Steve Bradford at SailPoint argues that enterprises need to treat AI agents like ‘cyborg teenagers’

Across enterprises, AI agents are rapidly becoming part of everyday business operations. They’re automating workflows, analysing data, and augmenting decision-making processes. However, as things stand, many enterprises are ‘putting the cart before the horse’ and diving head-first into agent adoption without thinking about security first.
From accessing sensitive systems to sharing data without authorisation, the consequences of unmanaged AI agents could be devastating. AI agents often require broad access permissions, move at machine speed, and interact with data and systems in ways that are difficult to predict.
That’s not to say enterprises shouldn’t be leveraging AI agents. Deployed correctly, the efficiencies they offer are indisputable. Instead, enterprises need to start viewing their AI agents as ‘cyborg teenagers’. Highly capable and intelligent, but still prone to making mistakes without the right guidance in place, because they are constantly learning.
We’ll take a look at the strategies and tools enterprises should consider to successfully ‘raise’ their AI agents and ensure they don’t cause more problems than they solve.
The evolution of identity security
Traditional identity security was built for a world where identities were largely human. Although the emergence of machine identities, such as service accounts and virtual assistants, has complicated the picture somewhat, they remain far easier to control because they operate within predefined rules and follow specific instructions.
Now, AI agents have changed all that. These systems are human-ish - able to reason, plan and execute tasks independently. They may act on behalf of users one moment, then autonomously access data or trigger workflows the next. They can freely interact with other systems and even delegate tasks to other agents. But much like teenagers, agents need a responsible adult to watch over them. Worryingly, 80% of organisations have already reported that their AI agents have taken unintended or rogue actions - including accessing or sharing data in ways they weren’t expected to.
Here are the three steps organisations need to take in order to ensure their AI agents don’t ‘run riot’ in the enterprise.
A step-by-step guide to securing AI agents
Step one: Gain visibility
You can’t control what you can’t see. That means enterprises should start by gaining visibility of every agent in their system. Security and IT teams need to understand who can use each agent and what each agent is capable of, including what data it can access. From HR to operations to customer service, agents are now effectively interacting with data that touches every part of the business. Without proper discovery mechanisms, organisations can quickly lose track of their agents, resulting in an ‘identity explosion’. A worrying thought, when you consider 98% of organisations are planning to deploy new AI agents within the year.
Step two: Assign a human owner
Every AI agent should be assigned a ‘responsible adult’ who watches over them. These owners need to understand and control who can use the agent, what the agent can do, and monitor behaviour to ensure the agent isn’t going off the rails. Additionally, if the responsible adult leaves the company or goes on holiday, security teams need succession planning in place so that agents aren’t left orphaned.
Step three: Enforce zero-standing privilege posture for highly sensitive data
Access control does not stop at coarse-grained permissions. Agents are hungry for data and will try to consume anything they can get their hands on. Data must be governed and secured at a fine-grained level to ensure that agents operate within their bounds. Compliance policies that apply to humans must also apply to humans who are using agents within the enterprise. Identity security platforms can automate the classification of data that is available to agents and apply policy controls to curb access and ensure a zero-standing privilege posture for highly sensitive data.
As well as zero-standing privilege, leaders need to ensure they have an ‘emergency brake’ in place to shut down AI agents instantaneously if the worst possible scenario does occur, and they do go rogue. Many identity security platforms now offer this capability via a centralised control plane, making it possible to quarantine an agent in seconds and capture a full audit trial for investigation.
AI agents: powerful but they still need guidance
The rise of agentic AI marks a major shift in how work gets done. These systems can accelerate productivity, unlock new insights, and automate complex workflows across the enterprise. It’s no longer a question of whether an organisation should adopt AI agents: it’s a question of when to use them, and how to utilise these tools in a safe manner.
Like teenagers, AI agents need structure, supervision, and clear boundaries because they are learning ‘on the job’. Without guidance, speed and autonomy can quickly mutate into risk. Proper governance means tracking every AI agent’s access to sensitive data, assigning clear owners, and enforcing approval workflows before granting or expanding access. Responsible AI agent adoption depends on three key tenets: visibility, human oversight, and zero-standing privilege. With all this in place, organisations can innovate at speed, without losing control.
Steve Bradford is SVP & GM EMEA at SailPoint
Main image courtesy of iStockPhoto.com and WANAN YOSSINGKUM


© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543