Mitigating security risks of Agentic AI
Mitigating security risks of Agentic AI
My second panel at teissAmsterdam 2026 focused on a different AI security problem: Agentic AI.
I joined Nir Chervoni, Jarren Budds, Shreeji Doshi and JB Benjamin to discuss what changes when AI moves beyond generating an answer and starts taking action.
For me, that changes the security question fundamentally:
The question is no longer only whether the model can be wrong. It is whether it can be wrong with permissions.
Treat agents as non-human identities
An AI agent is more than a model. Once it can access systems, use tools and execute tasks on behalf of a person or process, it becomes a non-human actor with context, delegated authority and the ability to create real business outcomes.
That means many familiar security principles become even more important.
Least privilege. Separation of duties. Strong authentication. Logging. Approval boundaries.
Instead of inventing an entirely new security discipline for agents, we should first apply these principles rigorously to this new class of identity.
Delegation needs to be verifiable
If an agent is allowed to act on behalf of someone, we should be able to answer some basic questions.
Who delegated the task? What exactly was delegated? For how long? Under which conditions? And how can that authority be revoked?
Without those answers, it becomes difficult to distinguish legitimate autonomous behaviour from overreach.
Delegation without verification is simply automation without sufficient accountability.
Permanent access is the wrong default
Persistent permissions are already a problem for human and machine identities. For autonomous agents, the potential impact increases because those permissions can be exercised at machine speed.
Agents should therefore receive access when they need it, for a specific task, with the minimum required scope and for the shortest practical period.
Just-in-time access should be a default design principle rather than an optimisation added later.
Context matters
Traditional role-based access control can also become too blunt.
Whether an agent should be allowed to take an action may depend on the sensitivity of the data, the business context, transaction risk, the user involved and whether the action can be reversed.
In an agentic environment, authorisation increasingly needs to understand not just who is requesting access, but what is happening.
Trust can fail before technology does
The first visible failure of Agentic AI may not be a major breach.
It could be an incorrect decision, an agent acting beyond expectations, inappropriate data exposure or a poor customer experience. Those events can erode confidence long before an organisation experiences a conventional cyber incident.
People therefore need practical operating principles: what data an agent may use, what should never be fully delegated, when human approval is mandatory, what must be logged and how an AI-related incident is escalated.
If people do not know where autonomy ends, they will eventually discover it through failure.

The objective is not to choose between innovation and control. It is to design AI-enabled systems where innovation can move quickly without trust collapsing underneath it.