business side: 73% grant agentic AI access to data or processes, yet only 20% have tested their incident response plans. It also found a perception gap inside the C-suite, with 54% of COOs worried about agentic AI compliance risk against 20% of CIOs and CTOs.

Two cautions. Okta sells identity governance and Grant Thornton sells advisory services, so both have an interest in the gaps they describe. And both are self-reported surveys, mostly weighted toward the US. Even so, the pattern is consistent with what independent incident reports show.

The Solution: Treat Every Agent as an Identity With an Owner, a Scope and an Off Switch

OWASP's Q1 2026 GenAI exploit round-up logged 8 major AI-related incidents between January and April 2026. The recurring patterns were "excessive agency" (agents given more permission or autonomy than is safe), prompt injection, supply-chain compromise and identity and privilege abuse. Among the cases it lists: an internal AI agent at Meta gave flawed engineering guidance that an employee followed, which broadened access to sensitive user and company data for two hours, and researchers showed how over-privileged service agents on Google's Vertex AI could abuse default permissions to reach credentials and internal resources. These are reported incidents summarized by a community project, not a complete count, but they show where the failures cluster: permissions, not clever model tricks.

The demand side is moving too. Gartner's May 2026 survey of 1,600 CISOs made "Enabling and Protecting AI" a new top functional priority, and its Q2 2026 emerging-risk survey (316 senior executives and risk managers) lists agentic AI, described as autonomous systems operating beyond organizational oversight, among the AI risks it highlights. The framing matters: the goal is to enable agents safely, not to block them.

The Approach: Five Controls Before an Agent Goes Near Production Data

1. Find every agent. Include agents built by your teams, agents embedded in SaaS products you already license, and agents employees connected themselves. If you cannot list them, you cannot review them.

2. Give each agent its own identity and a named human owner. No shared credentials, no borrowed personal accounts. The owner is accountable for what the agent can reach and do.

3. Apply least privilege to data and actions. Start from the narrowest scope that lets the agent do its job. Separate read access from write access, and treat anything that can send, delete, approve or pay as a higher tier.

4. Require human approval for irreversible actions, and build a kill switch. You should be able to suspend an agent's access quickly, and logs should show what it did and on whose authority.

5. Rehearse the failure. Run a tabletop exercise: an agent has exfiltrated data or taken a wrong action. Who notices, who decides, who is called? With only 20% of surveyed organizations having tested their incident response plans, this is where most of the learning is.

The question to ask about any agent is the same one you would ask about a new contractor: who is it, who vouches for it, what can it reach, and how do we switch it off?

How ANG Associates Can Help

ANG Associates offers an Agent Access Review for organizations that are giving AI agents access to real data and systems. We build the agent inventory with your IT, security and business teams, map each agent's identity, permissions and data reach, and identify where access exceeds need. You receive a prioritized remediation plan, a design for approvals, logging and shut-off, and a facilitated incident tabletop so your response is tested before it is needed.

We work with the identity, security and monitoring tools you already own, and can help you judge where a gap genuinely needs a new tool and where it needs a process or an owner. In regulated Life Sciences environments, we also align agent changes with the change-control and validation practices you already run. ANG is an advisory firm, not a security product vendor, which means our recommendations are not tied to selling you a platform.

This is one of six services in our ANG AI Trust Compass offering.

Sources

Agentic AICISOAccess ControlAI SecurityIncident Response

Interested in this topic?

Let's discuss how we can apply these approaches to your organization.

Contact Us