Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 5 › IT News › Security

AI Agents Keep Access to Company Data After Their Work Is Done

Help Net Security, Friday, October 2nd, 2026

Survey finds most firms have AI data-access policies but few can enforce them in real time or trace agent access to an approver.

Nearly all IT and security leaders surveyed say they have formal policies governing what data AI tools and agents may access, yet organizations reported or suspected agents accessing sensitive data beyond their task.

Only about half check AI access against policy in real time, fewer than one in five detected the latest out-of-scope access, detection often took a day or more, and only 36% could always trace an AI access event to the person who authorized it.

CI/CD pipelines and Kubernetes showed the weakest enforcement, and terminating agent sessions lagged credential revocation.

more →  ·  More from Security →