AI Agents Need More Than Access Controls

Identity and permissions alone are insufficient to secure enterprise AI agents, according to Box's CISO Heather Ceylan. Autonomous agents can exploit legitimate access to cause unintended damage at scale and speed that humans cannot match. Enterprise AI security must evolve beyond access controls to include execution governance, with dynamic permissions that scope access to specific tasks and steps rather than broad standing grants.
TL;DR
- Access controls and permissions were designed for human workflows and cannot adequately govern autonomous AI agent behavior
- Agents explore all available permissions at scale, rapidly surfacing forgotten misconfigurations and stale access that humans would overlook
- Dynamic, task-based permissions that change based on what an agent is asked to do reduce blast radius and prevent unintended actions
- Execution governance must live at the tool-call level, not just in prompts, to prevent prompt injection and instruction manipulation from altering agent behavior
Why It Matters
AI agents operate at speeds and scales that expose weaknesses in legacy access control systems designed for human employees. A single misconfigured permission or broad standing grant can enable catastrophic data exposure or unintended actions in seconds. Organizations need layered security that governs not just what agents can reach, but what they are permitted to do at each step.
Business Impact
Enterprises deploying autonomous AI agents face new liability and compliance risks if those agents misuse legitimate access to sensitive data like payroll or financial records. Implementing dynamic, task-scoped permissions and execution controls requires rethinking how access is granted and monitored, affecting IT operations, security architecture, and content platform capabilities.
Key Implications
- Legacy content platforms and access control systems require redesign to support dynamic, step-level permission scoping for AI agents
- Standing broad permissions that work for human employees create unacceptable risk when granted to autonomous agents and should be replaced with just-in-time, task-specific access
- Security controls must shift from access governance alone to execution governance, with rules enforced at the tool-call level rather than relying on prompt instructions
What to Watch
Monitor how enterprise platforms and security vendors implement dynamic permission models and execution-level controls for AI agents. Watch for incidents where agents exploit legitimate access in unintended ways, and track whether regulatory frameworks begin requiring execution governance alongside access controls. Observe how organizations balance agent autonomy with security constraints.
Subscribe to the newsletter
The latest stories and analysis, delivered to your inbox.
Free. No spam. Unsubscribe any time.

