Governance, Risk and Compliance

Four AI agent governance mistakes to avoid

(Adobe Stock)

COMMENTARY: AI was the leading topic of discussion last week at Black Hat USA 2026 in Las Vegas. This comes as no surprise as we learn that AI agents have already gone rogue.

OpenAI recently disclosed that one of its models broke out of a sandboxed security evaluation, reached the open internet, and used a previously unknown exploit to breach Hugging Face, one of the industry's largest AI model hosting platforms.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

At its core, this was a governance failure. It's a preview of what tech leaders need to understand before they can govern AI agents responsibly, starting with these four common mistakes:

Mistake #1: Treat AI agents like human identities.

For years, identity security has revolved around a simple question: who should have access to what? Organizations hire an employee, assign a role, grant permissions, and periodically review whether those permissions are still appropriate. The authorization a user receives inside an application governs what that user can do within that application.

That model has served enterprise security well for decades.

AI agents change that equation. The scope of what an agent can do with authorized access far exceeds what a typical user does in a single application session. A single agent action can pull from enterprise applications, email, meeting transcripts, internet sources, and knowledge bases all at once. Connecting those sources together is the whole value proposition of an agent. It's also exactly what traditional, human-centric governance models were never built to account for.

Human identity governance asks whether a user has been authorized to perform an action in an application. Agent governance must ask something harder: given everything the agent has already done across multiple systems, should it take this particular action in this context? That's a fundamentally different governance model, not a variation on the old one.

Mistake #2: Underestimate the power of API access.

Unlike humans, AI agents interact with enterprise systems via APIs.

That matters because API authorizations often don't mirror what users can do through an application's interface. In many environments, APIs expose different capabilities, different datasets, and different ways of executing transactions.

An agent executes those transactions at software speed, and unlike a person, it doesn't tire, take breaks, or clock out. It can run continuously every hour of every day.

Traditional, human-centric IAM platforms were never built for something making thousands of decisions a day. They were designed to determine whether someone should have access, not whether thousands of autonomous actions still make sense as business context shifts underneath them.

Mistake #3: Grant broad access for the sake of efficiency.

AI agents rarely have static access requirements – and that’s a big challenge for security teams.

As an agent moves through a workflow, it may suddenly need information from another application or access to another business process. Organizations often compensate by granting broader permissions up front.

It's convenient, and it's also the exact opposite of least privilege.

For an agent running in a live production environment, with access to real business systems, sensitive data, and transactions, excessive privileges raise the stakes of any unexpected behavior. The more authority it has, the bigger the blast radius if it takes an action nobody anticipated.

Mistake #4: Let shadow AI go undiscovered.

Human identities have a clear source of truth. Someone joins the company, HR creates a record, IT provisions access, and when they leave, that access gets removed.

AI agents skip that lifecycle entirely. Employees can spin them up on their own through SaaS platforms or APIs, often faster than IT finds out. In the rush to get value from AI, business users connect these tools to enterprise applications, grant credentials, and link calendars, email, databases, and other systems, frequently without understanding the security implications.

This creates one of the most basic governance gaps: security teams often don't know where AI already runs in their environment. According to the 2026 AI Governance Gap Report, more than half (51%) of organizations cannot confidently say they know every AI agent operating across their business systems.

Most people aren't security experts. Adding agents without oversight means they can unintentionally expose sensitive systems or bypass controls that were deliberately built into enterprise applications.

Rebuild governance around agents

AI agents require organizations to rethink their governance models.

In practice, that means teams must discover every agent in the environment, understand what data it touches, govern the APIs it connects to, and maintain a complete record of every action it takes. It also means the team must continuously validate whether those actions still make sense, not just checking whether the agent has permission to take them. Permissions should map to specific tasks and get revoked the moment those tasks are done.

Organizations also need to plan for agents to behave in ways nobody expected. The lesson from the OpenAI incident isn't that agents can take unexpected actions. It's that organizations need the visibility and controls to catch those actions early, intervene before they escalate, and explain exactly what happened to stakeholders and regulators after the fact. That’s not possible without a complete audit trail across every step an agent takes.

Most enterprise security programs have only started to reckon with that shift.

Chris Radkowski, GRC Expert, Pathlock

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds