Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Bonanza for Cell C executives - Jorge Mendes

      Bonanza for Cell C executives

      4 October 2026
      AI spending now dwarfs the railway and dot-com booms

      AI spending now dwarfs the railway and dot-com booms

      4 October 2026
      Meta's smart glasses are officially coming to South Africa - Mark Zuckerberg

      Meta’s smart glasses are officially coming to South Africa

      2 October 2026
      Eskom has a R1.20/kWh offer for bitcoin miners

      Eskom has a R1.20/kWh offer for bitcoin miners

      2 October 2026
      Usaasa consults on universal access as its abolition stalls

      Usaasa consults on universal access as its abolition stalls

      2 October 2026
    • World
      BMW restructuring plan bets on AI and new models

      BMW restructuring plan bets on AI and new models

      1 October 2026
      OpenAI's rogue agent problem keeps getting bigger - Sam Altman

      OpenAI’s rogue agent problem keeps getting bigger

      28 September 2026
      The new battle over the desktop

      The new battle over the desktop

      23 September 2026
      AMD is now worth a trillion dollars - Lisa Su

      AMD is now worth a trillion dollars

      22 September 2026
      Anthropic weighs new model launch to blunt OpenAI's Astra surge - Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman

      Anthropic weighs new model launch to blunt OpenAI’s Astra surge

      21 September 2026
    • In-depth

      10 days that changed the course of AI

      21 September 2026
      Meta to the AI industry: slow down without us - Mark Zuckerberg

      Meta to the AI industry: slow down without us

      16 September 2026
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
    • TCS
      Lexi Novitske, general partner at Norrsken22, on the TechCentral Show

      TCS | Norrsken22’s Lexi Novitske on how China is winning African tech

      1 October 2026
      TCS | Dominic White and Adam Ely on AI agents going rogue

      TCS | Dominic White and Adam Ely on AI agents going rogue

      29 September 2026
      TCS | Octotel's Trevor van Zyl on the fibre merger question

      TCS | Octotel’s Trevor van Zyl on the MetroFibre merger question

      16 September 2026
      Meet the CIO | Shoprite's Chris Shortt on what a supermarket becomes

      Meet the CIO | Shoprite’s Chris Shortt on what a supermarket becomes

      9 September 2026
      Rubicon's EV charging network is profitable - and growing fast - Watts & Wheels

      W&W | Rubicon’s EV charging network is profitable – and growing fast

      8 September 2026
    • Opinion
      South Africa's next energy crisis is in the accounts department - Craig Holmes

      South Africa’s next energy crisis is in the accounts department

      29 September 2026
      The steam engine lesson AI doomsayers keep missing - Sam Clarke

      The steam engine lesson AI doomsayers keep missing

      28 September 2026
      Regulating AI: apply the laws we have first - Dirk de Vos

      Regulating AI: apply the laws we have first

      21 September 2026
      What Revolut can and cannot take from South Africa's banks - Pambos Soteriades

      What Revolut can and cannot take from South Africa’s banks

      15 September 2026
      The end is nigh, and the shares go on sale in October - Duncan McLeod

      The end is nigh, and the shares go on sale in October

      14 September 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM.com
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Publishared
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Your AI agent is a privileged user. Treat it like one

    Your AI agent is a privileged user. Treat it like one

    Promoted | Prompt injection only matters if the agent already holds credentials and enterprise access, writes Simone Santana.
    By Solid8 Technologies14 September 2026
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    Get breaking news on WhatsApp

    Your AI agent is a privileged user. Treat it like one - Simone Santana
    The author, AlgoSec’s Simone Santana

    AI models and autonomous agents have moved out of isolated experiments and into the core of enterprise operations. They are being connected to databases, business applications, cloud platforms, internal application programming interfaces (APIs), software development environments and third-party services.

    That creates real business value. It also creates a security problem: what happens when an AI system has access to more of the organisation than it needs?

    The risk is not that a model produces a wrong answer. It is that an AI application, agent or connected tool could be manipulated, compromised or misconfigured, and then use its access to reach sensitive systems, expose data or trigger actions nobody intended. As AI becomes more capable and more autonomous, businesses need to consider not only what their models can do, but where they can connect.

    AI agents become privileged enterprise applications

    Many companies are running AI services that touch sensitive information and critical infrastructure. These systems retrieve customer records, query financial databases, generate code, start workflows and call external services. In practice, that makes them another class of privileged application.

