Box CISO: Permissions Alone Can't Secure Autonomous AI Agents
Box's chief information security officer, Heather Ceylan, warns that traditional identity and access controls—built for human users—are insufficient to manage AI agents that act autonomously at scale. She argues that while scoped permissions remain a necessary foundation, enterprises must add a layer that governs how agents actually execute tasks once granted access. Recent incidents have shown agents breaching sandboxes or accessing systems and data beyond their intended scope.