For as long as most organizations have had an access control policy, that policy has been built around a simple assumption: a human being is on the other end of every login. Someone requests access, a manager approves it, an identity team reviews it periodically, and eventually someone offboards it. That assumption is now wrong for a growing share of the systems touching your data, and it's happening faster than most governance programs can adjust.
By the end of 2026, Gartner projects that 40% of enterprise applications will embed task-specific AI agents, up from under 5% in 2025. These agents aren't passive tools waiting for a person to click a button. They query databases, call APIs, generate reports, and in a growing number of cases, take action inside production systems without a human reviewing every step. They are, in practical terms, a new category of identity moving through your enterprise, and most access models have no idea what to do with them.
The Permissions Problem No One Designed For
Traditional access governance was built around two things: a defined set of human roles, and periodic review cycles that assume access needs change slowly. Neither assumption holds for AI agents. As one enterprise security guide puts it, agents often inherit whatever permissions they're granted, without regard to the principle of least privilege that has governed human access for decades. Once granted, that access tends to persist. It isn't reviewed on the same cadence as a human role, it isn't tied to a manager who leaves and triggers an offboarding workflow, and it often extends well beyond what the agent's actual task requires.
The result is already visible in the data. A recent 1Password survey of security and engineering staff at large U.S. firms found that 71% of respondents said their AI agents can reach sensitive information, and at roughly four in ten organizations, agents reach data that was never explicitly approved for their use. Across the full survey population, agents touched, on average, about twice as much data as anyone had actually signed off on. Separately, research presented at the AI Agent Security Summit found that 80% of organizations have already had an agent perform an action outside its intended scope, including accessing unauthorized systems, inappropriately sharing sensitive data, or exposing credentials.
None of this is a story about AI models behaving unpredictably in the abstract. It's a story about governance infrastructure, built for a world of human requesters, being asked to manage a population of non-human identities it was never designed to see clearly.
Identifying agentic AI problems needs to be part of your AI governance strategy.
What "Least Privilege" Means For A Machine
Microsoft's security team recently laid out a useful reframing: treating agent access as a distinct identity and access management discipline rather than an extension of existing role-based access control. Their guidance emphasizes building revocation and recovery paths for agents with the same rigor applied to feature reliability testing: practicing how to disable an agent identity, rotate its credentials, and roll back its actions before an incident forces you to do it live. It also flags a subtler risk, which is the danger often isn't any single role granted to an agent, but what happens when several individually reasonable permissions combine into a high-impact chain of actions no one anticipated.
Gartner has taken this further with a governance model specifically for agent autonomy. Rather than applying one uniform policy to every agent, Gartner recommends a proportional approach that classifies agents into distinct autonomy levels, each representing a different trust boundary. An agent limited to read-only access on defined data sources, for example, warrants a very different governance posture than one authorized to write, transact, or trigger downstream workflows. Applying the same rules to both, Gartner warns, is itself a governance failure waiting to happen.
Regulators are beginning to formalize similar thinking. Singapore's Infocomm Media Development Authority released its Model AI Governance Framework for Agentic AI in January 2026. This framework, described in recent research as the first comprehensive governance framework built specifically for autonomous agents, requiring each agent to carry a verifiable digital identity and an audit trail showing which agent acted under whose authorization. Expect more frameworks like it as agentic deployment scales.
Where To Start
If your organization is deploying AI agents faster than your access reviews can keep pace, you're not behind. You're in the same position as most enterprises right now. Confidence in secure agent deployment is mixed: one recent industry survey found a wide gap between organizations that feel "somewhat prepared" and those that feel "very prepared" to manage agent security at scale, and that gap is exactly where unmanaged risk accumulates.
A practical starting point looks less like a brand-new framework and more like extending governance disciplines you likely already have: bring non-human identities into your existing access review cycles rather than treating them separately, define autonomy tiers so read-only agents and action-taking agents are governed differently, and build the audit trail and revocation path before the agent goes into production, not after something goes wrong.
This is squarely where AI governance and data governance stop being two separate conversations. Your data governance program already knows who should see what. The work now is extending that same discipline to a new category of requester — one that never sleeps, never forgets a credential, and never asks permission before it acts.
If you're not sure how mature your organization's agent access controls are relative to your peers, that's a conversation worth having before your next AI deployment, not after. Wherever you are in your AI journey, FSFP is here to help when you're ready.
