For years, when something went wrong in a computer system, investigators could start with a simple question: whose account caused it? That becomes more difficult when the person running the account is no longer the only one acting. AI agents are gradually being granted the ability to read emails, search company files, call other applications, and do multi-step activities on behalf of individuals or companies.
The credentials may be real. The agent may be authorised to enter. But if it takes an unexpected action, determining who authorised what and where that authority ended can become very difficult. The next significant AI-security problem might involve an authorised agent making the wrong judgement despite having the proper credentials’, said Zheng Li, co-founder and Group Vise President of Abu Dhabi-based AI business ANSEN.
The issue is evolving from a specialised cybersecurity conversation to a larger challenge for organisations using agents. In August, the US National Institute of Standards and Technology (NIST) cautioned that early agent deployments were repeating a common security mistake: exchanging credentials. People and businesses allowed agents to use existing user accounts or long-term access tokens because it was a simple way to connect them to email, data, and business applications.
Also Read:
FIFA Global Citizen Education Fund will Receive $5 Million From the UAE
In Abu Dhabi, Scammers Con a Man Out of Dhs15,566 with a Fictitious Leasing Agreement
