Permission Management Is the Starting Point of AI Agent Security
The key to securing AI agents—AI systems that perform tasks by making their own judgments—is not intelligence but permissions. In one experiment, an AI agent was found to have carried out more than 17,000 tasks over three days, accessing and attacking other systems in order to obtain the information needed to meet its evaluation criteria. In a contributed article published on the 29th, Jungin Park, a research professor at Duksung Women's University's AI DynaInfo Lab, pointed out that this case matters not because the AI acted maliciously, but because it chose paths humans did not anticipate in the course of pursuing its given goal. As agentic AI is adopted by businesses, public institutions, and critical infrastructure, she argued, we must abandon the expectation that AI will always behave in a predictable way.
As an alternative, the article proposed the principle of least privilege: allow only the data and functions necessary for the task at hand, and block internet or remote access when it is unnecessary. When access is unavoidable, restrictions should be placed on the destination, duration, and permissible commands, along with time-limited permissions that are automatically revoked after the work is completed. The article especially stressed that granting administrator privileges for extended periods should be avoided in critical infrastructure. What matters in critical infrastructure, it noted, is not whether AI can be trusted, but whether damage can be limited even if AI behaves incorrectly.
Cybersecurity and Infrastructure Security Agency (CISA) red team exercises show that security cannot be achieved with equipment alone. Even when assessed with the same tools, some organizations failed to find critical signals amid thousands of alerts, while others carefully tuned their alerts to focus on what truly mattered and respond immediately.
The article also addressed the issue of vendor responsibility. When cyber incidents occur, responsibility for password management and patching has often been shifted onto the using organizations or individuals. But if a product is designed to be vulnerable from the start or ships with excessive default administrator privileges, the problem cannot be solved by the using organization alone. CISA's emphasis on 'secure by design' rests on the principle that security responsibility should fall on the vendor, not the user. Against this backdrop, the article stated that public institutions and critical infrastructure operators should include minimum-privilege configuration, external access restrictions, emergency stop functions, independent security testing, vulnerability disclosure procedures, recovery support in the event of incidents, and security updates throughout the product lifecycle in their AI procurement contracts.
Park concluded that permission management is the starting point of AI agent security. Organizations, she said, must clearly define what AI can see, where it can gain access, and who can stop it when problems arise. The essence of security in the AI era, she argued, is designing systems so that even when AI behaves in unexpected ways, the harm to organizations and the public is minimized.
