NewsTradingSentimentCalendarCommunityBriefing
Tech

AI Agents Require Granular Security Controls

By Tech Desk · 2026-09-14 · 2 min read
A glowing digital shield hovering over a complex network of interconnected glowing nodes
Illustration: Tradingbird

As artificial intelligence moves into core business operations, standard identity checks are no longer sufficient to prevent unauthorized actions. New frameworks aim to govern specific agent behaviors rather than just verifying who is logging in.

Enterprise AI is shifting from passive content generation to active execution, creating a security gap that traditional models fail to address. According to Dawn-Marie Vaughan, Cybersecurity Global Offering Lead at DXC Technology, the core issue is not whether an AI agent can authenticate, but whether it should be permitted to perform a specific action at a specific moment. This distinction is critical because agents can now query sensitive systems, invoke external tools, and coordinate workflows at machine speed, a pace that makes human oversight alone ineffective.

The prevailing Zero Trust security framework, which relies heavily on identity verification, remains a necessary foundation but is insufficient for this new reality. An agent can hold valid credentials yet still execute unsafe or unauthorized tasks. To close this gap, security strategies are evolving toward decision-level governance. This approach requires evaluating every interaction, including prompts, tool calls, and data exchanges, against strict business context and policy constraints before allowing the action to proceed.

Partnerships Bridge Legacy Security Gaps

DXC Technology and Primary are collaborating to implement an AI-native Zero Trust approach that integrates with existing enterprise infrastructure. Rather than forcing organizations to replace their current security stacks, this partnership focuses on rationalizing overlapping investments in identity, network, and data security. Primary provides the specific control layer for AI actions, governing the entire transaction from identity verification to the final execution of a task.

The goal is to create a unified governed system where AI agents operate within bounded mandates. This method allows companies to retire duplicative controls that no longer add value, as noted in the report by GN technics/ai (en-US). By integrating AI action controls into the broader cybersecurity architecture, organizations can manage risks associated with agents crossing boundaries that legacy products were never designed to handle.

Limiting Access Prevents Data Exposure

A key trade-off in securing AI agents is the rejection of broad, repository-level access. Instead, effective governance requires assigning each agent a distinct identity and applying attribute-based policies that enforce access at the session layer. This ensures that agents receive only the minimum data and authority required to complete a defined task, preventing persistent entitlements that remain active after the task is finished.

This granular control allows organizations to govern both the intent of the agent and the outcome of its actions. By recording the prompt, response, tool call, and data movement as one accountable transaction, companies gain full visibility into how AI interacts with sensitive information. This level of detail is essential for maintaining compliance and trust as AI systems become more deeply embedded in daily business operations.

Traditional Models Fail Against Agents

Traditional security models are built on the assumption that activity is attributable to a person, a stable application, or a predictable service account. AI agents defy these categories. They are dynamic, autonomous, and capable of acting across multiple systems simultaneously. This lack of predictable behavior means that security controls must shift from static identity checks to dynamic, context-aware decision-making processes.

The transition to this new model requires a fundamental change in how enterprises view machine autonomy. It is no longer enough to ask who is accessing the data; the question must be what the system is doing with that data and why. As AI agents continue to expand their capabilities, the ability to enforce these precise, moment-to-moment controls will determine the security posture of modern organizations.

Based on reporting by Cyber Magazine, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories