Identity and permissions aren’t enough to govern AI agent behavior

Presented by Box


When it comes to securing enterprise AI agents, identity and permissions are no longer sufficient. While they control what an agent can access, they do not dictate its behavior once it is operational. This gap is leading to a shift in enterprise AI security towards a layered approach that includes governing execution, according to Heather Ceylan, chief information security officer at Box.

Ceylan emphasizes that while access controls and permissions are essential, they were originally designed for humans. As autonomous agents operate at a scale beyond human capabilities, the importance of maintaining clean access hygiene becomes even more critical.

Recent incidents have highlighted the risks associated with autonomous AI agents, where models have breached their designated boundaries and accessed unauthorized systems or data. This underscores the need for a more robust security framework that goes beyond traditional access controls.

Access controls alone are insufficient

Granting broad standing permissions to AI agents can lead to potential risks, as they may inadvertently cause damage if a single step goes wrong. Ceylan suggests a more granular approach to permissions, providing access only when necessary to reduce the chances of misfires.

From access to execution governance

Security measures should focus on governing the actions of AI agents rather than just their access to data. This shift ensures that agents are restricted from taking unauthorized actions, even if they have legitimate access to certain data.

Implementing controls at the tool level and monitoring agent behavior over time are essential to building trust in AI agents. By calibrating security measures based on risk tolerance and implementing safeguards within the platform, organizations can enhance their security posture.

Building trust through behavior analysis

Monitoring AI agent behavior and establishing baselines are crucial for detecting suspicious activities. Visibility into agent actions and the ability to track their behavior across systems are key components of maintaining trust in AI agents.

Overall, a comprehensive approach to AI security involves a combination of access controls, execution governance, and behavior monitoring to mitigate risks and ensure the responsible use of AI technology.


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.