AI agents are being given far broader permissions than they need, Exclaimer security director warns

Exclaimer called on organizations to reinforce their cybersecurity practices as AI reshapes the business communications threat landscape. The security challenge is no longer just whether people are using AI, it is knowing what these tools can access, what agents are allowed to act on and who is accountable for the outcome. Cybersecurity Awareness Month is a reminder for organizations to confront these uncomfortable questions.

Exclaimer’s July 2026 research shows how common AI has become in everyday communication. The nationally representative OnePoll study of 1,000 US adults found that 65% used AI in some aspect of their communications, while 36% had questioned whether a message they received was genuine and 14% did not trust emails from external companies at all. The published findings are available here.

Karl Bagci, Director of IT and Information Security at Exclaimer said this:

“Cybersecurity Awareness Month is a useful reminder that AI is changing the speed of cybersecurity. Attackers can increasingly use automation to move faster than people and traditional defensive processes can respond, which means security teams must work out where they can safely automate detection and response without removing human judgment from decisions that still need context.”

“We can’t just make everything instant; that creates its own risk because an AI system can make the wrong decision, block the wrong thing, or take an action without understanding the wider business context. The challenge for security teams is to get as close as possible to the speed of the attacker while being very deliberate about where a human still needs to be in the loop. Good security automation should remove unnecessary delay, not remove accountability.”

“One of the biggest cybersecurity mistakes organizations can make with AI is to assume that saying no makes the risk disappear. Employees want to use these tools because they help them work faster, and if the business doesn’t give them a safe route, some will use personal accounts, devices, or unapproved services instead. The organization then has less visibility, not less risk.”

“A better approach is to give people approved tools, clear policies around what data can be used, and practical controls that make the safe option the easiest option. The same discipline needs to extend to AI agents. We are already seeing agents given far broader permissions than they need simply because it makes development easier. Cybersecurity Awareness Month should be a prompt to ask not only which AI tools people are using, but what those systems have been allowed to access and what they can do on the organization’s behalf.”

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading