It is unlikely that your workplace has any formal whole-of-team framework for ‘identity security management’, let alone a framework specific to AI agent identities. This growing gap is revealing a compounding compliance problem that can put real employees at risk.

A large majority of Australian organisations (95%) already use, or plan to use, AI agents to resolve sensitive IT helpdesk tasks, such as password resets and VPN access. Additionally, more than one-third of employees on average have AI installed on their local PCs, where sensitive company data may be reachable to anyone – or anything – that can access it. A data breach can result in entire organisations facing costly downtime, stolen data, financial and reputational damages, and legal consequences.

Unify your organisation’s security strategy

As more AI agents pop up in Australian workplaces, your organisation’s security strategy should factor in both human employees and digital assistants/NHIs.

Regardless of how AI is deployed in workflows, all organisations should be adopting a ‘model of least privilege’ – this is where users are only granted the minimum level of file access required to do their specific jobs.

For example, the marketing team would generally require less access to sensitive company information like financial documents compared with say the accounting team.

To better protect your organisation’s identity environment, you should be asking the below questions about all of your AI agents: