top of page
Search

Stop Giving the Intern (AI) the Keys

Writer: Stephanne Payne
Stephanne Payne
Jul 24
2 min read

Everyone's excited (or scared) about Agentic AI... and they should be. The promise is powerful: AI doesn't just answer questions; it takes actions, orchestrates workflows, and gets work done.


From a CISO perspective, we're making a dangerous mistake.


We're focusing on what the agent CAN do instead of what it SHOULD do.


Try this: AGENTIC AI IS LIKE A BRILLIANT INTERN.


It can read faster than anyone, learn instantly, work 24/7, and do tasks at incredible speed. But it has ZERO common sense, no context, no intuition about politics, risk, or unintended consequences.


If you tell that intern: "Find all vendors who haven't been paid and send them an update."


It might do exactly that (even if a vendors is involved in litigation, another is under investigation, and a third is being intentionally offboarded).


The intern followed instructions. The business suffers the consequences.


Now let's talk about Model Context Protocol.


MCP is essentially the collection of tools, systems, and data that intern can access. Think of it as giving the intern a badge to open every door and access to:


ticketing systems


comms platforms


HR data and financial systems


production cloud environments


Every new MCP connection expands what the Intern (AI agent) can see and do.


And that's exactly where we should start paying attention.


The real risk isn't the model. Discussions focus on prompt injection, jailbreaks, or model vulnerabilities.


Those matter.


But usually, the bigger risk is overprivileged agents connected to too many tools with too little governance.


A compromised AI agent isn't dangerous because it is intelligent.


IT'S DANGEROUS BECAUSE IT'S TRUSTED.


Before deploying agents (just like before granting employee access), ask:


What systems can this agent access?


What actions can it perform?


What sensitive data can it retrieve?


Are permissions aligned to least privilege?


Can we monitor every tool invocation?


Can we revoke access immediately?


Do we know when the agent is operating outside its normal behavior?


If you can't answer those questions, you're not deploying AI. You're deploying risk.


Give AI agents unique identities, use RBAC and least privilege, avoid shared service accounts. Then secure the MCP layer (inventory what's connected, review permissions, create thresholds and require approvals for higher-risk stuff, etc.)


Log Everything: Prompts, Tool calls, Data access, Actions taken, Privilege escalations... ASSUME agents will be manipulated and be ready for that, even with an AI-IRP.


Agentic AI will become one of the most privileged identities in many organizations with MCP as the highway connecting those identities to critical systems and data.


Our job is not to slow adoption; it's to ensure that before we hire the world's smartest intern, we don't accidentally hand it the master key ring.



 
 
 

Recent Posts

See All
Deep Questions About AI, Governance, and Ethics

I had a conversation with AI this morning that left me with a governance question I don't think we're asking early enough. We spend enormous amounts of time discussing how we should govern what increa

 
 
 
The AI Arms Race

I was talking to a bud the other day and that convo made me realize that there are days when AI feels less like a technological revolution and more like an arms race. As security leaders, we're watchi

 
 
 

Comments


  • Linkedin

Cybersecurity Leadership Manifesto

© 2026 by Stephanne 
Powered by secure practices and innovative thinking.

bottom of page