The Forbes Technology Council published a new expert panel on August 7, 2026, at 8:15 a.m. EDT, offering a blunt warning: AI agents are no longer just chatbots. They can interact with software, retrieve sensitive data, and take actions across business systems. That capability can unlock major gains in speed and productivity, but it also raises the stakes when an agent behaves unpredictably, receives excessive access, or makes a mistake at machine speed. The Council Post, which appears in Forbes' Innovation section, gathers recommendations from 18 technology executives on the safeguards organizations should implement before allowing AI agents to access critical systems, sensitive data, or production environments.
The article is part of the Forbes Councils Member expertise, operated under license. Opinions expressed are those of the authors, and membership is fee-based. The piece also includes a voice experience generated by AI, alongside a video player and a featured Forbes video. Editorial standards and reprints/permissions links accompany the article.
The Core Problem: Agents Move Faster Than Oversight
The central question the panel addresses is straightforward: who controls AI agents, what are they allowed to do, and how is their activity tested, monitored, and reviewed? The answers vary, but a common thread runs through all 18 contributions. Human roles are already overprovisioned, accumulated over years and rarely shed. Hand an agent a role and it inherits that cruft instantly.
Harman Kaur, a Forbes Technology Council member from Tanium, put it directly. "Agents shouldn't get roles. They should get just-enough, just-in-time access that's granted for the workflow, then revoked." She noted that role-based access control designed for humans is a problem. Agents should get task-scoped access, not role-scoped access.
Ofer Klein of Reco advised mapping agent identity carefully. He recommended defining permissions, the apps and data an agent can reach, and the actions it can take. Scope to least privilege, monitor continuously, and revoke access when it is no longer needed.
Tim Currie of In Balance IT Solutions went further. He recommended eliminating standing permissions for AI agents entirely. Provision them with least-privilege, just-in-time access, with no standing permissions. Human approval should be required for irreversible actions.
Human Approval Gates and Accountability
Several executives argued that the human must remain in the loop, especially for high-impact decisions. Devendra Rajput of Accenture recommended a human approval step between agent recommendations and execution. That step, he said, is the difference between an agent that assists and an agent that acts.
Jessica Vitiritti of Bank of Montreal echoed that approach. She recommended least-privilege access, sandbox or nonproduction testing, and human approval for irreversible or high-impact actions. Her framework treats the agent as a tool that proposes, not a system that decides.
Ali Alkhafaji of APPLY insisted on named human accountability for every output an agent produces. No anonymous automation. Someone must own the result.
Jesse Stockall of Flexera called for approval gates, least-privilege permissions, and auditable actions. Access should be task-specific, time-bound, and regularly reviewed. He framed the entire effort as an architecture and risk decision, not a configuration toggle.
"The safeguard isn't a tool you buy; it's the discipline of treating agent access as an architecture and risk decision, not a config toggle," Stockall said.
Identity: Agents as Machine Identities
A second major theme is identity. Agents are not users, and they should not be treated as such. Darren Guccione of Keeper Security said AI agents must be treated as privileged identities. He recommended enforcing least-privilege, just-in-time access with full session accountability.
Jason Sabin of DigiCert Inc. recommended issuing cryptographic identities with policy-bound authorization. He called for continuous auditability, governance, and lifecycle management for AI agents as machine identities.
Bojan Šimić of HYPR Corp. proposed an inline control plane that cryptographically binds each agent to a verified human owner. That binding includes timebound authority and real-time oversight.
"Granting access without strong identity controls is a blueprint for disaster," Sabin said.
Boundaries, Trust Layers, and Monitoring
Elliott Cordo of Data Futures warned about asymmetric access. Low-privilege agents interacting with high-privilege agents or humans can create dangerous combinations. He said that unless every agent boundary is treated as a trust boundary and deterministic authorization policies are enforced, such interactions can create opportunities for privilege escalation.
"Overpermissive and/or inherited access creates a far larger blast radius than a single misused login," Cordo said.
Erez Tadmor of Tufin suggested a different route. He advised routing agents through existing guardrails, such as network-access-request frameworks, rather than giving them direct access. Use the controls you already have.
Chris Wade of Itential recommended locking agent actions at build time and enforcing them at runtime. The human decides which tools an agent can execute. Real safety, he argued, comes from scoping before execution.
"Real safety isn't approving actions after the fact. It's scoping what an agent can do before it ever runs," Wade said.
Jim Richberg of Fortinet, Inc. recommended real-time analytics to detect deviations, unusual access, and unexpected system interactions. He called for red lines and alert-driven monitoring, not static logs.
"By the time you audit static activity logs, the damage is already done," Richberg said.
Tony Grout of M-Files called for a trusted information layer and governance controls for data access and monitoring. He noted that agents are only as reliable as the data they use.
Asaf Kochan of Sentra advised discovering and classifying sensitive data, mapping access paths, and enforcing least privilege. Know what you have before you let an agent near it.
Virgil Bretz of MacroHealth drew a hard line on healthcare data. He stated that public LLMs should not directly touch protected health information or sensitive data. Only internally developed, governed agents should.
