29 July 2026

When AI actus on our behalf, governance needs to follow

In Part 1, we looked at a simple question: when an AI assistant acts with someone’s identity and authority, who is accountable for what it does?

That question becomes more important as assistant move from retrieving and summarising information to agents capable of making decisions and taking actions.

The next question is therefore: are our existing identity and governance controls designed for this?

What our existing governance and controls are missing cover it

We built our control frameworks for deterministic systems run by human actors.

Access policies authenticate and authorise a person, then stop, they say nothing about what an assistant does once it’s acting with that person’s authority.

Acceptable use policies govern what staff type into an AI tool; they’re silent on what the assistant does on its own, with no user action at all.

Data classification labels a document as confidential, but that label doesn’t stop an assistant from summarising it.

The frameworks organisations trust, like NIST’s Cybersecurity Framework and the risk guidance emerging for AI systems, already point toward the answer. The challenge is applying those principles consistently to this new class of identity.

The governance shift that matters

The organisations getting ahead of this are treating every AI assistant and agent as a first-class identity, not a feature switch. In practice that means:

  • Knowing what it can reach. Least-privilege access to data and systems by default, so a compromised or misused assistant has a small blast radius rather than the run of the business.
  • Owning it like any privileged account. A named owner, a defined lifecycle from onboarding to decommissioning, and periodic access reviews, exactly what any senior staff member or service account or deterministic workload would be subject to.
  • Watching what it does. Treating its actions as security events worth logging and reviewing, and requiring re-authorisation whenever its capabilities expand, rather than letting its authority quietly grow.

 

The boundary won’t wait

The principal risk here isn’t a lack of investment in security tooling. It’s relying on vendor assurances as a substitute for enforceable, identity-grounded governance. As assistants become more agentic and autonomous, the exposure moves from information disclosure to the active execution of tasks and the abuse of authority.

The least-privilege boundary set now isn’t overhead. It’s operational resilience, and it’s rarely available to draw upon retrospectively. It’s set before an incident or explained afterwards.

AI assistants are already identities in every system that matters.

The question for the leaders who carry this risk is whether governance has caught up: would you allow a human or service account to operate with the same reach, autonomy and oversight as your AI assistant?

If the answer is no, governance has some catching up to do.

Who answers when a machine acts in your name?
05Aug

Who answers when a machine acts in your name?

At SSS - Cybersecurity Specialists, we spend a lot of time with the leaders who…

The millionth-credential challenge
28Jul

The millionth-credential challenge

In pharmaceutical development, there's a well-known principal called "the first-pill problem". Brining a new medicine…

Reaching into the digital world
28Jul

Reaching into the digital world

Banking, shopping, learning, connecting with friends, joining communities, building a career. Increasingly, our digital lives…

Tākina Convention & Exhibition Centre