Originally Published: 1 Oct 2026

AI Agents Are Changing the Access-Control Question
AI agents are moving beyond simple chat interfaces. They can increasingly act inside browsers, SaaS platforms and business applications, sometimes using the same permissions as the users they support.
That raises a practical question:
who decides what an approved AI tool or agent is allowed to access?
Recent guidance from ENISA and Traficom has already raised concerns about increasingly autonomous AI agents, excessive permissions and new attack surfaces. Real-world incidents have made those risks much harder to treat as theoretical.
From AI Governance to Practical Access Control
AI governance can define which tools are approved and how they should be used. But organizations still need to decide what those tools are actually allowed to reach.
The challenge is not always unauthorized AI. An approved AI tool can still have broader access than intended.
This becomes especially important when agents operate with existing user permissions and can interact with sensitive files, applications and workflows.
What You’ll Learn
In this webinar, you’ll learn:
- How Shadow AI, autonomous agents and excessive permissions can expose sensitive data
- Why approving an AI tool is not the same as controlling what it can access
- What recent incidents tell us about autonomy, credentials and access
- Where existing controls fit – and the question none of them were designed to answer
- A practical framework for setting boundaries around sensitive files and applications
Who Should Watch
This webinar is designed for professionals responsible for AI governance, data protection and access control, including:
- Data Protection Officers
- Compliance Managers
- CISOs and security leaders
- IT Managers
- AI governance and risk professionals
It will be particularly relevant to organizations handling personal, financial, health or other sensitive business data.
Watch Webinar: AI Agents & Sensitive Data – Rethinking Access Control
The session includes a practical example of application-level access control and shows how organizations can move from policy to enforceable access boundaries.
Related Resources
For a deeper exploration of the topics discussed in the webinar:
- Agentic AI Security Risks: ENISA’s Warning & the Hugging Face Incident
Explore how ENISA’s guidance on frontier AI connects with the Hugging Face incident and the need for stronger access controls around autonomous agents.
- The EU AI Act Today: What Changed on August 2
Understand what changed under the EU AI Act, what was postponed and why organizations still need practical controls around AI use and data access.
- Shadow AI Agents: Why Access Control Is the Missing Layer
Learn why Shadow AI is no longer only an upload problem and how inherited permissions can give AI agents broader access than intended.
- BestCrypt Data Shelter
See how application-level access control can help restrict which applications, processes and AI agents are allowed to access sensitive files.
Speaker

Alexey Boltunov
Chief Operating Officer (COO), International
Alexey has been with Jetico since 2013, starting in technical support before moving through a series of technical and leadership roles. His background spans software quality assurance, usability, customer success and product strategy, giving him a practical view of how security controls need to work in real environments – not just on paper.
Today, Alexey works closely with Jetico’s engineering and commercial teams on data protection, access control and emerging security challenges. His current focus includes how increasingly autonomous and over-permissioned AI tools can interact with sensitive data, and how organizations can put practical boundaries around what applications and processes are allowed to access.