TL;DR: AI agents create new data-loss pathways, but DLP alone does not solve the identity, authorization, and audit gaps that govern how those agents reach enterprise data, according to WorkOS. The security problem is not just exposure prevention, it is controlling who or what can act before sensitive data ever becomes accessible.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Jazz Security for AI Agent Security: Features, Pricing, and Alternatives”.
Key questions
Q: What breaks when AI agents are governed with legacy DLP controls?
A: Legacy DLP breaks because it assumes data moves through predictable human actions such as email, uploads, and endpoint copy events.
Q: Why do AI agents increase the risk of oversharing sensitive data?
A: AI agents often aggregate context from multiple sources, then present or transmit that information in ways a user would not normally see.
Q: How can security teams tell whether agent access is actually under control?
A: Look for evidence that the team can trace every tool call, secret use, and cross-system action back to a named owner and a valid approval path.
Practitioner guidance
- Define the agent identity model Document whether each AI agent is authenticated as a user, service account, workload identity, or delegated application, and make that mapping explicit in policy.
- Constrain agent permissions before deployment Use fine-grained authorization to limit each agent to the smallest set of systems, data classes, and actions required for its workflow.
- Separate monitoring from authority Keep DLP and content inspection in place, but treat them as secondary to identity controls that determine what the agent can reach.
Bottom line: AI agent data protection fails when monitoring sits downstream of access decisions, because content controls cannot replace identity governance.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI agent DLP is incomplete because it sits after the identity decision. Content inspection can reduce exposure, but it cannot decide whether an agent should have received access in the first place. That makes authorization, credential scope, and lifecycle governance the primary control surface. The implication is that security teams must stop treating data protection as a standalone layer once autonomous systems are in play.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations use DLP or authorization first for AI agents?
A: Organisations should put authorization first and DLP second. Authorization determines whether the agent should reach the data at all, while DLP inspects what happens after access begins. If authorization is weak, DLP becomes a noisy backstop instead of a meaningful control.
👉 Read our full editorial: AI agent data protection is still incomplete without identity controls