Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Blog

Businesses Must Control AI Agent Actions and Identities—or Face the Consequences, Says Palo Alto Networks’ EMEA CISO

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

AI agents should be treated as privileged non-human identities, not as ordinary chatbots. They can interpret goals, select tools, access sensitive systems and take actions at machine speed. Palo Alto Networks EMEA CISO Haider Pasha warned in an ITPro interview published October 6, 2025 that agentic-AI projects could fail at an even higher rate than widely cited forecasts unless organizations impose strong strategic and technical controls.

The practical message for businesses is straightforward: every agent needs a known owner, a distinct identity, narrowly defined authority, observable activity, enforceable runtime policies and a rapid way to revoke access.

What Pasha’s warning means

Pasha’s argument is about governance and accountability, not banning artificial intelligence. ITPro reported that he viewed Gartner’s forecast that 40% of agentic-AI projects would fail by 2027 as potentially optimistic. That figure should be treated as an attributed forecast, not a universal measurement: “failure” might mean cancellation, missed business goals, technical abandonment or failure to reach production, rather than a cyberattack.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The same report said Palo Alto Networks estimated that an average organization was running 66 generative-AI applications at the time. That is a company-reported figure, not an independently verified benchmark. It nevertheless illustrates the discovery problem: organizations can accumulate AI tools and agents faster than security teams can inventory them.

Palo Alto Networks has a commercial interest in this warning. Its Prisma AIRS portfolio is marketed as a way to discover agents, verify identity, enforce policy and monitor runtime behavior. Those are vendor-described capabilities, not proof that any platform eliminates risk.

Agent, chatbot, copilot or automation?

System Typical behavior Core security question
Chatbot Generates a response to a prompt What information can it see and disclose?
Copilot Suggests or assists while a person usually takes the final action Who reviews and approves the action?
Workflow automation Executes predetermined steps Are the steps bounded and authorized?
AI agent Interprets a goal, chooses tools and may act autonomously What may it decide, invoke or change?
Multi-agent system Agents delegate tasks or exchange information Which identities and permissions flow between agents?

Not every generative-AI use is agentic. The security burden rises when a system can select tools, make decisions, retrieve data and cause changes without a person checking every step.

Why the security model changes

An agent can chain several services, react differently to prompts and retrieved content, and operate continuously. A hostile instruction hidden in an email, document, web page or tool response may redirect it. If it inherits a user’s broad permissions, one compromised session can expose data or alter multiple systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Traditional controls remain useful, but they do not automatically show which model version, prompt, retrieved source, tool call and policy decision led to an action. Palo Alto Networks describes AI environments as compound systems linking models, plugins, data sources, agents and external services at runtime; risks can emerge from those interactions after pre-deployment testing.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

What can go wrong?

  • Excessive privilege: A purchasing agent that can create vendors, approve invoices and release payments has far more authority than one that only drafts purchase orders.
  • Credential theft: An attacker who obtains an agent token may use it directly or force the agent to reveal a secret.
  • Prompt injection: Malicious text can instruct an agent to ignore its original task, disclose information or call an unsafe tool.
  • Data leakage: Confidential customer, financial or employee records may be sent to an external model, SaaS service or unauthorized recipient.
  • Tool or dependency poisoning: A compromised plugin, MCP server, package or tool description can steer decisions.
  • Cross-agent delegation: One agent may pass authority to another without a clear policy governing that delegation.
  • Runaway automation: A loop can generate repeated API calls, mass record changes, unexpected cloud bills or customer-facing errors.
  • Unclear accountability: Logs may say only that “the AI assistant” changed something, without identifying the model, prompt, credential, policy or authorizing user.
  • Availability failures: A model outage, provider change, revoked token or policy block can stop a critical process.

Identity is the first control layer

Authentication answers, “Is this the claimed agent?” Authorization answers, “What may it do?” Policy enforcement asks whether it may do that now, in this context. Accountability requires reconstructing what happened and why. These are separate controls.

Each agent, deployment or workload should have a distinct identity rather than permanently reusing a human employee’s credentials. The record should identify:

  • the business and technical owner;
  • the model, code, tools, plugins, MCP servers, data sources and environments connected to it;
  • the human or service principal that authorized a task;
  • the permissions and secrets used;
  • the approved purpose and operating boundaries; and
  • expiration, rotation and emergency-revocation procedures.

Short-lived credentials reduce exposure time but do not correct excessive scope. Read-only access prevents some changes but does not prevent unauthorized data retrieval or disclosure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Control actions, not just identities

An authenticated agent can still make an unsafe decision. Organizations should allowlist tools and APIs, assign permissions per tool and operation, and make read-only access the default where practical. Separate recommendation, execution and approval; an agent should not approve its own proposed action.

Rank #3
Ubiquiti Networks Networks Unifi Security Gateway Pro (USG-PRO-4)
  • Ubiquiti Networks networks networks Unifi security Gateway Pro 4-Port (USG-PRO-4)
  • 4 Gigabit RJ45 ports plus 2 Gigabit SFP ports for fiber connectivity If needed
  • Standard rack mount 1U size
  • Provide cost-effective, reliable routing and advanced security for your network
  • Max. Power Consumption:7W

Use transaction, spending, volume and time limits. Restrict deletion, privilege changes, external communication and data export. Require human confirmation for irreversible or high-impact actions, while recognizing that a reviewer can become a rubber stamp if the full tool call and hidden instructions are not visible.

