Instead of just defending the perimeter, or keeping an eye on staff members accessing files they shouldn’t, security leaders now have to govern software that already sits inside their walls. Except these AI agents are armed with valid credentials, direct access to sensitive data and systems, and a mandate to act autonomously and at machine speed.
“A common misconception is that AI agents behave like traditional enterprise software. That they are predictable, deterministic, and broadly aligned with what you intended when you set them up,” says Khetan Gajjar, field chief technology officer: EMEA at Mimecast. “In reality, agents are non‑deterministic, have no moral filter, and are laser‑focused on the goals you give them, not the spirit of your policy. If you don’t tell them not to do something, and if you don’t enforce hard limits, they will simply keep going until they hit a technical or commercial wall.”
The recent Hugging Face incident illustrated the governance gap at the heart of autonomous AI. Gajjar argues that while the agents were pursuing their assigned objective, they did so without sufficiently enforced limits on scope, budget or supervision. While the publicly reported incident points most clearly to failures in containment, access controls and real-time oversight, he says the absence of meaningful spend constraints is an equally important warning sign.
“In the real world, any human team running up a bill would have to stop, slow down, or ask for more budget. The controls that normally contain human actions simply weren’t in place for the software,” he says.
Agents acting as credentialed insiders
Gajjar explains that agents are increasingly working as credentialed insiders in most modern enterprise organisations. Most commonly they execute on behalf of a human, inheriting that person’s identity, permissions, and access to data. In more advanced deployments, however, they are given their own service accounts or API keys and allowed to run workflows end‑to‑end.
“In both cases, they sit on top of core systems, query sensitive information, move files, and trigger downstream actions, but at machine speed. Once set in motion, they don’t get tired, bored, or distracted. They just keep going,” he says.
The problem is that from the network’s point of view, there is often little difference between a disgruntled employee pushing data to an unsanctioned AI tool and an over‑enthusiastic agent over‑querying or exfiltrating data. Both are inside the fence, both are using approved channels, and both can do real damage.
So why isn’t this being tackled properly?
Gajjar believes there are three key problems still tripping up many security leaders:
- Organisations are still treating AI risk as a linear, human-led problem. They assume banning certain tools or traffic contains the threat. But shadow AI (including unofficial agents, scripts and workflows) can bypass these controls through browsers, APIs and desktop applications.
- Security efforts often prioritise detection over control. Teams face growing volumes of AI-related alerts, but lack the ability to automatically distinguish sanctioned from unsanctioned activity, attribute actions to a specific user or agent, and intervene in real time.
- High-level AI principles are rarely translated into enforceable rules embedded in agent workflows. This leaves agents operating largely on trust, with meaningful controls limited to manual reviews or, worse, investigations after a breach.
The four-pillar agent-insider mitigation plan
According to Gajjar, mitigation of the AI agent insider challenge must begin by asking three questions: where did this data come from, where is it going, and who or what is moving it? Adding that visibility must extend across browsers, desktop applications, managed AI platforms, and APIs, and it must apply equally to sanctioned and shadow AI.
Second, organisations need hard budget controls. Agents should never run with an unlimited token or spend allowance. When that budget is exhausted, the agent stops, slows down, or requires explicit human authorisation to continue.
The third pillar is robust logging and audit. Gajjar says every significant agent action should be recorded in a way that allows security teams to reconstruct incidents including which agent ran, on whose behalf, what data it accessed, which systems it touched, and when any controls intervened.
Finally, these elements need to be tied together through an AI rulebook. This must evaluate each agent request in context. For example: this type of agent, acting for this user, may access these systems, work with these classes of data, within this budget, and may not send that data to those destinations. When an action falls outside the rules, the system doesn’t only raise an alert, it blocks, throttles, or introduces the need for a human approval, and writes that decision to the audit trail.
“Security leaders have to treat agents with the same seriousness they do human insiders. Visibility, budgeted autonomy, enforced rules, and deep auditing will help organisations harness their power safely,” Gajjar says, adding that the alternative is a rogue insider and a liability claim that could permanently shut down the company.