Skip to main content
All posts

Agentic Security3 min readUpdated September 29, 2026

Every AI agent needs an identity and an access review.

An agent can use credentials, call tools, and move data. Security teams need to know what it can access, which actions are controlled, and what evidence remains.

Security and compliance leaders reviewing identity audit materials in a conference room.

An AI agent can use credentials, call tools, and move data. That makes it an identity and access question for the security team: what can the agent reach, which actions are controlled, and what record remains afterward?

In March 2026, Bessemer described agent security as a major CISO challenge and cited a useful principle: every AI agent is an identity. It may authenticate, receive permissions, call tools, and move data. Those permissions need an owner and a review process, just as service accounts do.

Three questions for security teams

An agent identity raises three questions, in this order.

  1. Step 01Which agents are running, and what can each one access? Record their owners, credentials, tools, and permissions.
  2. Step 02Which risky actions can be stopped? Set controls on the interactions and tools that the security team has chosen to protect.
  3. Step 03What evidence remains? Keep a reviewable record of the action, the applicable control, and the outcome.

The same review applies to service accounts. Agents add tools and dependencies that must be included in the access record.

How Hikma addresses those questions

Observe — what is running

Hikma's inventory covers supported API, web automation, MCP, and skill agents. It connects discovery and observed activity to a structured record that security teams can send to a SIEM. Review that record alongside the engineering team's inventory to find gaps.

Control — blocking in real time

For supported protected interactions, runtime controls can detect prompt injection, redact sensitive data, and limit access to tools or endpoints before a request completes.

Govern — proving behaviour

Per-agent policy, runtime records, assessment findings, and assessment-backed HikmaScore™ results connect a control to its outcome. Teams can review the evidence for the paths they have covered.

Why the revised EU timetable still matters

Since this article was first published, the EU has changed the AI Act timetable. Rules for Annex III high-risk AI systems now apply from 2 December 2027. Classification depends on the system's intended use; an agent working near credit, hiring, or another sensitive workflow is not automatically high risk. Teams should assess each use case and build records they can review before the applicable date.

For systems that are classified as high risk, Article 12 requires automatic recording of events over the system's lifetime to support traceability and monitoring. It does not prescribe a full transcript of every agent step. For an agent that calls tools, a practical record should still connect the relevant action, control decision, and outcome so a reviewer can understand what happened.

The shape of the conversation we want to have

Start with three questions: what is running, which actions are blocked, and what can we prove? Hikma connects assessment, runtime controls, and evidence for supported paths so the team can review the result.

When you deploy an AI agent, record its owner, permissions, applicable controls, and available evidence. Then check that the record shows what the agent actually did.

See how HikmaAI finds risk, enforces protection and produces evidence on a representative production flow.