    Traditional applications arrive with well-defined network requirements, clear ownership and an approval process. AI environments move faster. New models, tools, plugins and integrations appear within days, often without anyone fully mapping the connectivity they require. The result is overly broad access, unrestricted outbound connectivity and unnecessary exposure between AI workloads and sensitive business systems.

    If an AI agent is compromised – through prompt injection, malicious content or a vulnerable third-party integration – that excess connectivity determines how far the damage spreads. The problem is not that the model broke out of the network. It is that it was already granted access to systems it should never have been able to reach.

    Containing risk through connectivity governance

    A secure AI strategy needs connectivity governance: a clear view of every system an AI workload can talk to, including internal applications, databases, cloud services, development platforms and third-party APIs. Each connection should then be tested against a simple question – is it necessary? – and restricted to its intended business purpose.

    That means security and infrastructure teams mapping an AI application’s dependencies, assessing the risk of each proposed connection and enforcing least-privilege access. Rather than letting an AI service reach the internal network and the internet at large, organisations can limit it to the specific applications, services, ports and destinations it needs. If the workload then behaves unexpectedly or is compromised, the damage is contained.

    Protecting connections to third parties

    The danger is not that an AI agent can encounter malicious instructions through a third-party source or plugin. It is that those instructions can reach an agent that has already been given powerful tools, credentials and access to enterprise systems.

    The Open Worldwide Application Security Project (Owasp) lists ‘excessive agency’ as a top risk in applications built on large language models, and traces it to three root causes: unnecessary functionality, unnecessary permissions and unnecessary autonomy.

    Most AI deployments depend on external model providers, software-as-a-service platforms, plugins, data sources and APIs. Those dependencies deliver the capability. They also extend the attack surface.

    Securing the model is not enough. Organisations have to govern what sits around it – its identity, permissions, tools, APIs, applications and network connections. An AI agent should be able to reach only what it needs to do its job, and security teams should be able to see, justify and continuously re-check every one of those connections.

    AI changes how applications work. It does not change the principle of least privilege. It raises the cost of ignoring it.

    • The author, Simone Santana, is regional sales director at AlgoSec, which is represented in South Africa by Solid8 Technologies
    • Read more articles by Solid8 Technologies on TechCentral
    • This promoted content was paid for by the party concerned
    Add TechCentral as a preferred source on GoogleFollow TechCentral on Google NewsGet breaking news on WhatsApp


    OWASP Simone Santana Solid8 Solid8 Technologies
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleMTN opens fifth Women in Digital Business Challenge
    Next Article SA20 launches schools derby series with rain as title sponsor

    Related Posts

    Your AI agent is a privileged user. Treat it like one - Simone Santana

    Solid8 brings AlgoSec Horizon to Southern Africa

    1 September 2026
    NEWORDER brings Lasso's AI agent controls to South Africa - Bennie Barnard

    NEWORDER brings Lasso’s AI agent controls to South Africa

    1 September 2026
    Saviynt launches Zuma, its enterprise AI identity security platform - Solid8 Technologies

    Saviynt launches Zuma, its enterprise AI identity security platform

    26 August 2026
    Add A Comment

    Comments are closed.

    Company News
    Huawei sets out its vision for intelligent government at GovTech 2026

    Huawei sets out its vision for intelligent government at GovTech 2026

    2 October 2026
    A simple guide to modern laptop processors for small businesses - Incredible

    A simple guide to modern laptop processors for small businesses

    2 October 2026
    Cloud and AI won't deliver value on their own, executives warn

    Cloud and AI won’t deliver value on their own, executives warn

    1 October 2026
    Opinion
    South Africa's next energy crisis is in the accounts department - Craig Holmes

    South Africa’s next energy crisis is in the accounts department

    29 September 2026
    The steam engine lesson AI doomsayers keep missing - Sam Clarke

    The steam engine lesson AI doomsayers keep missing

    28 September 2026
    Regulating AI: apply the laws we have first - Dirk de Vos

    Regulating AI: apply the laws we have first

    21 September 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Bonanza for Cell C executives - Jorge Mendes

    Bonanza for Cell C executives

    4 October 2026
    AI spending now dwarfs the railway and dot-com booms

    AI spending now dwarfs the railway and dot-com booms

    4 October 2026
    Meta's smart glasses are officially coming to South Africa - Mark Zuckerberg

    Meta’s smart glasses are officially coming to South Africa

    2 October 2026
    Eskom has a R1.20/kWh offer for bitcoin miners

    Eskom has a R1.20/kWh offer for bitcoin miners

    2 October 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    🇿🇦 Sign up to the TechCentral newsletter