CIO Brief: AI Agents Are the Newest Privileged Users
Retrospective: this article looks back at events from May 2025, written in 2026 with the benefit of hindsight.
The short version: AI agents — software that can read your data and take actions on its own — are spreading quickly across companies. In 2025, Microsoft began giving them their own identities, like employees. Agents are now among the most powerful "users" in many organizations, and they need the same oversight.
Why agents are privileged users
An AI agent might read every email in a shared mailbox, update customer records, send messages or trigger payments. It works around the clock, can be manipulated by malicious content, and often has broader permissions than any single employee. Yet many organizations don't know how many agents they have.
The business impact
- Data exposure through over-permissioned agents.
- Unauthorized actions if an agent is manipulated or malfunctions.
- Accountability gaps when nobody owns an agent.
Questions to ask your team
- How many AI agents do we have, and who owns each one?
- What can each agent read and do?
- Do agents need human approval for important actions?
- Could we switch off an agent immediately if needed?
What good looks like
An inventory of agents with owners, least-privilege permissions, human approval for high-impact actions, monitoring of agent activity and a kill switch.
The decision
Make AI agent governance part of your identity program now, while the number of agents is still manageable.
- Microsoft Entra Agent ID (May 2025): Giving AI Agents Their Own Identities Platform Changes
- How to Inventory and Govern AI Agent Identities in Entra ID How-To & Hardening
- AI Agent Identity Governance Checklist How-To & Hardening