{"id":122345,"date":"2026-07-29T04:54:10","date_gmt":"2026-07-29T04:54:10","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/122345\/"},"modified":"2026-07-29T04:54:10","modified_gmt":"2026-07-29T04:54:10","slug":"your-ai-agents-can-reach-data-no-one-approved","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/122345\/","title":{"rendered":"Your AI agents can reach data no one approved"},"content":{"rendered":"<p>A credential expired. An AI agent kept using it anyway, and a mid-sized company\u2019s systems went down for a quarter\u2019s worth of trouble before anyone traced the failure back to a non-human account no one had been logging.<\/p>\n<p>That agent could reach customer records, source code, and HR files the whole time. The tools that track who touches sensitive data were built for employees, and they lose the thread once a semiautonomous account starts opening doors on its own. The exposure lands on the company whose data the agent can reach.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/ai-drown.webp\" class=\"aligncenter\" alt=\"AI agent governance\" title=\"AI\"\/><\/p>\n<p><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/02\/12\/1password-security-comprehension-awareness-measure-scam-ai-benchmark\/\" rel=\"nofollow noopener\" target=\"_blank\">1Password<\/a> surveyed 1,000 security and engineering staff at large U.S. firms in late May and early June 2026. 46% of the developers run AI agents in production right now.<\/p>\n<p>Agents are reaching data outside their approval<\/p>\n<p>Agents at these companies can get to material that carries legal and competitive weight. 71% of respondents said their agents can reach sensitive information.<\/p>\n<p>Access maps loosely to approval. At about four in ten organizations, agents reach data outside their approval. Across the survey, agents touched roughly twice as much data as anyone had signed off on. One person who runs IT operations at a mid-sized company knows the feeling firsthand.<\/p>\n<p>\u201cWe had an AI agent pull data from the wrong system due to overly broad access permissions, which caused some inaccurate reporting that took us a while to track back to the source.\u201d<\/p>\n<p>Credentials that stay live too long<\/p>\n<p>The credentials behind that access tend to linger. 40% of developers grant agents persistent access to systems and secrets, so the access stays live after the task ends. Add stale credentials to thin logging and a failure becomes hard to trace. A senior network administrator at a mid-sized company lived through exactly that.<\/p>\n<p>\u201cWe had a major system outage last quarter because an AI agent was using an expired credential and nobody knew about it until things broke. Tracking it down took forever because our audit trails for non-human accounts are basically nonexistent right now, it was a mess.\u201d<\/p>\n<p>The habits feeding agents come from how developers handle their own secrets. About a quarter hardcode credentials into scripts or config files. Best practices for secrets management run slow, and companies want engineers shipping code on a tight clock. <a href=\"https:\/\/www.linkedin.com\/in\/jason-meller-04498230\/\" target=\"_blank\" rel=\"nofollow noopener\">Jason Meller<\/a>, VP of Product at 1Password, has watched this standoff play out for two decades.<\/p>\n<p>\u201cSecurity tools have spent twenty years asking people to slow down, and people have spent twenty years saying no. The lesson here isn\u2019t that developers need more training. It\u2019s that the secure thing has to become the easy thing, or it won\u2019t happen at all.\u201d<\/p>\n<p>Untrusted content is steering agents<\/p>\n<p>Untrusted content can hijack an agent mid-task. 47% of developers have had an agent take an unintended action after following instructions buried in a webpage, document, email, or tool output.<\/p>\n<p>\u201cThis result is alarming, but it also tracks with our own independent research,\u201d says Meller. \u201cOur testing found that models are near-perfect at recognizing phishing, but recognition doesn\u2019t make an agent stop in the middle of a task. Often the agent isn\u2019t even being tricked into disobeying instructions, it\u2019s just faithfully following a request that leads somewhere dangerous.\u201d<\/p>\n<p>The damage shows up in incident logs. Among developers who use agents, 33% said their company had a breach or security incident tied to overprivileged non-human identities. Close to three-quarters of developers reported some unintended consequence from agents, from inaccurate outputs to data leaks.<\/p>\n<p>No one agrees who is responsible<\/p>\n<p>Nobody agrees who answers for an agent\u2019s actions. The survey asked who is held accountable when an agent causes harm, and the answers scattered across the org chart. 65% said a different person should carry the responsibility. Meller skips past the biggest numbers and lands on a small one.<\/p>\n<p>\u201cThe number that gets me isn\u2019t the 24% or the 19%. It\u2019s the 5% who say the agent itself is accountable. An agent can\u2019t be fired or sued. That answer means the conversation hasn\u2019t happened yet,\u201d he told Help Net Security.<\/p>\n<p>Ask Meller where it belongs.<\/p>\n<p>\u201cAccountability should actually sit with whoever authorized the agent\u2019s access. The person who decided this agent gets access to this system bears the responsibility for what it does with that access, regardless of who was typing the prompts. That framing is uncomfortable because it means access grants carry real moral weight. You can\u2019t hand an agent the keys and then shrug when it drives somewhere you didn\u2019t intend.\u201d<\/p>\n<p>1Password is building a credential broker that ties each credential issuance to a specific agent identity and to the person who authorized it.<\/p>\n<p>Capability gains keep reopening the gap<\/p>\n<p>Meller sees the sequence repeating with each capability jump. New abilities open fresh paths to systems no one flagged as a risk. Governance tends to arrive after the incident. He offers one marker for progress.<\/p>\n<p>\u201cThe first sign to watch for is whether anyone consults security before deploying agents. Right now the pattern is deployment first, governance retrofit, incident, actual policy. When security is in the room during the scoping conversation rather than in the postmortem, that\u2019s when organizations have turned a corner.\u201d<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/divider.gif\" class=\"aligncenter\"\/><\/p>\n<p>Download: <a href=\"https:\/\/helpnet.short.gy\/7EcjJ3\" target=\"_blank\" rel=\"nofollow noopener\">The ultimate guide to network operations management<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"A credential expired. An AI agent kept using it anyway, and a mid-sized company\u2019s systems went down for&hellip;\n","protected":false},"author":2,"featured_media":71368,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[27679,179,24,405,7537,313,30,1163],"class_list":["post-122345","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-1password","tag-agentic-ai","tag-ai","tag-ai-agents","tag-artificial-intelligence-agents","tag-cybersecurity","tag-report","tag-survey"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122345","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=122345"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122345\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/71368"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=122345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=122345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=122345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}