Agentic AI
,
Artificial Intelligence & Machine Learning
,
Governance & Risk Management
HS-ISAC Warns About Weak Governance and Credential Misuse
Marianne Kolbasuk McGee (HealthInfoSec) •
May 27, 2026

Humans delegating data, decisions and more to agentic AI in blended healthcare environments pose a variety of amplified risks, including cyber and patient safety, says a new report. (Image: Getty Images)
Humans make mistakes. They fall for phishing scams and click on malicious links. Machines aren’t necessarily better: Delegating decisions to agentic artificial tools can significantly intensify cybersecurity risks, warns a healthcare association.
See Also: Know Thy Enemy: Threats to Cyber Resilience
Over-permissioned accounts, weak governance and credential misuse – all are amplified by AI-enabled workflows, said Errol Weiss, chief security officer of the Health Information Sharing and Analysis Center. The center published Tuesday advice for managing agentic artificial intelligence risk in healthcare settings.
The stakes aren’t restricted to data security and privacy risks, Weiss said. Patient safety and continuity of care need electronic health records and a functioning clinic. A rogue AI agent can interrupt the normal flow of medical care. “Disruptions to communications can slow care and increase errors,” he said.
Organizations can be slow to perceive the risks of agentic AI. At first, AI use is often informal and unsanctioned. But much as they’ve progressed in raw capacity agents are still prone to wide swings in behavior – as a startup founder discovered earlier this year when an AI agent deleted three months of production data over nine seconds – despite being explicitly instructed to never guess about the consequences of its actions (see: AI Agent Wipes Startup’s Data in 9-Second API Call).
“When AI agents are implemented without strong identity and policy controls, attackers only need one foothold to misuse delegated privileges,” Weiss said.
The center advises organizations to adopt a framework that shifts traditional security awareness training to continuous risk management that encompasses human behavior and agentic AI risk. “The maturity model is clear – you can’t manage what you can’t see,” Weiss said.
That includes treating human and AI-driven behavior as part of the enterprise attack surface and monitoring AI-agent activity such as its access privileges. Risk managers should govern AI agents as if they were “digital workers” with defined ownership, monitoring, logging and approved use cases.
Compliance-based training is better supplanted by risk-based interventions and organizations should build cross-functional governance models that involves security and privacy officials as well as clinical leadership and human resources, the report says.
“CISOs should manage workforce risk continuously and intervene based on observed risky behaviors and exposure, not generic completion metrics,” Weiss said.
It’s not just the responsibility of healthcare CISOs and their teams to address these issues, he said.
“Executives, clinical and operational leadership should treat cyber as patient safety and resilience planning,” he said. Leaders should sponsor downtime planning, ensure clinical managers participate in exercises and reinforce that safe workflows matter as much as technology, he said.
Additionally, HR, compliance, legal and privacy departments should reinforce “ownership” of AI use, not just the rules, Weiss said. “Organizations must shift their culture from simple AI compliance to true AI ownership. Employees shouldn’t just follow rules; they must be accountable for the behavior of the AI systems they deploy.”
Chief information officers, IT managers and data owners should bake guardrails into tools and workflows, he said. “If healthcare adds agentic automation without matching governance and visibility, it can unintentionally make attacks faster, broader and more damaging.”