Feature Story News

The New Insider Threat: Why AI Agents Need Governance Before They Need Access

Mazen Adnan Dohaji, Senior Vice President & General Manager, Exabeam

As enterprises accelerate the adoption of autonomous AI, Exabeam is championing a new security discipline, Agent Behavior Verification, designed to ensure AI agents are properly configured, governed, and accountable before they enter production environments.

Artificial intelligence is rapidly evolving from a productivity tool into an active participant in enterprise operations. Across industries, organizations are deploying AI agents to automate workflows, access business applications, interact with customers, analyze data, invoke APIs, and execute tasks that were traditionally performed by humans. While this transformation promises enormous gains in efficiency and innovation, it is also creating a security challenge that many organizations are only beginning to understand.

According to Mazen Adnan Dohaji, Senior Vice President and General Manager at Exabeam, the next frontier in cybersecurity is not simply protecting AI systems from attackers. It is ensuring that AI agents themselves behave within clearly defined boundaries before they are trusted with enterprise access.

This thinking has led Exabeam to introduce Agent Behavior Verification (ABV), a new security discipline designed specifically for the age of the agentic enterprise.

From Human Insider Threats to AI Insider Threats

For years, insider threats have been among the most difficult challenges for security teams. Traditional security programs were designed primarily to stop external attackers, but many of the most damaging incidents often involved legitimate users with legitimate access.

The arrival of AI agents transforms that challenge dramatically.

Unlike traditional software, AI agents can make decisions, interact with multiple systems simultaneously, access sensitive data, and act with a level of autonomy that resembles human users. They are increasingly becoming digital workers with permissions, responsibilities, and access privileges across enterprise environments.

“The biggest risk organizations underestimate today is treating AI agents solely as productivity tools,” says Dohaji. “In reality, they are becoming a new class of insider.”

Unlike malicious hackers attempting to breach a network, AI agents often operate with approved credentials, trusted permissions, and legitimate workflows. When something goes wrong, separating normal activity from problematic behavior becomes far more difficult.

An AI agent may have access to customer records, financial data, cloud services, development environments, or operational infrastructure. If that agent receives excessive permissions, accesses unintended data, or takes actions outside its intended role, the consequences can be significant despite no malicious intent being involved.

This challenge is especially relevant in the Middle East, where organizations are aggressively embracing AI to support digital transformation initiatives, smart city projects, financial innovation programs, and national technology strategies.

“In the age of the agentic enterprise, the question is no longer whether an AI agent can perform a task. The real question is whether it should be allowed to perform that task in the first place.”

Mazen Adnan Dohaji, Senior Vice President & General Manager, Exabeam

The Missing Layer in AI Security

Most existing AI security frameworks focus on identifying vulnerabilities through penetration testing, red teaming exercises, runtime monitoring, or adversarial testing.

These approaches remain important. However, according to Exabeam, they all share one assumption: the AI agent already exists.

Agent Behavior Verification takes a different approach.

Rather than asking whether an agent can be exploited, ABV asks whether the agent should be trusted in the first place.

Before deployment, ABV evaluates whether an AI agent’s permissions, tools, memory, integrations, workflows, and authority align with the role it has been assigned.

This approach addresses one of the most overlooked risks in enterprise AI adoption: governance.

Many AI failures do not stem from sophisticated cyberattacks. Instead, they emerge because an AI agent receives broader permissions than necessary or operates without sufficient oversight.

By validating an agent before deployment, organizations can identify governance gaps before they become security incidents.

Why Pilot Projects Often Fail in Production

One of the recurring challenges organizations encounter is the transition from experimentation to enterprise-wide deployment.

During pilot phases, AI agents are typically evaluated based on functionality. Organizations focus on whether the agent performs a task successfully.

Once deployed, however, agents are often connected to additional applications, integrated with business workflows, and granted broader access privileges.

This is where governance failures emerge.

Organizations frequently prioritize deployment speed over security design. Questions such as ownership, accountability, approval processes, authorization boundaries, and permissible actions are often addressed later, if at all.

As a result, AI agents can operate with unclear responsibilities and excessive permissions.

Many organizations mistakenly treat deployment as a technical milestone. In reality, deployment should be viewed as a governance milestone.

The challenge is not whether an agent works. The challenge is ensuring it operates only within approved parameters.

