How do we secure AI agents that can take actions in our systems?

Short answer

Secure agentic AI by treating each agent as a privileged identity: give it the least access and fewest tools it needs, treat everything it reads as untrusted input, require human approval for high-impact actions, log every tool call and keep an inventory of approved agents. OWASP's Top 10 for Agentic Applications, published December 2025, ranks agent goal hijack as the first risk.

Why agents change the risk

A chat assistant answers a question and a person decides what to do. An agent acts: it sends email, updates records, calls APIs, moves files or runs code. A mistake, or a manipulated instruction, becomes an action in your systems rather than a bad paragraph on a screen.

The core weakness is that an agent reads its instructions and its working material through the same channel. A document, web page or email it processes can contain text written to redirect it. The 2025 edition of OWASP's Top 10 for LLM Applications ranked prompt injection first and listed excessive agency as a separate risk; the agentic list extends that thinking to systems that plan and act.

The OWASP agentic risks

The OWASP GenAI Security Project's Top 10 for Agentic Applications (version 2026, December 2025) names these risks:

  • ASI01 Agent Goal Hijack and ASI02 Tool Misuse and Exploitation.
  • ASI03 Identity and Privilege Abuse and ASI04 Agentic Supply Chain Vulnerabilities.
  • ASI05 Unexpected Code Execution and ASI06 Memory and Context Poisoning.
  • ASI07 Insecure Inter-Agent Communication and ASI08 Cascading Failures.
  • ASI09 Human-Agent Trust Exploitation and ASI10 Rogue Agents.

Controls that matter most

  • Least agency and least privilege: OWASP recommends per-tool permission profiles, limited data scopes and egress allowlists.
  • Human approval for high-impact or goal-changing actions, such as payments, deletions, external email and permission changes.
  • A separate identity for each agent, never a shared admin account, with credentials you can revoke when the agent is retired.
  • Untrusted-input handling: content the agent retrieves is data, not instructions, and is screened before it can influence planning or tool calls.
  • Sandboxed code execution and logging of every tool call, so you can reconstruct what an agent did and why.

Use the controls your platforms already have

Microsoft says admins choose which agents are allowed in Microsoft Copilot from the Integrated apps section of the Microsoft 365 admin center, users can only access agents the admin allows, and each agent's own privacy statement and terms govern how it handles your data. Microsoft also notes that encryption can exclude programmatic access, limiting what agents can read. OpenAI lists role-based permissions for connected tools and workspace agents in ChatGPT Enterprise.

Neither vendor claims to eliminate prompt injection. Microsoft describes its classifiers as helping to block high-risk prompts and notes they may not be available in every scenario. Design as if some injected instructions will get through.

Govern agents like any other system

Keep an inventory of every agent, its owner, its tools and the data it can reach, and review it on a schedule. NIST's AI Risk Management Framework gives you the governance structure, and NIST AI 600-1, the Generative AI Profile, lists information security and value chain and component integration among its generative AI risks, which covers the third-party tools and models your agents depend on.

Common follow-up questions

Is prompt injection a solved problem?

No. Vendors use filters and classifiers that reduce the risk, and Microsoft notes its protections may not be available in every Copilot scenario. Limit what an agent can do, require approval for high-impact steps and log everything, so a successful injection causes limited harm.

Should an AI agent use an employee's account?

Avoid it. An agent acting under a person's full permissions inherits everything that person can reach. Give each agent its own identity with only the access its task needs, so you can audit, limit and revoke it separately.

Where should a mid-size company start with agent security?

Start with an inventory: which agents, connectors and automations already exist, who owns them and what they can touch. Then restrict which agents users may install, remove unused ones and add human approval to anything that moves money, data or permissions.

Need help with this?

LAN Service Group builds secure agentic systems and reviews existing AI agents for small and mid-size businesses, covering agent identity, least-privilege access, human approval steps, logging and governance.

Talk to LAN Service Group (888) 281-7243

Sources