AI & Technology

AI Agents Are Creating a New Category of Insider Risk

Xalient calls for a shift from software governance to workforce-style oversight as autonomous systems gain identity, context and delegated authority.

As organisations move from generative AI experiments to autonomous systems that can access data, invoke tools and act on behalf of the business, a more fundamental governance question is emerging: should AI agents still be managed as software, or as a new class of enterprise actor? 

David (DJ) Morimanno, Field CTO at Xalient, argues that the traditional software model is becoming insufficient. Once an agent has an identity, a defined role, access to enterprise systems, knowledge of business context and delegated authority, the risk is no longer limited to whether the technology is secure. Leaders must also determine who owns the agent, what decisions it is permitted to make, how its behaviour is supervised and how its authority can be changed or removed. 

“The question is no longer simply what AI can do. It is what authority we are delegating, to whom, within what boundaries and under whose supervision.” 

David (DJ) Morimanno, Field CTO, Xalient 

Why the software model is reaching its limit 

Traditional software is generally designed to execute defined logic. Agentic systems are increasingly asked to achieve an outcome. In doing so, an agent may select tools, draw on enterprise context, interact with other systems and make bounded decisions. The distinction matters because an authenticated agent can still take an inappropriate action while operating with valid credentials and approved access. 

This changes the security conversation. Identity and access controls remain essential, but they do not answer every question created by delegated authority. An organisation may know that an agent is authenticated without knowing whether the agent is still acting within its original purpose, whether its role has expanded, or whether connected tools and data have changed its risk profile. 

The insider-risk comparison 

The argument is not that AI agents possess human intent or that every agent is malicious. The comparison is operational. Insider risk becomes significant when access, context, authority and organisational trust are combined. Agentic systems are increasingly being given that same combination, often at machine speed and across multiple environments. 

A harmful outcome may therefore arise without a malicious actor. An agent can be misconfigured, compromised, given ambiguous instructions, connected to an unsuitable tool or allowed to retain authority after its original purpose has changed. In each case, the weakness is not only technical. It is a gap in ownership, supervision and lifecycle governance. 

From machine identity to agentic identity 

Many organisations already manage non-human identities such as service accounts, APIs, certificates and workloads. Agentic identity introduces an additional layer because an agent is not merely using a credential to complete a fixed task. It may be interpreting context and deciding how to act within delegated boundaries. 

That means governance must extend beyond credential security. Leaders need visibility of the agent’s purpose, accountable business and technical owners, approved data and tools, decision limits, escalation rules and a reliable route to intervene or suspend activity. 

The leadership question 

If an AI agent is performing business-critical work, who owns it, supervises it and can stop it? 

What AI workforce governance looks like 

Xalient’s proposed approach applies familiar workforce disciplines to digital actors without suggesting that agents are people. The principle is that delegated authority requires explicit accountability. A practical model should cover: 

CONTROL  WHY IT MATTERS 
Discover the AI workforce  Maintain an inventory of agents, copilots and autonomous workflows, including where they operate and which systems they can reach. 
Assign accountable ownership  Give each agent a business sponsor, a technical owner and a clear route for decisions and escalation. 
Define role and purpose  Document the outcome the agent is expected to achieve, the data and tools it may use, and the decisions it may make. 
Govern identity and authority  Apply least privilege, time-bound access where appropriate, and reviews when an agent’s tools, model, data or purpose change. 
Supervise at runtime  Monitor behaviour, policy compliance, exceptions and authority drift rather than relying only on periodic access reviews. 
Control the full lifecycle  Provide a governed process for approval, changes in scope, suspension, retirement and removal of access. 

A leadership and operating-model issue 

Responsibility for agentic AI cannot sit with one function alone. Business leaders define the purpose and acceptable outcomes. Technology teams manage architecture and integration. Identity and security teams govern access and monitor risk. Legal, privacy and risk functions help set boundaries. For the model to work, those responsibilities must connect around named ownership and shared evidence. 

The shift also changes the questions boards and executive teams should ask. Instead of focusing only on which AI tools have been approved, leaders should ask which agents can take action, what authority has been delegated, how exceptions are detected and who can intervene when behaviour moves outside the intended boundaries. 

“AI workforce governance is not about pretending agents are human. It is about recognising that systems capable of acting on behalf of the business need defined roles, accountable owners, supervision and a controlled end to their access.” 

David (DJ) Morimanno 

Where the book fits 

Morimanno develops this argument in his book, HR for AI: Why Agentic Systems Are the New Insider Threat. The book provides the wider context for the governance model, but the central issue extends beyond the publication itself: enterprises are creating digital actors with meaningful authority, and their operating models need to catch up. 

Questions organisations should ask now 

  • Do we know which AI agents and autonomous workflows are operating across the organisation? 
  • Does every agent have a documented purpose and named business and technical owner? 
  • Can we see which identities, systems, data and tools each agent can use? 
  • Do we review authority when an agent’s model, tools, data sources or role change? 
  • Can we detect behaviour or privilege drift while the agent is operating? 
  • Can we suspend an agent and remove its access reliably when its purpose ends? 

Organisations do not need to resolve every element before adopting agentic AI. They do need to make ownership, authority and intervention explicit before experimentation becomes an unmanaged digital workforce. 

About David (DJ) Morimanno 

David (DJ) Morimanno is Field CTO at Xalient and a cybersecurity, identity and AI governance leader focused on the intersection of digital identity, workforce transformation and enterprise trust. His work examines how organisations can govern increasingly autonomous systems through identity, accountability, supervision and lifecycle management. 

With more than 20 years of experience, DJ advises organisations on identity governance, privileged access, access management, machine identities, cloud entitlements, identity threat detection and response, Zero Trust and emerging AI governance challenges. 

About HR for AI 

HR for AI: Why Agentic Systems Are the New Insider Threat explores why autonomous AI agents require more than conventional software and access controls. It sets out a workforce-style operating model covering role and purpose, risk approval, identity and access governance, behavioural boundaries, ownership, runtime monitoring, changes in authority, suspension and retirement. 

About Xalient 

Xalient is a global, independent specialist in identity, cybersecurity and networking solutions. It provides advisory, professional and managed services that help enterprises stay agile, resilient and secure. 

Related Articles

Back to top button