Recommended Free Tools
An AI agent is not an employee, but if it can sign in to company systems, access sensitive data, change records, or trigger business processes, it has effective authority that needs to be governed. Treat the agent’s identity and permissions—not its apparent autonomy—as the core security issue: know what exists, what it can do, who approved it, and how to revoke its access.
What “privileged” means for an AI agent
Privilege is about capability, not job title. An agent is privileged when the identities or credentials it uses let it reach sensitive information or perform consequential actions—for example, changing operational records or invoking administrative functions.
Keep the agent distinct from the mechanisms it uses. An AI agent may act through a service account, cloud role, integration, or credential. Each can have different permissions and owners; governing the agent alone will not reveal all the access paths it can use.
Serkan Cetin, Head of Solutions Engineering at Tenable ANZ, framed the issue this way in an iTWire guest opinion published 30 September 2026: “The main issue to consider when onboarding AI is that your newest privileged employee will never show up on the payroll – but it still needs a job description, a manager, and an offboarding plan.” The employee comparison is a useful reminder about accountability, not a claim that an agent is literally a person.
#1 Best Overall
What the reported figures show—and what they do not
Tenable’s 2026 Cloud and AI Security Risk Report release says its analysis used anonymized telemetry from diverse public-cloud and enterprise environments collected from April through October 2025, with AI findings extending through December 2025. Tenable is both the report publisher and a security vendor, so its figures should be read as vendor-reported findings within that stated scope, not as independent prevalence estimates for every organization.
| Finding | What Tenable reported |
|---|---|
| Non-human and human identities with critical excessive permissions | 52% of non-human identities, compared with 37% of human users, had critical excessive permissions in Tenable’s 2026 analysis. |
| Organizations with AI services holding rarely audited administrative permissions | 18% of organizations in Tenable’s 2026 analysis. |
| AWS roles that AI services could instantly assume | 18% of organizations had IAM roles with critical or high excessive permissions that AWS AI services could instantly assume, according to Tenable’s 2026 findings. |
| Inactive AWS roles | Tenable reported that 73% of Amazon SageMaker roles and 70% of Amazon Bedrock agent roles were inactive in its 2026 analysis. |
The identity figures cover non-human identities and human users; they are not all measurements of AI agents alone. The AWS findings concern cloud roles and their exposure or use, not proof that an agent caused a breach. Together, they support a more specific concern: identities and roles can hold excessive permissions or remain unused, leaving access paths that deserve review and removal when they no longer serve a purpose.
Rank #2
See Tenable’s 2026 report release and its report and AWS findings for the vendor’s published figures and context.
How to govern agent access
1. Inventory agents, identities, and credentials
Maintain a record of each agent and the service accounts, roles, integrations, and meaningful credentials it uses. Link each entry to a defined business purpose and an accountable owner. An agent that cannot be tied to an owner and a purpose is difficult to assess or safely offboard.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsRank #3
2. Grant only the access its task requires
Scope permissions to the agent’s defined task. Avoid expanding access merely to make a prototype easier or meet a deadline. Review what the agent can reach through every identity it uses, not just the permissions shown in its application configuration.
3. Review access and use continuously
Access and workloads can change faster than a quarterly review catches. Build ongoing review into identity and cloud operations, and remove permissions that are no longer needed. Pay particular attention to inactive identities and roles: inactivity does not itself prove compromise, but it can indicate access with no continuing business purpose.
Rank #4
4. Make revocation part of onboarding
Name the person or team that can explain why the agent has access and can disable it. Decide how to revoke its credentials, remove or restrict its roles, and stop related integrations if it is compromised or no longer needed. Rehearse that response rather than assuming a shutdown button will remove every access path.
5. Check roles AI services can assume
For cloud environments, identify which roles AI services can assume and examine whether those roles carry administrative or otherwise excessive permissions. Tenable’s AWS findings make this a concrete review area: the relevant question is not just which role an agent currently uses, but which roles its service may be able to assume.
Best Value
Questions boards should ask
These five questions, presented by Cetin in the iTWire article, can help boards test whether an organization has made agent access visible and accountable:
- “How many agents can act inside the business today?”
- “Which of these agents can reach sensitive customer, financial or operational data?”
- “Who approved that access?”
- “What happens if the agent is compromised?”
- “What is the risk to our business, and how is this risk being managed?”
A useful answer connects the inventory to actual permissions, a named owner, a response plan, and an explanation of the business risk. A count of agents without their access paths is not enough to show what they can do.
What to look for in a governance process
These controls are about identity and access governance; the evidence here does not establish that any particular security product is required or identify a winning tool. If evaluating software, compare it against the work the organization needs to do:
Quick Recap
- Can it discover agents, non-human identities, roles, and meaningful credentials across the relevant environments?
- Can it associate access with an accountable owner and support onboarding, review, and offboarding?
- Can teams scope permissions to tasks and see what an identity can reach or assume?
- Does it provide audit visibility and help identify dormant identities and excessive access?
- Does it cover the cloud providers and systems the organization actually uses?
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

