Box: AI Agent Security Needs More Than Just Permissions
Traditional permission systems are insufficient for governing AI agent behavior, necessitating new, behavior-focused security mechanisms.

Enterprise AI agent security must evolve beyond traditional permission systems to a broader model that governs behavior, according to Box Chief Information Security Officer Heather Ceylan.
AI agents operate differently than humans. While permissions define what an agent can access, they do not constrain its actions once it begins working autonomously. An autonomous agent can quickly turn legitimate access to enterprise data into unintended actions, creating significant security risks.
"Access controls and permissions are the foundation, but the challenge is they were designed for humans," Ceylan explains. "Permissions need to change based on what the agent has been asked to do and when it needs to take that action." She emphasizes that if an agent is performing a task and only needs certain tools, its permissions should be scoped to just those.
Box proposes a three-tier model for approving AI actions: fully autonomous actions, monitored actions, and high-risk actions requiring human approval. This helps manage risks and ensures agent actions remain within defined boundaries. Legacy content platforms are also not ready for AI agents' demands, with insufficient metadata and logs.