Here are five critical actions Chief Information Security Officers (CISOs) should prioritize now to safeguard AI agents.
Mar 17, 2026 // 21:14 - Niko Dunn


By Itamar Apelblat, Founder and CEO, Token Security

AI agents that can act independently are a game changer for businesses. These aren’t just improved chatbots or assistants.

They’re self-governing entities that strategize, make decisions, and take actions. More and more, they’ll be writing code, handling data, carrying out transactions, setting up infrastructure, and interacting with customers—often without human intervention. They’ll also work constantly, across different systems, at rapid speeds.

This shift is already creating significant business advantages. However, this will only work if security is addressed. Currently, most businesses are not ready.

Current AI security methods often involve setting up restrictions like filtering inputs, controlling outputs, and tracking behavior. This approach isn’t ideal. These restrictions try to limit actions after access is granted. But once an AI agent has access and permissions, a single error can lead to data breaches, destructive actions, or widespread problems across connected systems.

To secure AI agents effectively without hindering progress, you need to rethink how you control them. Managing access through identity management—not prompts, networks, or vendor promises—is the best foundation for securing and managing independent systems.

For a more in-depth explanation of why identity is becoming so important for AI security, check out Securing Agentic AI: Why Everything Starts with Identity.

Here are five essential steps that CISOs should take now to ensure AI agent security:

1. Treat AI Agents as Key Identities

As soon as an AI agent is linked to live systems, APIs, cloud roles, software platforms, or infrastructure, it transitions from an experiment to a key identity.

Each AI agent utilizes identities, often multiple: API keys, OAuth permissions, service accounts, cloud roles, secrets, and access keys. Yet most businesses don’t track, manage, or properly govern these identities.

You must insist that every AI agent is handled as a critical digital identity:

If you aren’t tracking your agents’ identities, you aren’t in control.

2. Move from Restrictions to Access Management

Restrictions assume that AI can be contained by rules. However, AI agents are unpredictable and learn. With endless possible inputs and interactions, getting around restrictions is inevitable.

Even if input controls worked almost all the time, a tiny fraction of infinity remains infinite.

Security should focus on access management, where the real control exists. You need to consider:

When access is strictly defined, actions become much less risky. Identity-based access management is a safety net for independent software. Network controls are too generalized. Input filters are too inadequate. Promises from AI platforms aren’t sufficient.

Identity management is the only control that spans every system an agent uses.

3. Address Unseen AI by Enhancing Identity Visibility

The key to unseen AI isn’t just about tools; it’s about identity. Developers, IT staff, and business users are already building AI agents that connect to crucial systems, use APIs, get data, and kick off workflows.

These agents don’t announce their presence; they simply start working. When security teams can’t see these identities, Zero Trust falls apart. Unknown agents are trusted automatically because their credentials are valid.

You need to prioritize:

If you can’t see it, you can’t protect it. And in the AI landscape, what goes unseen often acts independently.

4. Secure Based on Purpose, Not Just Permissions

AI agents are driven by goals. Two similar agents with similar permissions can act very differently based on their purpose. This introduces a missing aspect in traditional access models: purpose.

To effectively secure AI agents, businesses need to answer:

An agent designed to summarize support requests shouldn’t be able to export the entire customer database. An agent that optimizes infrastructure shouldn’t be able to alter access management policies. Purpose determines acceptable behavior.

This challenges the risky idea that agents can simply inherit human permissions. An agent acting “on behalf of” a senior engineer shouldn’t automatically receive all of that engineer’s permissions.

Securing AI agents isn’t about predicting behavior; it’s about enforcing purpose through strictly defined identity and access controls.

5. Fully Manage the AI Agent Lifecycle

Security problems rarely occur at the start; they develop over time. Access builds up. Ownership becomes unclear. Credentials remain active. Agents are changed, repurposed, and eventually abandoned, often without notice. AI agents speed up this process significantly. What once took months can now happen in hours or even faster.

You must ensure lifecycle governance for every agent:

Without continuous lifecycle management, risk grows unnoticed. If you can’t answer these questions at any moment, you aren’t in control of your AI agents.

New approaches to managing the AI agent identity lifecycle are emerging to specifically address this challenge. Download Token’s new AI Agent Identity Lifecycle Management ebook for details.

AI agents that act autonomously are coming, and they will greatly benefit businesses. The advantage is in autonomous access, which lets agents operate across systems at scale and at machine speed. But, independence without identity control results in disorder.

Businesses that simply add AI to old, human-focused identity models will either over-privilege agents or slow innovation. Businesses that ignore identity will ultimately lose control. The solution isn’t to limit AI but to properly secure it.

Identity management is the only way to effectively control AI agents at scale. Managing the lifecycle is essential. And security must support, not hinder, innovation.

The companies that succeed in the coming decade will be those that use AI to transform their business while staying secure. Identity is critical to achieving this.

To see how Token Security is handling AI agent identity at scale, schedule a demo with our technical team.

Sponsored and written by Token Security.

#actions  #agents  #are  #chief  #cisos  #critical  #five  #here  #information  #news  #now  #officers  #prioritize  #safeguard  #security  #should   —   News