AI Agents Operate with Privileged Access but Little Identity Oversight, Auditor Warns
An IT audit leader argues that enterprises are granting autonomous AI agents broad production access via long-lived service accounts, API tokens, and delegated cloud permissions, while focusing security spending on human-user authentication like MFA. These agents can execute code, provision resources, and modify records, effectively acting as privileged users outside traditional interactive access controls.