Praxen: Verifying AI Before It Goes Live

To help organizations address these concerns, Exabeam introduced Praxen, an open-source implementation of Agent Behavior Verification.

At the center of Praxen is the concept of an “ABV Remit,” effectively a policy contract that defines what an AI agent is authorized to do, which resources it can access, and what limitations apply to its behavior.

Praxen evaluates whether the agent’s actual capabilities align with its intended purpose.

The platform analyzes:

  • Agent permissions
  • Tool access
  • Memory structures
  • Data integrations
  • Operating environment
  • Workflow capabilities
  • Authorization scope

The objective is to identify gaps between design intent and practical capability.

Many AI-related risks emerge precisely within those gaps.

An organization may create an AI agent designed to retrieve customer support information, but through misconfiguration it could gain access to financial systems, customer databases, or sensitive operational data. Praxen helps identify those risks before deployment.

Balancing Innovation and Compliance

One of the biggest concerns facing organizations globally is how to balance AI innovation with growing regulatory expectations.

This challenge is particularly important in the Middle East and Africa, where countries are rapidly building digital economies while simultaneously strengthening privacy and data protection regulations.

Different jurisdictions impose different requirements for data storage, processing, access, and transfer.

AI agents operating across multiple business environments must comply with these varying obligations while still delivering business value.

According to Dohaji, organizations that succeed with AI will be those that build governance into the foundation of their AI strategy rather than attempting to add controls later.

Innovation and security are no longer competing objectives. Sustainable innovation depends on strong governance.

Extending UEBA into the AI Era

Exabeam has long been associated with User and Entity Behavior Analytics (UEBA), a security discipline focused on identifying insider threats through behavioral patterns rather than traditional indicators of compromise.

Now the company is extending that philosophy into the AI domain through Agent Behavior Analytics (ABA).

ABA expands behavioral intelligence beyond human users and machine identities to include AI agents.

Instead of focusing exclusively on credentials or usernames, ABA analyzes behavioral patterns across systems, workflows, identities, applications, and agents.

This enables organizations to detect:

  • Prompt injection attacks
  • Guardrail violations
  • Unauthorized tool usage
  • Abnormal workflow execution
  • Delegated credential abuse
  • Behavioral drift
  • Excessive agent activity

Most importantly, it enables security teams to reconstruct activity chains from human users to AI agents and downstream systems.

This visibility allows organizations to understand not only what happened, but why it happened and where risk originated.

The CISO’s New Responsibility

As organizations move toward agentic AI, CISOs are assuming a broader strategic role.

Historically, CISOs focused on securing networks, endpoints, applications, and identities.

Today, they must also govern autonomous decision-making systems.

Dohaji believes CISOs must act as the accountability layer between AI autonomy and enterprise risk.

Their role is to define where autonomy is permitted, where human approval is required, and how decisions are audited.

This increasingly points toward a Human-on-the-Loop (HOTL) operating model.

In this model, AI agents act autonomously within defined parameters while humans maintain oversight and retain intervention authority.

The result is faster operational efficiency without sacrificing accountability.

Building the Future of Agent Security

Over the next three to five years, AI agent security is likely to become as important as identity security or cloud security is today.

Organizations will need continuous visibility into agent activity, behavior, permissions, and risk exposure.

Exabeam’s vision combines three core capabilities:

  • Praxen for pre-deployment verification
  • Observra for AI activity monitoring and telemetry
  • Agent Behavior Analytics (ABA) for ongoing behavioral intelligence

Together, these technologies establish a framework where AI agents are verified before deployment, monitored during operation, and continuously evaluated for unusual behavior.

As enterprises embrace autonomous systems, the focus of cybersecurity is shifting from merely protecting infrastructure to governing intelligence itself.

The organizations that succeed in the AI era will not simply be those that deploy agents the fastest. They will be those that establish trust, accountability, and governance from day one, ensuring that AI innovation remains secure, transparent, and aligned with business objectives.

Related posts

Axis Communications Launches New License Plate Recognition Camera Kits for Traffic Monitoring and Access Control

Enterprise IT World MEA

Nutanix Launches Agent Gateway to Strengthen Governance for Enterprise AI Agents

Enterprise IT World MEA

Tencent Expands Global Access to Hy3 AI Model to Accelerate Enterprise AI Adoption

Enterprise IT World MEA

Leave a Comment