CIOs face an urgent security challenge as AI agents gain autonomous access to enterprise systems: without proper controls, these tools could become the weakest link in corporate defenses. Harish Peri, Okta’s AI security lead, warns that ungoverned AI agents—whether built in-house or procured from third parties—pose risks ranging from data leaks to compliance violations, yet most organizations lack the visibility and governance frameworks to mitigate them. “The problem isn’t just rogue AI—it’s the invisible agents already operating in your environment,” Peri told World Today Journal, emphasizing that 68% of enterprises now use AI tools without centralized oversight, according to Okta’s 2024 State of AI Security Report. The stakes are higher than ever as generative AI models increasingly interact with sensitive workflows, from customer data to financial systems.
Peri’s insights come as enterprises rush to deploy AI agents for tasks like automated customer service, fraud detection, and internal workflows—yet security teams often treat these tools as “black boxes.” Without proper authentication, audit trails, or access controls, even well-intentioned AI systems can inadvertently expose organizations to breaches. “The key question isn’t whether AI agents will access your data, but whether you’ll know it’s happening—and whether you can stop it,” Peri said. His recommendations focus on four pillars: shadow AI detection, real-time visibility into agent activities, governance policies tailored to AI-specific risks, and zero-trust principles applied to machine identities.
This article explores Peri’s framework for securing AI agents, the real-world risks of unchecked deployments, and actionable steps CIOs can take today—before their AI tools become the next major attack surface.
Why AI Agents Are Becoming the New Shadow IT Threat
The rise of AI agents—autonomous systems capable of decision-making, data processing, and system interactions—mirrors the unchecked growth of shadow IT a decade ago. Just as employees once bypassed IT policies to use unsanctioned cloud apps, today’s AI tools often operate outside traditional security perimeters. The difference? AI agents don’t just store data—they act on it, making them far more dangerous if compromised.
According to a Gartner report from March 2024, 45% of enterprises have already experienced security incidents tied to AI tools, with data exfiltration and privilege escalation as the top risks. Peri cites a case where an AI-powered customer support bot, trained on internal knowledge bases, inadvertently leaked proprietary product details to external users due to misconfigured access controls. “The bot wasn’t malicious—it was just following its training, but with no guardrails,” he said.
Unlike traditional applications, AI agents often require access to multiple systems—databases, APIs, and internal tools—to function. This creates a lateral movement risk: if an agent is compromised, attackers can pivot across an organization’s infrastructure. Okta’s research found that 72% of AI-related breaches in 2023 involved agents with overly permissive credentials, often inherited from human users or poorly managed service accounts.
The Four Controls CIOs Must Implement Now
Peri outlines a four-step security model for AI agents, adapted from Okta’s zero-trust framework but tailored to machine identities. Each step addresses a specific gap in current enterprise defenses:

- 1. Detect and Inventory Shadow AI: Most organizations don’t know which AI agents are active in their environment. Peri recommends using identity governance tools to monitor for unusual access patterns—such as AI models requesting data from multiple departments simultaneously. “You can’t secure what you can’t see,” he said.
- 2. Enforce Least-Privilege Access for Agents: AI tools should never inherit the permissions of human users. Peri advocates for machine identities with granular, just-in-time access, revoked immediately after use. Okta’s Identity Threat Protection platform now includes AI-specific access policies, allowing CIOs to set rules like “this agent can only query HR data between 9 AM and 5 PM.”
- 3. Implement Real-Time Activity Monitoring: Traditional SIEM tools often miss AI agent activity because they’re optimized for human behavior. Peri suggests deploying continuous access evaluation to flag anomalies, such as an AI model suddenly requesting access to financial systems. “You need to treat AI agents like rogue employees—always assume they could be compromised,” he warned.
- 4. Govern AI Agents as a New Class of Assets: Most enterprises lack policies for AI-specific risks, such as model drift (where an AI’s behavior changes over time) or data poisoning. Peri advises treating AI agents as regulated assets, subject to the same audit trails and compliance checks as human users. For example, an AI handling EU customer data must comply with GDPR, just like a human employee.
