Permanent access was always a bad idea. AI agents just made it catastrophic.
By Alex Lei - Senior VP APJ at Saviynt
![]() |
| Source: Saviynt. Lei. |
That model was already showing its age before AI entered the picture. Now, AI agents have made it untenable.
Unlike human employees who log in, complete tasks, and sign out, AI agents operate continuously, autonomously, and at scale. They do not simply access data, they traverse it, reason over it, and act on it across multiple systems simultaneously.
An agent with permanent permission to read and change data across an organisation’s core business systems and its cloud storage is no longer just another user. It is a permanent attack surface, a way in that never clocks out.
“Ghost” administrators
AI agents are no longer experimental technologies confined to innovation teams. According to PwC, 17% of Singapore organisations are already deploying AI autonomously – more than double the global average. Yet only 53% report having robust security controls in place to support that adoption.
At the same time, the Cyber Security Agency of Singapore (CSA) has warned that AI is collapsing the time attackers need to run a newly-discovered software flaw into a working attack from months down to hours. Its recommended fixes point in the same direction: apply least privilege to service accounts and the connections between systems, retire dormant accounts and unused service accounts. Those are not generic hygiene tips; they are what it takes to bring non-human identities under control.
This is often framed as an AI security challenge. In reality, it is an identity security challenge. Identity security exists to govern every identity according to the risk it carries. It is difficult to imagine a higher- risk identity than one that operates continuously, cannot be checked through the human sign-in steps we rely on - such as multifactor authentication, relies on credentials that rarely expire, and operates largely out-of-sight of traditional IT oversight.
Many AI agents already possess access privileges comparable to senior administrators. Yet unlike human administrators, they are frequently deployed without the same safeguards, oversight, or governance requirements. The result is a growing population of "ghost administrators" or non-human identities with extensive reach and very limited accountability.
Visibility isn't everything
Many organisations are making progress in identifying AI-related identities across their environments. Far fewer are prepared to contain one if it becomes compromised.
The purpose of identity security was never simply to provide visibility into privileged accounts. Its purpose is to eliminate standing privilege, enforce access controls, and contain the damage when something goes wrong.
Knowing where AI agents exist is useful. Knowing how to immediately restrict, revoke, or isolate their access is significantly more important.
The challenge is that many incident response models remain designed around human-speed events. Security teams assume there will be time to investigate, escalate, and coordinate responses.
A compromised AI agent operates at machine speed. By the time a traditional response process begins, sensitive data may already have been accessed, copied or modified across multiple environments.
Why parity matters
IDC finds that just 7% of enterprises in the Asia Pacific have the governance and compliance skills they will need to meet emerging AI rules. At the same time, AI identities are becoming the fastest-growing and least-governed identity category in the enterprise.
This creates a dangerous inconsistency. Mature identity security programmes are built on the principle that high-risk identities should be governed consistently, regardless of whether they belong to a person, service account, or application. Human administrators are subject to strict controls, approval workflows, and monitoring because their access presents risk.
AI agents escalate the same risk, yet many organisations continue to treat them differently. Operational parity matters. If privileged human users are required to justify access, use multifactor authentication and operate under strict governance controls, autonomous agents should not receive exemptions simply because they are software.
The end of “always-on” access
Least privilege remains an important principle but granting it once and leaving it in place is no longer enough.
For autonomous, non-human actors operating at machine speed, even minimal persistent access introduces significant risk. Any standing privilege creates an opportunity for misuse, compromise, or unintended behaviour.
The goal must be to remove standing access altogether; an approach the industry calls Zero Standing Privilege. It is least privilege taken to its logical conclusion: access is granted only at the moment it is needed, the credentials that comes with it expire on their own, and every request is judged on its context at the time it is made. Access becomes temporary and continuously verified rather than permanently assigned.
Achieving this requires bringing privileged access controls and broader identity governance under one approach. Together, they provide the mechanisms needed to govern every identity consistently, whether human, machine, or autonomous agent.
The closing window
Identity security was built for a world where high-risk identities had human faces. That world no longer exists.
AI agents are rapidly becoming some of the most privileged and least-governed identities in enterprise environments. They move faster than human users, operate continuously, and possess the ability to interact with multiple systems simultaneously.
The challenge facing organisations is not whether identity governance will eventually catch up, but whether it does so before a security incident forces the issue. In the age of autonomous AI, standing privilege is no longer merely inefficient. It is increasingly indefensible.

Comments
Post a Comment