Skip to content
IdentitéTrust starts here
English
EnglishEspañolPortuguês
Contact

AI Agents Are Moving Into the Enterprise: Seven Mistakes That Can Turn Automation Into a Security Risk

Eusebio CoterilloEusebio Coterillo ·
Editorial illustration for AI Agents Are Moving Into the Enterprise: Seven Mistakes That Can Turn Automation Into a Security Risk.

Artificial intelligence is rapidly moving from answering questions to taking action.

That distinction is enormous.

Traditional generative AI might summarize a report, draft an email or analyze information.

AI agents can potentially do much more.

And, depending on the authority they are given, make decisions and take actions with limited human involvement.

A recent CIO article, “7 mistakes IT leaders make when deploying AI agents,” highlights an important reality for enterprise leaders: organizations are under tremendous pressure to deploy AI agents and demonstrate business value, but moving too quickly can create rogue agents, AI debt, compliance problems and operational consequences.

The article's message is straightforward.

Deploying AI agents successfully requires far more than selecting an AI model and connecting it to enterprise systems.

Organizations need governance, accountability, trustworthy data, carefully controlled access, continuous monitoring and a strategy for the people whose workflows will be affected.

There is also another issue that deserves particular attention.

Identity.

Once software can act autonomously on behalf of people and organizations, enterprises must determine not only what an AI agent is capable of doing, but also:

Those questions place identity and authentication directly at the center of the agentic AI conversation.

AI Agents Are Not Just Another Application

One of the easiest mistakes to make is treating an AI agent like conventional enterprise software.

Traditional software generally follows predefined instructions.

Given the same inputs and conditions, deterministic software should produce predictable results.

AI agents introduce variability.

They may interpret information, select tools, determine intermediate steps and take actions based on changing context.

CIO notes that agents can be non-deterministic and stateful, meaning the same request may result in different sequences of tool calls. Even a series of individually permitted actions can potentially combine into an undesirable result, including unauthorized transactions or data exfiltration.

That means the traditional security model of:

Let's examine the seven mistakes identified by CIO and what they mean for enterprise security.

Mistake 1: Using AI Agents When Conventional Automation Would Work Better

Not every business problem needs AI.

That may sound obvious, but the excitement surrounding AI agents can encourage organizations to treat them as the default solution.

CIO points out that processes with known inputs, predictable outputs and established execution requirements may be better served by conventional automation, integrations or predictive systems. Agents can introduce additional cost, latency and variability into processes that were already reliable.

This creates an important first question:

Does this process actually require judgment?

If the answer is no, an AI agent may unnecessarily increase complexity and risk.

The objective should not be:

Deploy as many AI agents as possible.

It should be:

Use AI where AI creates measurable business value.

Security benefits from that discipline too.

Every additional autonomous system creates another identity, another permission structure, another set of integrations and another potential attack surface that must be governed.

Mistake 2: Giving AI Agents Authority Without Accountability

This may be one of the most important issues CIO identifies.

Who owns the AI agent?

And more importantly:

Who is responsible when it makes the wrong decision?

CIO argues that agents, particularly those automating parts of business-critical decision making, need clearly identified owners. Organizations should establish governance before experimentation begins and determine when human augmentation is mandatory, when humans must remain in the middle of the process and when agents can operate autonomously.

This becomes even more complicated with multiple agents.

These are not simply AI governance questions.

They are identity and authorization questions.

AI Agents Need Identities Too

Editorial concept illustrating AI Agents Are Moving Into the Enterprise: Seven Mistakes That Can Turn Automation Into a Security Risk

Humans aren't the only identities operating inside modern enterprises.

And those agents may act on behalf of people.

That means organizations need to distinguish among several different concepts:

Simply giving an agent access credentials is not enough.

Authentication establishes identity. Authorization establishes what that identity is permitted to do.

Agentic AI makes both dramatically more important.

Mistake 3: Building Agents on Data You Cannot Trust

AI agents depend heavily on the information available to them.

If the underlying data contains duplicates, outdated records, conflicting definitions or inaccurate information, an agent may confidently act on bad data.

CIO makes this point particularly well: AI agents can amplify existing data and governance problems at machine speed. Trusted business data, context and governance therefore need to become prerequisites for reliable agentic AI.

This creates a simple principle:

Automation does not transform bad data into good data.

It can transform bad data into faster bad decisions.

Before organizations grant AI agents meaningful autonomy, they need confidence in the information driving those decisions.

Data provenance matters.

Data integrity matters.

Permissions matter.

And the identity of whoever can modify that data matters too.

Mistake 4: Giving AI Agents Too Much Access

This is where agentic AI becomes a significant cybersecurity issue.

Human experts often have broad access because their jobs require it.

That doesn't mean an AI agent assisting those experts should inherit the same permissions.

CIO cites experts who recommend thinking about AI agents more like semi-trusted contractors or unvetted employees than fully trusted insiders. Organizations should define exactly what information agents can access, what systems they can interact with and what boundaries they cannot cross.

This is classic least privilege applied to AI.

An accounting agent shouldn't automatically have access to HR information.

A recruiting agent shouldn't automatically have access to financial systems.