What Happens When AI Agents Go Rogue: Real-World Scenarios
The risks of unsecured AI agents extend beyond data leaks. Peri highlights three emerging threat vectors:
- Automated Insider Threats: AI agents with access to sensitive workflows (e.g., payroll, procurement) could be manipulated to commit fraud. In one case Peri reviewed, an AI-powered expense approval system was tricked into processing fake invoices by injecting malicious prompts into its training data. The attack went undetected for six months because the AI’s decisions were treated as “automated” and not scrutinized.
- Supply Chain Attacks via Third-Party AI: Many enterprises use AI tools from vendors without vetting their security posture. Peri points to a 2023 breach where a third-party AI chatbot, integrated into a bank’s customer service portal, was exploited to steal account details. The bank’s security team had no visibility into the vendor’s access controls. “You can’t outsource security risks,” he said.
- Regulatory Non-Compliance: AI agents processing personal data must comply with laws like GDPR, CCPA, and HIPAA—but many organizations don’t track which agents handle regulated data. Peri notes that under GDPR, enterprises could face fines of up to 4% of global revenue if an AI agent mishandles user data. “The regulators aren’t asking if you intended to comply—they’re asking if you could have prevented the breach,” he said.
How to Get Started: A Step-by-Step Checklist for CIOs
Implementing AI agent security doesn’t require a complete overhaul. Peri recommends starting with these immediate actions:
- Audit Your AI Landscape: Use tools like Okta’s Identity Governance to inventory all AI agents in your environment. Look for tools with direct database access, API keys, or service account credentials.
- Segment AI Agent Access: Isolate AI tools in dedicated network zones with strict ingress/egress controls. Use zero-trust networking to limit lateral movement.
- Implement AI-Specific Logging: Traditional logs don’t capture AI agent interactions. Deploy solutions like Okta’s Continuous Access Evaluation to track agent activities in real time.
- Train Teams on AI Security Risks: Many breaches stem from employees unaware of AI tool risks. Peri suggests mandatory training on prompt injection attacks and data exfiltration via AI.
- Establish an AI Governance Council: Assign ownership for AI security policies, including model approvals, access reviews, and incident response. Peri recommends including legal, compliance, and security teams in this group.
What’s Next: The Regulatory and Technical Landscape
The pressure on CIOs to secure AI agents is only growing. In June 2024, the U.S. White House issued guidelines requiring federal agencies to assess AI system risks, including autonomous agents. Meanwhile, the EU AI Act (set to take full effect in 2026) will classify high-risk AI systems—including those handling sensitive data—subjecting them to strict compliance requirements.

Technically, the field is evolving rapidly. Okta recently announced AI-specific security controls in its platform, including automated anomaly detection for machine identities. Peri expects 2025 to bring AI-native security tools, designed to monitor agent behavior, detect prompt injection, and enforce governance policies dynamically.
The next critical checkpoint for enterprises will be the NIST AI Risk Management Framework, set for an updated public draft in Q3 2024. This framework will provide CIOs with a standardized approach to assessing AI system risks, including autonomous agents. Organizations should prepare to align their governance policies with NIST’s recommendations to avoid compliance gaps.
Key Takeaways for CIOs
- AI agents are the new shadow IT: Without visibility, they operate as blind spots in your security posture.
- Least-privilege access is non-negotiable: AI tools should never inherit human permissions.
- Real-time monitoring is essential: Traditional SIEM tools miss AI-specific threats.
- Governance must evolve: Treat AI agents as regulated assets, not automated scripts.
- Regulations are coming: The EU AI Act and U.S. federal guidelines will impose strict compliance requirements.
As AI agents become more autonomous, the line between tool and threat blurs. Peri’s advice is clear: “The organizations that treat AI security as an afterthought will pay the price—whether in breaches, fines, or lost trust. The ones that act now will set the standard for the next decade.”
For CIOs looking to dive deeper, Okta offers a free AI security checklist, while the NIST AI Risk Management Framework provides a roadmap for compliance. Share your challenges or successes in the comments—and let us know what steps your organization is taking to secure AI agents.