TL;DR: Fortinet’s FortiAI 8.0 underscores that AI security is now a board-level infrastructure issue, but the article argues perimeter visibility still stops short of runtime authorization for agents, according to EnforceAuth. The real failure is assuming authentication and traffic inspection can govern autonomous, always-on identities after the session starts.
Editorial analysis by NHI Mgmt Group, based on content published by EnforceAuth: “Fortinet Just Confirmed What We've Been Saying. Here's What They Can't Fix.”.
By the numbers:
- Machine identities outnumber human identities 45 to 1 in the average enterprise.
Key questions
Q: What breaks when AI agent permissions are only enforced at the network perimeter?
A: Perimeter-only controls miss actions that happen locally inside the developer environment, such as shell commands, file writes, and local tool calls.
Q: Why do AI agents create a different authorisation problem from ordinary automation?
A: Ordinary automation follows predefined rules, so the access path is known before execution starts.
Q: What are the signs that an agent’s effective permissions are too broad?
A: Look for agents that can move from retrieval to mutation, inherit user or service credentials without separation, or reach multiple environments with the same identity.
Practitioner guidance
- Define per-action authorization for agents Map every agent workflow to a decision point that evaluates the exact resource, action, and context before execution.
- Inventory non-human identities with persistent access Identify agent sessions, service accounts, and API keys that can continue operating after initial authentication.
- Convert permission lists to policy-as-code Store authorization logic in version control, test it in CI/CD, and deploy it with the same change discipline as application code.
Bottom line: The article’s central risk is the gap between seeing an AI agent enter and governing what it is allowed to do after entry.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Authorization, not visibility, is the missing control plane for AI agents: perimeter telemetry can show that an agent entered and what traffic it generated, but it cannot decide whether each action was permitted. AI security programmes that stop at detection are still leaving the governing question unanswered: what is the agent allowed to do right now? The practitioner implication is that runtime authorization must become the primary enforcement layer for non-human action.
A question worth separating out:
Q: How should security teams govern AI agent authorization in distributed systems?
A: Security teams should govern AI agent authorization as a per-request decision problem, not a one-time entitlement. That means enriching each request with identity, resource, and relationship data, then enforcing policy at the tool or protocol boundary. The goal is consistent access control across apps, APIs, queues, and data platforms, with audit logs that show exactly what drove each decision.
👉 Read our full editorial: AI agent security beyond the perimeter: why authorization is missing