A customer-service agent shouldn't automatically have administrative privileges.

And an agent that needs read access doesn't necessarily need write access.

The principle should be:

Give the agent the minimum authority necessary to perform its assigned task.

Nothing more.

An AI Agent Should Never Inherit Unlimited Human Authority

Balance visual connecting An AI Agent Should Never Inherit Unlimited Human Authority, Mistake 5: Testing AI Agents Like Traditional Software, Authentication Should Follow the Transaction, Mistake 6: Deploying AI Agents Without a People Strategy

Consider an executive who has access to dozens of enterprise applications.

The executive authorizes an AI agent to help prepare financial reports.

Should the agent automatically inherit every permission belonging to that executive?

Of course not.

Yet poorly designed agent architectures could create precisely this problem.

This becomes especially important when agents can communicate with other agents.

A chain of individually legitimate permissions could potentially produce an outcome nobody intended.

Mistake 5: Testing AI Agents Like Traditional Software

Traditional software testing often assumes that behavior can be evaluated before deployment and that production software will continue behaving according to those tested rules.

AI agents challenge that assumption.

CIO notes that production environments can introduce different data, contexts and tool-call sequences than those encountered during pre-deployment testing. The article therefore recommends combining testing with ongoing monitoring and runtime enforcement.

One expert cited by CIO recommends several particularly useful controls:

A kill switch capable of suspending an agent quickly.

A behavioral baseline defining normal activity.

A post-incident review process after near misses.

And a feedback process for improving controls.

These concepts should sound familiar to cybersecurity professionals.

They closely resemble the controls we already use to protect human identities.

Authentication Should Follow the Transaction

This raises another important question.

Suppose an AI agent has permission to purchase routine office supplies.

A normal transaction might be:

$300 from an approved supplier.

But one day the agent attempts:

$300,000 to a previously unknown recipient.

Should the fact that the agent was authenticated allow that transaction to proceed automatically?

Probably not.

The transaction itself has changed the risk context.

A mature security architecture might require additional authorization.

For example:

Agent requests transaction → Risk evaluated → Human authorization required → Human strongly authenticates → Transaction proceeds

This is where authentication becomes part of agent governance rather than merely an employee login function.

Mistake 6: Deploying AI Agents Without a People Strategy

Network visual connecting Mistake 6: Deploying AI Agents Without a People Strategy, Human in the Loop Is Only Useful If You Know Which Human Is in, Mistake 7: Treating Deployment as the Finish Line, The Security Question Behind All Seven Mistakes

AI deployment is not only a technology project.

It changes how people work.

CIO emphasizes the importance of determining when agents operate independently and when they must stop and involve a human. Organizations also need change-management programs that help employees understand evolving workflows and learn how to manage AI agents effectively.

This leads to one of the most important questions in agentic AI:

When should the AI stop and ask a human?

The answer will vary by organization and industry.

But the decision should be made before deployment, not after the first serious incident.

Human in the Loop Is Only Useful If You Know Which Human Is in the Loop

There is another dimension to human oversight that receives less attention.

Suppose an AI agent stops and requests approval.

Someone clicks:

Was the request presented by the legitimate enterprise system?

These questions move agentic AI directly into the authentication conversation.

Mistake 7: Treating Deployment as the Finish Line

Deploying an AI agent is not the end of the project.

It is the beginning of its operational life.

CIO emphasizes that agents may encounter edge cases and messy integrations in production that never appeared during carefully controlled pilots. Organizations therefore need an operating model built around continuous delivery, measurement, feedback and improvement.

That means organizations should continuously evaluate:

Agent governance cannot be a once-a-year compliance exercise.

Autonomy requires continuous oversight.

The Security Question Behind All Seven Mistakes

Although CIO's seven mistakes address different aspects of AI deployment, they converge around a common idea:

And don't automatically trust an agent simply because it was previously approved.

This is essentially a Zero Trust philosophy applied to agentic AI.

Trust should be established according to identity, authorization, context and risk.

AI Agents Create a New Identity Layer

Article-specific explanatory visual for AI Agents Create a New Identity Layer

Enterprise IAM was already complicated before AI agents arrived.

Now imagine an organization operating hundreds or thousands of agents.

That creates an entirely new category of machine identity.

The security model therefore needs to connect:

Human Identity → Agent Identity → Delegated Authority → Transaction

If that chain breaks anywhere, accountability breaks with it.

Why Passwordless Authentication Becomes More Important

AI agents do not eliminate the need to authenticate people.

In many cases, they make strong human authentication even more important.

The higher the authority granted to an agent, the more important it becomes to establish the identity of the human who:

Traditional passwords are poorly suited to carry that level of trust.

When AI agents can potentially initiate consequential enterprise actions, compromised administrator credentials become particularly dangerous.

Passwordless Authentication Removes the Reusable Password

Passwordless authentication changes the equation by eliminating reliance on a reusable password.

Authentication can instead combine factors such as:

Something the user has, such as a trusted device.

and

Something the user is, such as locally verified biometrics.

This can provide strong multi-factor authentication without requiring a password that can be phished or reused.

