For many years, when an issue arose in a computer system, investigators could start with a simple question: which account did this happen under? This task becomes more complicated when a single person is no longer behind the account.
AI agents are increasingly being granted permissions to read email, search company files, call other programs, and perform multi-step tasks on behalf of employees or organizations. Even if the credentials are legitimate and the agent is authorized to log in, it becomes surprisingly difficult to accurately determine who authorized what, and where that authority ends.
Zhen Li, co-founder and vice president of the Abu Dhabi-based AI company ANSEN, noted: 'The next major AI security incident may occur when an authorized agent makes an incorrect decision using correct credentials.' He added: 'Traditional cybersecurity asks whether a user, file, or process is malicious. In the age of agentic AI, organizations must also ask: should we allow this AI to perform this specific action?'
This question is beginning to move from a narrow cybersecurity discussion to a broader problem for companies implementing agents. In August, the U.S. National Institute of Standards and Technology (NIST) warned that the early deployment of agents repeated an old security mistake—credential sharing.
People and companies allowed agents to operate through existing user accounts or long-term access tokens because it was a simple way to connect them to email, data, and business applications. The problem lies in accountability. If AI uses an employee's account to open a database, modify a file, and then call another system, logs might simply show that these actions were performed using the employee's credentials. This does not necessarily reveal what actions the person requested, what the agent chose itself, or if any other program was involved in the process.
NIST argues that agents should increasingly be viewed as 'first-class entities' with their own identifiers, credentials, and permissions tied to the person or system that authorized them. Microsoft is moving in the same direction. Its security guidance recommends assigning each agent a dedicated identity, strictly limiting its access, and logging the full chain of actions so the organization can later answer three basic questions: what happened, under whose authority, and what changed.
This distinction sounds technical, but the idea is familiar. A company typically does not give every employee the CEO's login, relying on trust to determine who did what. Different people are given different accounts and permissions. As AI agents begin to work side-by-side with humans, security researchers are increasingly arguing that software should have a similar clear identification trail.
Identification alone is not enough to solve all problems. An agent might have its own account, but it could still be granted too many permissions. For example, it might be allowed to summarize a security alert, but should the same agent also have the ability to disable an account or stop a service without additional verification?
Li believes that the level of control should be determined by the consequence of the action. He stated: 'An AI system may be allowed to automatically summarize an alert, but blocking a critical service, changing security policy, or initiating real-world response must remain regulated.' This is becoming a broader industry issue. Microsoft warns that agents can accumulate broad permissions as their tasks expand, especially when one system is connected simultaneously to email, files, ticketing tools, and company databases. Permissions that seem harmless individually can become significantly more powerful in combination.
The Open Worldwide Application Security Project also presented an Agent Management Standard this month, calling for AI agents to be auditable and traceable, including visibility into what they can access, what they have done, and how their behavior can be constrained while operating.
Thus, the new security model goes beyond the question of whether AI has permission to log in. It also asks what the agent is allowed to do after logging in, how long that permission lasts, and whether its actions can be traced later.
These questions are particularly relevant in the UAE, as agentic AI begins to penetrate government operations. The federal government aims to transition 50 percent of government sectors, services, and operations to agentic AI within two years, including systems designed for autonomous execution and decision-making. In June, over 300 participants from 50 federal agencies began mapping services and operations for potential deployment.
This does not mean that AI systems will gain unlimited power over public services. It means that identification, permissions, and audit trails must increasingly be designed as these systems are widely deployed. Li argues that this should also become part of the UAE's discussion on sovereign AI. He said that control is not complete if an organization cannot see what the AI is doing, restrict access to anything, or intervene before it takes a high-risk action.
The challenge is to maintain the reasons why agents are attractive in the first place. Requiring human approval for every small action would eliminate most of the speed and automation they promise. Allowing the agent to act too freely creates the opposite problem. Li emphasized: 'Human control does not mean a human must manually perform every step. AI handles volume and speed. Humans provide judgment.'
As AI agents become more capable, the question may not be whether they can log in, but whether anyone can answer a very human question after thousands of automated actions: who did what and who is responsible for it happening?
