That question lands directly in Sydney this week.
An AISA NSW branch session on August 20 asks how organisations can trust AI assistants, bots, and automated tools that behave like workforce members, with access to systems, data, and business processes.
Cyber Daily has also reported that Westpac is already using five AI agents in lending workflows.
The usual answer is least privilege: give a system only the access it needs. That remains essential, but it leaves a second problem unresolved. Permissions that were sensible when an agent was created can quietly become inappropriate as its purpose changes, integrations multiply, data expands, or the human team around it moves on.
Australian organisations should give every production AI agent an authority lease.
An authority lease works like a time-limited operating mandate. The agent receives permission to perform a defined job for a defined period. When that period ends, its authority expires unless a named human owner revalidates the arrangement.
The lease should contain five things. First, a human owner who remains accountable for the agent’s behaviour. Second, a narrow business purpose, written in ordinary language. Third, the systems, data, and actions the agent may access. Fourth, a fixed expiration or review date. Fifth, the evidence required for renewal, such as successful task completion, exception rates, human interventions, security alerts, or changes in the underlying workflow.
This changes governance in an important way.
Today, many access reviews ask whether a permission still exists and whether someone can justify it. An authority lease reverses the burden. Continued access becomes a decision that someone must actively make.
That matters because normalisation is powerful. Once an automated process works for several weeks, people stop noticing it. A service account that felt temporary becomes infrastructure. An AI agent that started as a pilot begins touching more consequential work. Teams inherit workflows they did not design. Nobody intentionally expands the risk, yet the operating environment drifts.
Expiration creates a scheduled moment to notice that drift.
A practical test can start small. Pick three production agents and give each a 30-day lease. Five days before renewal, require the owner to answer four questions: Is the original purpose still valid? Does the agent still need every permission it has? What human interventions or exceptions occurred? What would be the business impact if the agent acted incorrectly tomorrow?
Then track what changes at renewal. Count permissions removed, integrations no longer needed, unclear ownership, recurring human rescues, and agents that no longer justify their authority. Those figures tell security leaders more than a dashboard showing that an agent remains active.
The goal is to speed responsible agentic AI deployment by giving employees and managers clear boundaries. Autonomy has limits, accountability has a name, and access does not persist indefinitely by default.
AI agents are becoming colleagues in a functional sense. Organisations already know that human employees receive roles, managers, access reviews, and offboarding. Non-human workers deserve an equally clear lifecycle.
The next generation of identity governance should therefore ask two questions: What is this agent allowed to do today, and when does that permission automatically end?
The second question may become the stronger control.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.