AI agents are quickly moving beyond answering questions.
They can access enterprise data, call APIs, trigger workflows, update records and even interact with other agents.
That creates an important architectural shift:
An AI agent is no longer just an application using an LLM. It is becoming an identity inside the enterprise.
Microsoft’s 2026 Digital Defense Report highlights the growing security challenge around agentic AI.
For architects, the question is no longer only:
What data can the AI see?
We also need to ask:
What is this agent allowed to do?
From Chatbot to Digital Actor
A traditional GenAI application is relatively straightforward:
User → AI Model → Response
An enterprise agent is different:
User → AI Agent → Tools / APIs → Applications → Enterprise Data
The agent may authenticate to systems, retrieve information and perform actions — sometimes without the user approving every individual step.
That means we need answers to some familiar security questions:
- Who is this agent?
- What permissions does it have?
- Which tools can it use?
- Which data can it access?
- Can we immediately revoke its access?
These are fundamentally identity and access management questions.
Zero Trust Needs to Include AI Agents
The familiar Zero Trust principles still apply:
Verify explicitly. Use least privilege. Assume breach.
But now they need to extend to AI agents.
A simplified enterprise architecture could look like this:
Around this flow, we need:
Monitoring • Audit • Data Protection • Threat Detection • Revocation
The principle is simple:
An agent shouldn’t automatically receive broad permissions simply because the person using it has them.
Least Privilege Matters Even More
Imagine an HR agent designed to check leave balances and submit leave requests.
It doesn’t need permission to modify salaries or export the entire employee database.
But if the agent operates through an overly privileged service account, its technical capabilities could be much broader than its intended business purpose.
Avoid:
Agent → Powerful Service Account → Everything
Prefer:
Agent → Approved Tools → Specific Operations
For higher-risk actions — deleting resources, changing security policies, financial transactions or bulk data exports — an additional policy check or human approval may also be appropriate.
Tools Become Part of the Attack Surface
Tools are what make agents powerful.
An enterprise agent might connect to:
Microsoft Graph • SQL • SharePoint • SAP • Azure • ServiceNow • Internal APIs • MCP Servers
But every additional tool also increases the potential blast radius.
This is why prompt injection is only one part of AI security.
Even a perfectly functioning model can become dangerous if the identity behind it has excessive permissions.
AI security therefore isn’t just about securing the model.
It’s about securing:
Identity + Permissions + Tools + Data + Actions
Agent-to-Agent Changes the Trust Model
Now imagine:
User → HR Agent → Payroll Agent → ERP
We now have multiple machine identities communicating with each other.
Which agent initiated the request? Which agent delegated it? What permissions travelled with the request? Which system ultimately executed the action?
Agent-to-agent architectures therefore need many of the controls we’ve already learned to apply to APIs and workloads:
Authentication • Authorization • Least Privilege • Auditability • Revocation
Zero Trust increasingly needs to cover not only user-to-application, but also agent-to-agent communication.
The Architect’s Perspective
There is currently a lot of attention on:
Which model should we use?
How large is the context window?
What is the latency?
How much do the tokens cost?
Those questions matter.
But as enterprise agents become capable of taking actions, another question becomes more important:
What are we allowing this agent to do?
We spent years learning how to secure users.
Then applications.
Then service principals and workload identities.
AI agents are the next identity we need to secure.
Once an agent can authenticate, access enterprise data, call tools and perform actions, it isn’t merely something employees talk to.
It has become part of the enterprise security boundary.
Further Reading
Microsoft’s 2026 Digital Defense Report provides additional context on the evolving security landscape, including the security considerations emerging around AI and autonomous agents.

