AI agents are rapidly becoming part of everyday business operations and this increases non-human insider risk. They can improve productivity, reduce repetitive work and help organisations accomplish tasks far more efficiently.
The answer, therefore, is not to ban them. Instead, organisations need to manage AI agents with the same discipline applied to human identities, privileged accounts and other powerful technologies.
Following on from last weeks article where we explained the ways organisations create non-human insider risk, here are six practical steps security teams can take:
1. Start with visibility
You cannot secure AI agents you do not know exist.
Organisations should maintain an inventory of deployed agents, record who owns them, identify the systems and data they can access, and document the actions they are authorised to perform. This inventory must remain current as agents, integrations and business requirements change.
2. Apply least privilege aggressively
An agent should receive only the access required to perform its specific task.
If it summarises support tickets, for example, it should not be able to modify customer records or access financial systems. Narrowly scoped credentials and permissions reduce the potential blast radius if an agent makes a mistake, is manipulated or behaves unexpectedly. Least privilege for agentic AI must be treated as an ongoing control, not a one-time configuration exercise.
3. Use temporary privileges whenever possible
Standing administrative access creates unnecessary risk for both humans and machines.
Where an agent occasionally needs elevated privileges, access should be granted only for the specific task and revoked automatically when that task ends. Particularly sensitive actions should require an additional approval or other step-up control.
4. Monitor behaviour, not just authentication
A valid identity can still perform a dangerous action.
Security teams need to understand what normal activity looks like for each agent: which systems it usually accesses, how much data it retrieves, which tools it uses and what actions it performs. Sudden deviations, such as an unexpected data export or access to a new system, should trigger investigation.
Logging what happened is important. Determining whether it should have happened is the real challenge.
5. Keep humans involved in high-risk decisions
Large data exports, financial transactions, privilege changes, production deployments and customer-impacting decisions should include meaningful human oversight.
This does not mean requiring approval for every routine action. Controls should focus on decisions with significant security, financial or operational consequences. The goal is to ensure that someone verifies the action makes sense before it becomes irreversible.
6. Build an offboarding process
AI agents do not always disappear when projects end.
Forgotten agents can retain credentials, integrations and permissions long after their original purpose has gone away. Organisations should establish clear processes for disabling unused agents, revoking their credentials, removing connected tools and preserving relevant audit records.
AI agents may not be human, but they should still have owners, defined responsibilities and complete identity lifecycles. As their autonomy increases, the security controls surrounding them must become equally mature.
You can read the full blog from Erich Kron, CISO Advisor at KnowBe4.





