Skip to main contentSkip to footer
Get in touch with our experts
Data Privacy

AI Needs Access. But How Much?

08/17/2026 by Tihana Komadina

Why identity and access are becoming critical foundations for enterprise AI

Identity and access management has traditionally focused on a familiar set of questions: Who is the user? Which device are they using? Which applications and data should they be allowed to access?

AI is adding another dimension to this picture. As it becomes embedded in business processes, more applications, workloads, APIs and AI services are connecting to enterprise systems and data.

This means organizations need to think not only about which employees should have access, but also which applications, workloads and AI services should be trusted, what they should be allowed to access, what actions they should be permitted to perform and how much autonomy they should have when interacting across enterprise systems.

The security question is therefore changing. AI needs access to create value, but how much access should it have?

AI creates value through access

AI systems depend on information to provide useful answers, support decisions or automate business processes. That information may reside across collaboration platforms, cloud applications, databases, customer ERP systems and operational environments.

Access to relevant information is therefore fundamental to what AI can deliver. At the same time, every additional system, data source or application connected to AI introduces another access relationship that needs to be understood and managed.

Consider an AI assistant used to support employees. To be genuinely useful, it may need access to internal documents, customer information or business applications. But that does not mean every employee using the assistant should indirectly gain access to everything the AI can reach.

The same applies to an AI application connected to several enterprise systems through APIs. It may require information from those systems to perform its function, but this does not necessarily mean it needs permanent or unrestricted access to all of them.

Securing enterprise AI therefore goes beyond protecting the AI platform itself. Organizations also need to understand and control the growing number of access relationships around it.

Food for thought: Do you know which enterprise systems and data your AI applications can access – and whether they need all of it?

When identity is no longer only human

Machine identities are not new. Enterprises already manage service accounts, applications, workloads and automated processes. What AI changes is the potential scale and complexity of these interactions, as well as the level of autonomy that some of these identities may have within business processes.

An AI-enabled process may involve an employee, an AI application, several APIs, multiple data sources and other automated services. Each may have its own identity and different access rights. As these interactions multiply, understanding which identity is accessing which resource – and for what purpose – becomes more difficult.

This makes identity an increasingly important part of the infrastructure supporting AI. Being connected to the corporate network alone is no longer sufficient reason to trust a user, device, application or workload.

Organizations need to understand who or what is requesting access, which resource is being requested and whether that access is appropriate in that particular context.

Zero Trust provides an architectural approach to addressing this challenge.

From implicit trust to controlled access

Zero Trust is based on the principle that access should not be granted simply because a user, device or application is already inside a trusted environment. Instead, access is verified and limited according to identity, context and need.

This distinction becomes particularly relevant for enterprise AI.

An AI application connected to a customer database may need access to selected information but not necessarily the entire database. Similarly, an employee using an AI assistant may be authorized to retrieve documents from one business area but not another.

The objective is to make access more precise rather than simply more restrictive. Users, applications and workloads should have the access required to perform their role, without automatically gaining access to resources they do not need. As organizations connect AI to more systems and information, this principle of least privilege becomes an important part of maintaining control.

Security needs to follow the interaction

The access challenge also reflects the broader evolution of enterprise connectivity.

Users work from different locations, applications run across cloud and enterprise environments, and data moves between systems, partners and locations. AI workloads may operate across cloud, edge and on-premises infrastructure.

In this environment, network location alone provides limited information about whether an interaction should be trusted. Security therefore needs to take into account the identity involved, the resource being accessed and the context of the interaction.

This is also why networking and security are becoming more closely connected. Approaches such as Zero Trust Network Access (ZTNA) can help organizations establish access based on identity and context, while Secure Access Service Edge (SASE) architectures combine networking and security capabilities across distributed environments.

The underlying principle is straightforward: every connection should have a reason to exist, and the level of access behind it should reflect that reason.

This becomes even more important as AI moves from retrieving and processing information towards acting across enterprise systems. Organizations will increasingly need to manage not only which systems and data an AI application can access, but also what level of access it has – whether it can retrieve information, write or modify data, or trigger actions across other applications and systems. As AI systems become more capable of acting independently, organizations also need to decide how autonomously these actions can be performed and where human approval is required.

AI makes least privilege harder to manage

Applying least privilege becomes more challenging as enterprise environments change.

Employees move between roles, applications evolve, new data sources are connected and cloud environments expand. AI use cases that start as relatively isolated projects may eventually become integrated into business-critical processes.

Permissions can accumulate along the way.

An AI application initially connected to two systems may eventually interact with ten. A service designed to retrieve information may later become part of an automated workflow. Access that was appropriate when a project began may no longer be appropriate as its purpose changes.

This means access cannot simply be configured once and left unchanged. Organizations need visibility into which identities exist, which resources they can access and whether those permissions remain appropriate as their AI environment develops.

Food for thought: If one of your AI applications changed its role tomorrow, how quickly could you identify and adjust everything it is allowed to access?

When AI starts taking action

This question will become even more relevant as organizations begin using AI agents more widely.

Many enterprise AI applications today primarily help users find information, generate content, analyze data or support decisions. AI agents can go further by performing tasks across different systems, such as retrieving information, updating records, triggering workflows or interacting with other applications.

As a result, organizations need to consider not only what information an AI system is allowed to access and retrieve, but also which actions it is authorized to perform.

An AI system that can read a customer record requires one level of control. A system that can modify the record, initiate a transaction or trigger another business process requires a different level of authorization and oversight.

As AI takes on a more active role in business processes, organizations will need to consider identity, authorization and visibility not only for their employees and applications, but also for the AI systems acting on their behalf.

Questions leaders should ask

As AI becomes integrated into more business processes, technology and security leaders should consider:

  • Which users, applications, workloads and AI services can access our critical systems?
  • Do we have a centralized view of which human and machine identities have access to which systems, applications and data across the organization?
  • Which enterprise data sources are currently connected to AI applications?
  • Does each AI service have access only to the information it needs?
  • How are human and machine identities authenticated and authorized?
  • Can access rights change as roles, risks or business requirements change?
  • Can we see which identities are accessing sensitive resources across different environments?
  • What actions are AI applications permitted to perform, not only what information can they retrieve?
  • Could these controls scale if the number of AI applications and agents increased significantly?

The aim is to ensure that access remains intentional and manageable as AI becomes more deeply integrated into the business.

Building trust into enterprise AI

AI creates value by bringing together information, applications and business processes. As those connections grow, organizations need a more precise way to determine who and what can access their digital resources.

Zero Trust provides a useful architectural principle for this environment. Rather than assuming trust based on location or an existing connection, access is based on verified identity, context and the permissions required for a particular interaction.

As AI evolves from supporting employees with information to performing more tasks across enterprise systems, these principles become relevant not only to controlling what AI can access, but also what it can do.

The question is therefore not simply how much access AI needs. Organizations also need to determine what AI should be allowed to do with that access, while retaining the visibility and control required to change or remove those permissions when necessary.

Continue the conversation

As AI connects to more enterprise data, applications and business processes, managing identity and access becomes an important part of the infrastructure supporting it.

If you would like to discuss how Zero Trust, secure connectivity and access controls can support your AI strategy, our specialists are available to help.


Image: created with AI