Rise of AI Agents Creates New Security and Access-Governance Challenges
As generative artificial intelligence and AI agents rapidly gain adoption, many companies are integrating them into internal workflows to boost efficiency. These automated tools need access to sensitive data, making machine identities and access controls a key focus of next-generation cybersecurity. Without proper governance, AI agents could become a weak point in corporate defenses, which is why the technology and cybersecurity sectors are paying close attention to the issue.
Palo Alto Networks said on July 16, 2026, that companies face mounting cybersecurity challenges from AI agents. It recommended that businesses first establish 100% visibility into their internal AI tools, then use automated platforms for governance and audits to guard against a single data breach that could cause more than $4 million in financial losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventExperts Urge Employee-Level Access Controls for AI Agents
Companies are rapidly adopting AI agents that can do more than generate answers: they can invoke tools, execute workflows and retrieve sensitive corporate data with limited human intervention. Security experts say that autonomy makes agents closer to digital workers than conventional software. Treating them as ordinary applications could widen the impact of data leaks, unauthorized transactions and compliance failures, particularly when an agent can combine access across multiple systems.
The latest report recommends onboarding each AI agent like a new employee, granting only the data access and operational privileges required for its assigned role. Companies should impose granular controls on tools and information, monitor activity and preserve a complete audit trail for investigations and regulatory reviews. The report did not identify a specific institution, financial exposure or implementation date, but said least-privilege access and recurring permission reviews should be established before agents are deployed at scale.
AI Agents Pose New Identity-Governance Challenge as Experts Urge Tighter Controls
Companies are rapidly deploying AI agents for account management, data queries and automated tasks, turning them into a new form of “digital identity” with access to corporate systems. Identity-governance provider SailPoint warned that many companies do not even know who is authorized to log in through third-party accounts. Without clear boundaries on AI behavior, sensitive data and core systems face still greater exposure.
SailPoint recently advised companies to break large AI workflows into multiple smaller agents, grant each only the minimum permissions needed for its task, and restrict the data and systems it can access. These measures would reduce the risk of AI agents exceeding their authority when acting autonomously. The report did not disclose the survey date, the number of companies interviewed or any losses, but underscored that auditing third-party accounts and AI permissions has become a governance priority.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →