AI Agents Need Identity, Access Controls and Continuous Oversight
Cognizant's cybersecurity chief explains why autonomous systems require fundamentally different security architectures than traditional software.
Autonomous AI agents are forcing a fundamental rethink of enterprise cybersecurity. Unlike traditional applications that operate within predefined rules, agents can interpret information, make decisions and take action across connected systems with minimal human intervention—creating risks that conventional security controls were never designed to address.
Vishal Salvi, Global Head of Cybersecurity Service Line at Cognizant, argues that three decades in cybersecurity have given him perspective on threats, but "the last six months of AI advancement has changed the threat landscape in ways the last decade did not."
The core challenge: when an agent fails or is compromised, the impact extends far beyond a single system. An agent can disrupt business processes, trigger unintended actions in connected platforms, or make confidently wrong decisions at scale. Models, prompts, data pipelines and tool integrations now represent live attack surfaces inside every enterprise, Salvi told Cyber Magazine.
Why it matters
As organizations deploy autonomous agents to handle everything from customer service to payment approvals, the traditional perimeter-based security model breaks down. Agents that can access enterprise context—internal documents, customer records, operational procedures—become both powerful business tools and significant vulnerabilities. Without proper controls, a compromised agent doesn't just leak data; it makes harmful decisions with real financial and operational consequences.
Identity and access as first-line defense
Salvi emphasizes that every agent must have a verifiable identity and access only to the specific data, systems and tools required for its designated role. "The more an agent can see and do, the greater the potential impact if it is compromised," he explains.
This means treating context itself as a security asset. Organizations need controls covering both the information agents can access and the actions they can take, with access levels reflecting risk. An AI assistant answering employee questions shouldn't have the same permissions as one authorized to approve financial transactions.
Real-time monitoring replaces periodic reviews
Continuous governance becomes essential when agents learn, adapt and act in real time. Static, point-in-time security controls designed for predictable software cannot keep pace with systems that interpret new information and behave differently over time.
Salvi advocates for unified security signals, identity systems and policies enforced through a single control plane, combined with audit-ready evidence of agent behavior. Some organizations are exploring guardian agents that monitor other AI systems and flag deviations—governance itself becoming autonomous to match the pace of the systems being overseen.
Cognizant has built continuous checks into its own governance model, Cognizant Trust, which tracks AI systems in use, monitors compliance, records incidents and provides leadership visibility. The company recently earned ISO 42001 certification for this approach.
Accountability remains human
Despite increased autonomy, responsibility for agent actions must remain with the people and organizations deploying them. Salvi stresses that giving an AI agent greater autonomy should never mean surrendering human accountability.
This requires anticipating what could go wrong, defining where human intervention is mandatory, and establishing clear ownership and escalation paths—particularly where operational, financial or regulatory risks are significant. The CISO role is evolving to manage AI trust continuously through governance backed by traceability, auditability and explainability.
Three essential controls
For CISOs deploying autonomous AI today, Salvi recommends three immediate priorities: control identity and access with verifiable agent identities; build real-time oversight with the ability to contain unexpected behavior; and protect the context agents rely on, ensuring information feeding agents is trusted and appropriate.
Underpinning all three: securing AI and governing it responsibly are not separate programs. Organizations that unify these efforts will define trust in the coming decade.
These details were first reported by Cyber Magazine in an interview with Salvi.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call