Agentic AI: how can risks be managed before deployment?
By acting autonomously, agentic AI creates new business opportunities, while raising significant security concerns.
Agentic AI is gaining ground in Canadian businesses. According to a study by SAP Canada and Oxford Economics published in September 2026, 66% of the organizations surveyed are already using this technology. However, 70% of the executives surveyed acknowledge – or cannot rule out – that the roll-out of AI agents is outpacing governance.
What is agentic AI? Unlike generative AI, which responds to prompts by producing content or making recommendations, agentic AI can interpret an objective, make decisions and carry out certain actions without constant human intervention.
The challenge is not to curb its use, but to determine how much autonomy to grant and under what conditions.
Why is agentic AI changing risk management?
An AI agent can connect to your email system, databases, cloud applications or other internal systems. It can then access files, transfer information or trigger certain actions independently.
This autonomy accounts for much of its value, but it can also have unforeseen consequences. An agent may, in fact, seek to achieve its goal by taking a course of action that the organization had neither planned nor authorized. Recent incidents have shown that certain models can bypass instructions, circumvent access authorization or exploit vulnerabilities to achieve the objective assigned to them. In some cases, agents tested on fictitious targets even accessed real organizations’ systems without authorization.
Risk depends not only on an agent’s intended role, but also on its technical capabilities. The more access it has to sensitive systems or data, the greater the potential impact of an incident.
How can the risks of agentic AI be assessed?
Before any deployment, assess the risks specific to the intended use against your organization’s risk tolerance. An agent carrying out a low-risk task does not present the same challenges as one capable of accessing financial information, modifying data or interacting with critical systems.
The assessment must take into account:
- the degree of autonomy granted to the agent;
- the sensitivity of the data and systems to which it is connected;
- the nature of the operations it can perform;
- the potential consequences of errors, unexpected behaviour or malicious use.
Which controls help secure AI agents?
After assessing the risks, implement appropriate safeguards, particularly in terms of identity and access management. To carry out their tasks, some agents are granted broad permissions within the IT environment. However, traditional identity and access management mechanisms were originally designed for human users. As a result, agents may operate without a clearly defined identity and be granted more privileges than necessary.
For example, a malicious command hidden within a document can alter the behaviour of the agent accessing it, while a stolen authentication token or API key can let an attacker impersonate the agent.
Securing an agent therefore relies on several complementary mechanisms:
- Applying the principle of least privilege by limiting permissions to only those resources essential to the agent’s task;
- Keeping a human in the loop for operations likely to have a major impact on data confidentiality, integrity or availability;
- Logging the agent’s activity to track the files accessed, commands executed and operations carried out;
- Establishing a revocation mechanism to quickly withdraw the agent’s permissions or capabilities.
The aim is not to supervise every task, which would undermine the agent’s value, but to identify where human intervention is essential.
Why is governance essential for agentic AI?
Technological controls are important, but insufficient. They must form part of a governance framework that clearly defines acceptable use. Which tools can be used? For which tasks? Who can deploy an agent? Which actions require approval? Who is accountable?
These rules must also set out the procedure to follow when new uses are being considered. Users, for their part, remain accountable for the tasks assigned to these technologies, even when they are carried out autonomously.
Governance must be defined right from the design stage. Setting limits only after an agent enters production means trying to regain control after it already has the tools to act.
Are you ready to intervene if an agent goes beyond its mandate?
Even with robust preventive measures, there is no such thing as zero risk. Your incident response plan must therefore address the specific characteristics of agentic AI.
Running through different scenarios allows you to verify that your organization will be able to detect abnormal behaviour and respond if an agent exceeds its mandated scope. These exercises also clarify responsibilities and validate response procedures before a real incident can occur.
Are you deploying, or planning to deploy, AI agents? Contact our experts!