You Approved the AI Tool. Did You Ask What It Could Access?
Boards have spent the better part of a decade being told that identity is the new perimeter. Access reviews, least-privilege principles, prompt offboarding of departing staff: all standard fixtures of audit committee reporting now, and some organisations got genuinely good at it. Then the same board approved an AI agent deployment as a productivity initiative and handed it broader system access than most of its executives hold, with no background check, no employment contract and no termination process.
iTnews recently reported that AI agents are outpacing identity governance across enterprises, and that organisations largely cannot say what access these systems hold or how it was granted. The part the article leaves implicit is why governance never caught up: nobody asked it to. These deployments went through as business decisions, and security was consulted late, if at all.
The Decade of Identity Discipline, Undone Quietly
Think about what large organisations have built around human identity over the past ten years. Joiners, movers, leavers processes with HR integration. Privileged access management platforms. Quarterly entitlement reviews. Separation of duties controls. External audit scrutiny on who has access to what, and whether that access is still warranted.
All of that discipline was built around one assumption: the entity with access is a person, and persons have accountability structures around them. They sign employment agreements. They can be questioned. They can be terminated. Their access can be revoked in a defined process when they leave.
An agent has none of that. It has credentials, usually with permissions scoped generously at deployment and never revisited, and it works across email, documents, CRM and finance platforms under the identity of whichever user or service account provisioned it. Often those permissions were set by the vendor during onboarding rather than by your identity team, and nobody with security accountability looked at them before go-live.
Which means your AI vendor may hold more effective access to your business information than your CFO does, without the annual review, the notice period or the exit interview.
Productivity Decisions Are Not Risk Decisions
AI tool deployments are being approved as operational decisions. The CIO presents a business case, the numbers look good, the vendor’s enterprise tier arrives with a compliance pack that gets filed somewhere, and the committee approves or delegates to management and does not revisit it.
We have sat in those rooms. What almost never happens is a structured discussion of what access posture the tool actually requires, what data it will touch, what the exposure is if the vendor is compromised, and how access gets revoked when the relationship ends or the tool is retired. All four questions belong at the approval stage.
Boards are not expected to configure access controls, and nobody sensible wants them to. They are expected to ask whether the controls exist and whether anyone governs them. An audit committee that requires evidence of quarterly access reviews for Tier 1 systems should be able to ask, in the same breath, whether AI agents are in scope for those reviews. In most organisations the honest answer is no.
The Australian Governance Context Makes This Worse
Australian organisations operating under APRA CPS 234 have obligations around information asset classification, access controls, and third-party risk that are not academic. CPS 234 requires that boards maintain oversight of information security capability — which extends to whether controls over privileged access actually cover the entities holding that access.
An AI agent with administrative permissions over a system holding regulated data is not a grey area under CPS 234. It is a third party with privileged access and it attracts the same scrutiny as any other. Being marketed and approved as a productivity tool does not change the classification.
The Privacy Act position is similar. What an agent can read, retain and transmit is a live compliance question today. If it touches personal information and the organisation cannot describe the boundaries of that access or the data flows behind it, the problem exists now, whatever the roadmap says.
What to Ask For
Nobody is suggesting you pause AI adoption. The ask is narrower: apply to AI agents the rigour you already apply to a human holding equivalent access.
Any tool reaching material systems or data belongs in scope for identity governance. In practice that means someone can produce a list of what it can reach, someone periodically asks whether that is still appropriate, and there is a defined way to switch it off when the tool is retired or the vendor is acquired. Discoverable, reviewable, revocable. If those three cannot be evidenced for the AI tools already in production, the audit committee has a finding rather than a watch item.
So ask management for a register of AI tools and their current access entitlements at the next committee meeting — owned internally, not a vendor brochure and not an attestation from the supplier, showing what these systems can touch and who last looked at it. Organisations that ask this year will find the gap tedious but manageable. The ones that leave it will meet the same list during an incident, at the point where the access nobody reviewed turns out to have been the way in.