Runtime policies should consider the user, device, location, data sensitivity, time and risk. They should block prohibited destinations, detect suspicious tool use, stop loops and record every meaningful event.

A practical control framework

Before deployment

  1. Classify the use case. Decide whether the agent is advisory, approval-supporting or autonomous. Rate maximum harm, data sensitivity, reversibility and blast radius.
  2. Map dependencies. Document the model provider, framework, system instructions, retrieval sources, tools, APIs, MCP servers, secrets, service accounts, approvers and downstream systems.
  3. Assign owners. Name business, technical, security, data and incident-response owners.
  4. Create a workload identity. Avoid shared credentials, bind access to the specific environment and link each task to its initiating human or system.
  5. Apply least privilege. Start read-only; scope by resource, operation, tenant and classification.

During operation

  1. Log the chain of activity. Capture agent and user identities, model and version, task identifier, retrieved sources, tool parameters, policy decisions, approvals, results and downstream changes. Protect logs because prompts may contain personal or confidential data.
  2. Enforce runtime policy. Block prohibited operations, require approvals for irreversible actions and cap spend, volume and execution time.
  3. Continuously test. Use malicious documents, prompt-injection attempts, tool impersonation, data-exfiltration tests, privilege-escalation scenarios and cross-agent delegation tests. Re-test after model, plugin or policy changes.

When something goes wrong

  • Maintain a kill switch and revoke the agent’s tokens immediately.
  • Disable individual tools without necessarily shutting down the whole workflow.
  • Preserve prompts, tool calls, policy logs and affected data.
  • Determine whether the cause was the model, prompt, retrieval data, tool, identity, policy or human approval.
  • Roll back data and configuration changes where possible.
  • Notify customers, regulators or partners when required.
  • Change permissions and tests after the incident; do not rely only on user retraining.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Where Palo Alto Networks fits

Palo Alto Networks positions Prisma AIRS as a lifecycle platform covering agent discovery, configuration and supply-chain assessment, identity verification, policy control, runtime monitoring, audit trails, AI posture management and red teaming. Its AI Runtime Security materials describe monitoring and real-time inspection, while its AI red-teaming offering is described as continuous simulation of attacks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On March 23, 2026, the company announced Prisma AIRS 3.0 and described an AI Agent Gateway as a centralized control plane for identity and runtime security, governance and observability. The announcement said the gateway was in limited preview at that time. Availability, packaging and regional access should therefore be confirmed directly rather than assumed from a product page.

Rank #4
FortiGate-30G Network Security Appliance Plus 3 Year FortiGuard Enterprise Protection and FortiCare Premium (FG-30G-BDL-809-36)
  • Single appliance with integrated firewalling, SD-WAN and Wi-Fi controller reduces complexity of WLAN management. Its zero-touch deployment helps optimize your onboarding experience.
  • Built on a patented secure processor, this compact network firewall delivers the highest level of security and performance in its class – 800 Mbps IPS | 500 Mbps threat protection.
  • User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
  • Compact and fanless design equipped with 4 GE RJ45 ports (1 WAN port and 3 internal ports) provide essential connectivity and flexibility for various network configurations in a small-scale environment.

Palo Alto’s reported AI Access Security capability, delivered through its network-security stack, addresses employee access to generative-AI applications. That is different from full identity and runtime governance for an autonomous agent modifying internal systems. A firewall, IAM platform or gateway may be necessary, but none alone is a complete agent-security architecture.

Questions buyers should ask

  • How are agents discovered across SaaS, cloud, low-code and custom environments?
  • Can every agent receive a distinct non-human identity?
  • Can permissions be scoped per tool, operation, resource and tenant?
  • Are prompts, retrieved sources, tool calls, outputs and policy decisions logged?
  • Can the system block an action in real time, not merely alert afterward?
  • Can one agent’s access be revoked immediately?
  • How are model, plugin, MCP, API and prompt changes tracked?
  • Which features are generally available and which are preview?
  • How does licensing work, and what integrations and log-storage costs are required?
  • What independent evidence supports detection and prevention claims?

The business trade-off

Centralized platforms can simplify inventory, policy consistency and reporting, but they may bring vendor concentration, integration work and enterprise licensing costs. Point tools and native IAM, API gateways or service meshes can be more modular, yet the organization may need to build its own AI-specific inspection, testing and correlation.

Human-in-the-loop controls reduce high-impact mistakes but add approval latency. Human-on-the-loop automation can be faster, provided alerts and intervention work. Fully autonomous execution is best limited to bounded, reversible, low-impact actions. The right question is not whether to automate everything or nothing; it is which actions are safe to automate, under what limits, with what evidence and recovery path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Palo Alto Networks’ fiscal 2026 earnings materials referenced more than 300 Prisma AIRS customers, but defined the count as customers with a booked quote for software NGFW credits that included Prisma AIRS. It should not be read as 300 standalone production deployments.

Bottom line

Agentic AI turns software into a form of privileged, non-human identity. Autonomy without explicit authorization, runtime controls, observability and reversibility is uncontrolled privilege. Businesses do not need to abandon agents, but they do need to make each agent’s authority bounded, attributable, testable and revocable before allowing it to touch money, customer data, production systems or other high-impact resources.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.