As AI agents gain the ability to access emails, files and business applications and perform tasks on behalf of employees, cybersecurity experts are raising questions over how organisations can track their actions and determine responsibility when something goes wrong.

Unlike conventional software, AI agents can make decisions and execute multiple steps across connected systems. This creates a new security challenge: an action may be carried out using legitimate credentials, but it may not always be clear whether the employee, organisation or AI agent effectively authorised the specific action.

“The next major AI-security incident may involve an authorised agent making the wrong decision with the right credentials,” said Zheng Li, co-founder and Group Vice President of Abu Dhabi-based AI company ANSEN.

“Traditional cybersecurity asks whether a user, file or process is malicious. In the agentic AI era, organisations must also ask: Should this AI be allowed to take this particular action?”

AI agents may need separate identities

The issue is becoming increasingly relevant as businesses deploy AI agents to work with enterprise data and applications.

A recent National Institute of Standards and Technology (NIST) publication warned that organisations are increasingly sharing existing human credentials with AI agents to give them access to data, applications and services. NIST said this can create accountability, privacy and security gaps.

NIST recommends treating agents as “first-class entities”, giving them their own identifiers, credentials and associated permissions while linking those permissions back to the human or system responsible for authorising the agent.

The approach is intended to make it easier to establish which agent performed an action, what authority it had and who authorised that authority.

NIST's broader AI Agent Standards Initiative is also examining authentication, identity infrastructure and secure human-agent and multi-agent interactions.

Access does not mean unlimited authority

Giving an AI agent its own identity is only one part of the security challenge.

An agent may be authorised to perform one task but could potentially gain significant power when it is connected to several systems. For example, an agent permitted to analyse a security alert may not necessarily need permission to disable an account, change a security policy or shut down a service.

Li said the level of control should correspond to the potential consequences of an action.

“An AI system may be allowed to summarise an alert automatically, but blocking a critical service, changing a security policy or initiating a real-world response should remain governed,” he said.

This distinction becomes particularly important when agents can simultaneously interact with email, databases, files, ticketing systems and other business applications.

New controls focus on traceability

The cybersecurity industry is also developing standards aimed at making AI agents more visible and controllable.

The OWASP GenAI Security Project introduced its Agent Control Standard (ACS) on September 1. The standard calls for agents to be inspectable, traceable and instrumentable, including visibility into what an agent is, what it can access, what it has done and why. It also focuses on controls that can be enforced while agents are operating.

The emerging approach therefore goes beyond simply asking whether an AI system has permission to access a particular platform.

Organisations increasingly need to determine what the agent can do after gaining access, how long its authority remains valid and whether its actions can be reconstructed afterwards.

Why agentic AI security matters in the UAE

The issue is particularly relevant as the UAE expands the use of AI across government and business.

The country's wider push towards agentic AI means questions around identity, authorisation, auditability and human oversight will become increasingly important as automated systems are connected to more services and operational processes.

For organisations deploying these systems, the challenge is to maintain the speed and automation that make AI agents attractive without creating unclear chains of authority.

Li said human control does not necessarily require people to manually approve every automated action.

“AI handles volume and speed. Humans provide judgement,” he said.

As AI agents become more capable, cybersecurity is therefore moving beyond the question of whether an AI system can access a platform to a more fundamental question: who authorised the agent, what was it allowed to do and can the organisation establish exactly what happened afterwards?

AI agents agentic AI AI security Abu Dhabi AI ANSEN cybersecurity UAE AI identity AI governance NIST AI agents OWASP Agent Control Standard AI accountability UAE technology