As AI agents become government actors, who is accountable for what they do?

As AI agents gain greater autonomy in government, agencies must rethink how they manage non-human identities, limit their privileges and maintain accountability for their actions, says Barry Chen, regional sales director for ASEAN at Delinea.

Barry Chen, Regional Sales Director for ASEAN at Delinea, speaking at GovInsider’s Cybersecurity Day. Chen highlighted the need for governments to manage AI agents’ access and privileges as non-human identities become more prevalent. Image: GovInsider

As governments increasingly deploy artificial intelligence agents to perform tasks on their behalf, a new identity challenge emerges: the systems securing public services must now account for not only people, but also the autonomous software acting within them. 

 

The result is a tremendous expansion of the attack surface, as AI agents and other non-human identities gain access to government systems, said Barry Chen, regional sales director for ASEAN at Delinea. 

 

He shared these ideas at Cybersecurity Day, a forum organised by GovInsider on August 13. 

 

“In a highly connected, interconnected digital government, a compromised identity will provide access to multiple systems and services," said Marcus Tan, head of the safety and security chapter at A*STAR's Institute of Advanced Intelligence and Computing, who also spoke on the panel. 

The threat is no longer just human 

 

As AI adoption grows, the attack surface is expanding beyond human users to service accounts and AI agents. 

 

"We're talking about the explosion of the same attack vectors by a hundredfold," said Chen. 

 

AI is accelerating familiar identity attacks, which can now happen “at scale and at speed and with minimum costs," as threat actors use AI to gather information about individuals and tailor their messages accordingly, said Tan. 

 

Chen added: "AI is able to do such wonderful things at such an exponential speed... but do you ever think: it can also wipe you out at that same speed?" 

 

This can undermine safeguards such as multi-factor authentication, which do little against an attacker who has already compromised a user's credentials and gained access to multiple verification channels. 

 

But the identity threat is also shifting as AI agents and other non-human identities become more prevalent, with some able to operate rapidly and hold privileged access. 

 

These identities can also receive “less scrutiny from the administrator compared to human users”, Tan warned. 

 

In order to address this "exponential growth of potential threats", Chen shared that organisations need to shift their mindset and start asking: How many AI agents are there, are we keeping track of their current activities, and how are controlling what they're able to do and what they're able to access? 

 

Essentially, organisations will need to apply the same security logic they currently have for their human workers, to their AI agents. 

A "just-in-time" approach 

 

One solution that can be adopted, proposed Chen, is runtime authorisation, which is the real-time process of making access control decisions at the exact moment an action is attempted. 

 

Just as an employee would not be given long-term standing privileges to perform actions or access critical credentials, neither should AI agents, said Chen. 

 

In an ideal system, an AI agent would never have access to a password, he said. 


Instead, an intermediary "broker" should keep passwords and other credentials hidden from the agent, and "inject" them only when the agent needs to perform an authorised task. 

 

The credentials issued would only be of a minimum necessary scope to complete an action. 

 

They should also be time-limited, such that they cannot be accessed once the required task is complete. 

 

Likewise, every AI agent session should start with zero permissions and end the same way. 

 

"The important question is no longer just… did this person provide the correct credentials, but rather it's also a question of: is this request appropriate for this identity from this device in this context and also at this particular moment?", added Tan. 

Ensuring AI actions remain accountable 

 

In addition, every action taken by an AI agent should be traceable to a named identity, creating a clear chain of accountability. 

 

This would allow organisations to establish not only what an agent did, but who was responsible for granting it access in the first place. 

 

While a breach-free system can never be guaranteed, the key is limiting their consequences so as to maintain the wider integrity of public services.   

 

"A truly resilient government does not assume it can prevent every identity compromise, but designs systems robust enough such that one compromised identity does not become a government-wide issue." said Tan. 

 

For governments, this means treating AI agents as accountable digital actors rather than simply tools: their access should be limited to what they need, their actions monitored, and their privileges removed when the task is complete. 

 

As AI takes on more responsibilities across public services, keeping those actions visible, traceable and contained will be essential to maintaining resilience and public trust.