You Approved the AI Tool. Did You Ask What It Could Access?
Boards have spent the better part of a decade being told that identity is the new perimeter. Access reviews, least-privilege principles, prompt offboarding of departing staff — these became standard fixtures of audit committee reporting. Some organisations got genuinely good at it. Then they approved an AI agent deployment as a productivity initiative and handed it broader system access than most of their executives have, with no background check, no employment contract, and no termination process.
This is not a technical observation. It is a governance failure, and it is happening at the board approval level. iTnews recently reported that AI agents are outpacing identity governance across enterprises — that organisations largely don’t know what access these systems hold or how it was granted. What the article doesn’t say plainly enough is that the reason governance hasn’t caught up is that nobody asked it to. These deployments were approved as business decisions. Security was consulted, if at all, as a checkbox.
The Decade of Identity Discipline, Undone Quietly
Think about what large organisations have built around human identity over the past ten years. Joiners, movers, leavers processes with HR integration. Privileged access management platforms. Quarterly entitlement reviews. Separation of duties controls. External audit scrutiny on who has access to what, and whether that access is still warranted.
All of that discipline was built around one assumption: the entity with access is a person, and persons have accountability structures around them. They sign employment agreements. They can be questioned. They can be terminated. Their access can be revoked in a defined process when they leave.
An AI agent has none of that. It has credentials, often with broad permissions scoped at initial deployment and never revisited. It operates across systems — email, documents, CRM, finance platforms — under the guise of the user or service account that provisioned it. In many cases, the agent’s access was configured by the vendor during onboarding, not by your own identity team, and was not reviewed by anyone with security accountability before go-live.
The uncomfortable truth is that your AI vendor may now hold more effective access to your business information than your CFO does. And unlike your CFO, there is no annual review, no notice period, and no exit interview.
Productivity Decisions Are Not Risk Decisions
This is where board-level accountability becomes specific rather than general.
AI tool deployments are being approved as operational or productivity decisions. The CIO presents a business case. The numbers look good. The vendor’s enterprise tier comes with a compliance pack that gets filed somewhere. The board or its relevant committee approves, or delegates to management and doesn’t revisit.
What is not happening — and we have been in these rooms — is a structured discussion about what identity and access posture the tool requires, what data it will touch, what happens if the vendor is compromised, and how access gets revoked if the relationship ends or the tool is retired. Those questions belong at the approval stage. They are almost never asked.
This is a structural problem, not an implementation detail. Boards are correctly not expected to configure access controls. They are expected to ask whether access controls exist and are governed. The same audit committee that asks management to evidence quarterly user access reviews for Tier 1 systems should be asking whether AI agents are in scope for those reviews at all. In most organisations, they are not.
The Australian Governance Context Makes This Worse
Australian organisations operating under APRA CPS 234 have obligations around information asset classification, access controls, and third-party risk that are not academic. CPS 234 requires that boards maintain oversight of information security capability — which extends to whether controls over privileged access actually cover the entities holding that access.
An AI agent with administrative-level permissions to a system containing regulated data is not a grey area under CPS 234. It is a third-party system with privileged access, and it requires the same scrutiny as any other. The fact that it was marketed and approved as a productivity tool does not change the regulatory classification.
Similarly, under the Privacy Act and the OAIC’s expectations around data governance, the question of what an AI agent can read, retain, and transmit is a live compliance question — not a future consideration. If that agent has access to personal information and your organisation cannot articulate the boundaries of that access or the data flows involved, that is a problem now.
What the Board Should Actually Do
The ask here is not to pause AI adoption. It is to apply the same rigour to AI agents that you already require for human identities holding equivalent access.
Any AI tool with access to material systems or data should be in scope for your identity governance programme. That means it should be discoverable — you should be able to list what it has access to. It should be reviewable — someone should be periodically asking whether that access is still appropriate. And it should be terminable — there should be a defined process for revoking access when the tool is retired, the vendor changes ownership, or the relationship ends.
If your organisation cannot answer those three questions for the AI tools currently in production, the audit committee has a finding. Not a potential finding. A finding.
Ask management to bring a register of AI tools with current access entitlements to the next relevant committee meeting. Not a vendor brochure. Not a compliance attestation from the vendor. A register, owned internally, showing what these systems can touch and who reviewed it.
That is the question a senior board director should be asking. The organisations that ask it now will find the gap manageable. The ones that wait will find it at breach time, when the access that was never reviewed turns out to have been the path in.