"Public models are built for general use, not for the accountability healthcare data demands," Bretz said.
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
Testing, Evaluation, and Continuous Review
Pawel Rzeszucinski of WebPros required evaluations and observability. Evals verify consistent behavior. Observability provides traces of prompts, tool calls, decisions, and actions. Both are necessary.
Brian Stimpfl of S-Docs advised mapping the exact problem and success measures before granting access. Start with scoped, auditable access, then expand based on usage data. Do not grant broad access upfront.
Abhijit Kakhandiki of BMC Software emphasized clear accountability. He called for defined ownership, operating boundaries, and auditable actions for every agent. Someone must be responsible.
"Governance is not a constraint on what you build. It is what makes what you build worth trusting," Kakhandiki said.
The panel's collective message is consistent. Agents can deliver speed and productivity, but only if organizations build the guardrails first. The leading enterprises across industries will be those that can accelerate AI adoption while maintaining trust in the decisions and actions AI takes.
The article's publication date of August 7, 2026, places this guidance at a moment when AI agent adoption is accelerating across industries. The Forbes Technology Council, an invitation-only community for world-class CIOs, CTOs, and technology executives, assembled the panel to address the gap between agent capability and organizational control.
"Most organizations have no framework for what an agent can access, who owns it or how its actions are audited. That gap is the attack surface, and it's exponentially expanding," Guccione said.
The 18 contributors represent a broad cross-section of technology leadership. They come from Accenture, Tanium, BMC Software, Bank of Montreal, S-Docs, APPLY, M-Files, Reco, Itential, Keeper Security, Fortinet, Inc., MacroHealth, Flexera, DigiCert Inc., WebPros, Sentra, HYPR Corp., Data Futures, In Balance IT Solutions, and Tufin.
Their recommendations converge on a few practical steps. Grant agents the minimum access required for a specific task. Bind every agent to a named human owner. Require human approval for irreversible actions. Monitor activity in real time, not after the fact. Test in sandboxes before production. Treat agent access as a governance decision, not a technical afterthought.
The stakes are high. An agent with excessive access can move at machine speed, making mistakes faster than any human can intervene. The panel's advice is designed to slow that process down, inserting checkpoints and boundaries at every stage.
For organizations already deploying agents, the guidance suggests a review of current access policies. For those still planning, the message is to build the safeguards before the connection, not after.
The article is a Council Post, meaning it reflects the expertise of its members rather than original reporting. It contains no statistical evidence or case studies. The value lies in the collective experience of the executives who contributed.
Forbes' use of an AI-generated voice experience alongside the article reflects the very technology the panel discusses. The company has integrated AI into its own content delivery while publishing expert guidance on how to control it.
The panel's recommendations are practical, not theoretical. They address the specific failure modes that emerge when autonomous systems interact with production environments. Excessive access, missing accountability, and untested behavior are the risks. Least privilege, named ownership, and continuous monitoring are the remedies.
The article also includes links to Forbes' editorial standards and reprints/permissions, standard for Council Posts. The video player and featured video are part of the standard Forbes article layout.
As of August 7, 2026, the guidance stands as a reference point for technology leaders navigating the shift from generative AI to agentic AI. The distinction matters. A chatbot that generates text is limited. An agent that takes actions is powerful. Power requires control.
The 18 executives agree on the fundamentals. They differ on emphasis. Some focus on identity. Others focus on monitoring. Still others focus on human approval. All of them point to the same conclusion. AI agents need guardrails before they get access.
The article's publication in the Forbes Innovation section signals its intended audience. Technology executives, CIOs, and CTOs are the readers. The recommendations are written for them, in the language of enterprise IT.
The fee-based membership of the Forbes Councils means the contributors have paid to be part of the community. That does not diminish the substance of their advice. It does mean the article should be read as expert opinion, not independent journalism.
The voice experience generated by AI is a notable detail. It shows that Forbes itself is using the technology its contributors are advising on. The company has adopted AI for audio while publishing guidance on how to govern it.
The panel's advice on data is particularly relevant for regulated industries. Healthcare, finance, and government all face strict requirements on data handling. Bretz's warning about public LLMs and protected health information applies broadly.
The recommendation to route agents through existing guardrails, from Tadmor, is a pragmatic approach. Organizations already have network access controls, approval workflows, and audit systems. Agents can be plugged into those frameworks rather than bypassing them.
The emphasis on real-time monitoring, from Richberg, reflects the speed of agent operations. Static logs are insufficient. Alerts must be immediate. Red lines must be defined in advance.
The cryptographic identity approach, from Sabin and Šimić, points to the future. Agents as machine identities, bound to human owners, with timebound authority. That is a technical solution to an organizational problem.
The panel's advice is not a single blueprint. It is a set of options, each tailored to different organizational contexts. The common thread is discipline. Treat agent access as seriously as human access. Maybe more seriously.
The publication date of August 7, 2026, at 08:15 a.m. EDT, marks the moment this guidance became available. The article is now part of the public record on AI governance.
For technology leaders, the message is clear. The time to build safeguards is now. The agents are coming. The controls should be ready before they arrive.