But Identité's approach goes beyond simply removing the password.

Full Duplex Authentication® Is Particularly Relevant to Agentic AI

Editorial scene illustrating Full Duplex Authentication® Is Particularly Relevant to Agentic AI

AI agents create complex chains of communication.

A human may communicate with an agent.

The agent may communicate with an application.

That application may communicate with another service.

Another agent may become involved.

Eventually, a high-risk action may return to the human for authorization.

At that point, authentication should answer more than:

"Is this the legitimate user?"

It should also help establish:

"Is this the legitimate destination requesting authorization?"

That is the principle behind Identité's patented Full Duplex Authentication®.

Traditional authentication primarily authenticates the user to the destination.

Full Duplex Authentication® establishes mutual authentication.

The user establishes legitimacy.

The legitimate destination establishes legitimacy.

Both sides participate in the authentication relationship.

In an environment filled with automated agents, APIs and machine-to-machine interactions, the principle becomes increasingly important:

Trust should not be assumed simply because a request arrived from something that appears legitimate.

Intent Matters When AI Requests Human Approval

Suppose an agent sends an executive an authentication request approving a $2 million transaction.

A generic notification saying:

Approve?

isn't enough context for such an important decision.

Identité can provide contextual information during authentication and explicitly ask:

"Did you request this authentication session?"

On the same screen, Identité can present an image and three-digit verification number associated with the authentication interaction.

This helps move the user from reflexive approval toward confirmation of intent.

That becomes especially valuable in an agentic environment.

The human should not simply authenticate.

The human should understand why they are authenticating.

Decentralized Biometrics Reduce Another Enterprise Risk

If biometrics are used for strong human authentication, organizations should also consider where that biometric information resides.

Identité uses a decentralized architecture in which biometric verification occurs on the user's trusted device.

The user's biometric data does not need to leave that device or reside in a centralized Identité biometric database for matching.

The biometric stays on the user's device.

This reduces the need to create another centralized repository of highly sensitive identity information.

And unlike a password, biometric characteristics cannot simply be replaced if compromised.

Architecture matters.

PasswordFree® for SaaS Environments

Journey visual connecting PasswordFree® for SaaS Environments, NoPass™ for Enterprise AI Deployments, Seven Questions CIOs Should Ask Before Giving an AI Agent Auth, The Identité Perspective: AI Agents Need Zero Trust Too

Identité's PasswordFree® is our SaaS passwordless authentication solution.

PasswordFree® is designed around capabilities including:

For organizations integrating AI agents into SaaS workflows, strong authentication can help establish greater confidence in the humans authorizing sensitive actions.

NoPass™ for Enterprise AI Deployments

For organizations requiring greater infrastructure control and enterprise integration, Identité offers NoPass™, our PaaS solution powered by patented Full Duplex Authentication®.

NoPass™ can be deployed on premises or in the cloud and supports enterprise environments involving:

This deployment flexibility can be particularly important for banks, healthcare organizations, government agencies and highly regulated enterprises.

Banks in particular frequently prefer on-premises deployment because of concerns about placing customer and sensitive information in cloud environments.

NoPass™ provides organizations with the ability to maintain greater control over authentication infrastructure while implementing passwordless and mutual authentication.

Seven Questions CIOs Should Ask Before Giving an AI Agent Authority

The CIO article provides an excellent framework for thinking about AI agent deployment. Based on those lessons, enterprise leaders should be able to answer seven questions before moving an agent into production:

If an organization cannot confidently answer those questions, the agent probably isn't ready for unrestricted autonomy.

The Identité Perspective: AI Agents Need Zero Trust Too

AI agents could become one of the most transformative enterprise technologies since cloud computing.

They may automate enormous portions of routine work, accelerate decision making and allow organizations to operate at a scale previously impossible.

But autonomy changes the security equation.

The CIO article correctly emphasizes that successful agent deployment requires planning, ownership, trustworthy data, limited access, continuous testing, human oversight and lifecycle management.

We would add another requirement:

Strong identity must sit underneath agent authority.

Before an agent receives authority:

Who authorized it?

Before its permissions change:

Who approved the change?

Before it accesses sensitive information:

Is that access appropriate?

Before a high-risk transaction executes:

Does a human need to authorize it?

When human authorization is required:

Is this really the authorized person?

And before that person approves the request:

Is the request coming from the legitimate destination?

With Identité, the biometric can help establish:

"I am the authorized user."

The trusted device participates in establishing:

"This is the authorized device."

Contextual authentication can ask:

"Did I request this authentication session?"

The image and three-digit number provide additional context.

And patented Full Duplex Authentication® addresses:

"Is this the legitimate destination?"

Combine those controls with least privilege, agent identities, behavioral monitoring, human approval thresholds, kill switches and continuous governance, and organizations can build a much stronger foundation for agentic AI.

The goal should not be to prevent AI agents from acting autonomously.

The goal should be to ensure that autonomy exists inside clearly defined boundaries of identity, authority and accountability.

Because the most important question about an AI agent isn't:

"What can it do?"

It is:

"What should it be allowed to do, who gave it that authority, and how do we prove it?"