As Companies Go All In on AI, Who Controls What the Agents Can Access?

Companies are moving quickly to find ways artificial intelligence can make their employees more productive. But as AI evolves from a tool people use into agents capable of accessing information and performing work on their behalf, a new question is emerging: How much access should those agents have?

It’s a question Charles Canavan, a Solutions Architect at Kiteworks, believes companies need to start thinking about now.

Speaking with Developers.Net Co-Founder Emilio Baez at Ai4 2026 in Las Vegas, Canavan described Kiteworks as being “as close to all in as you can get” when it comes to embracing AI internally.

At the same time, the company’s presence at Ai4 centered on what could happen when AI agents are given access to sensitive company data without the proper controls in place.

“As you unleash these guys and be more productive, how are you securing and controlling that access?” Canavan said.

Kiteworks Is Embracing AI While Thinking About the Risks

For Canavan, the benefits of AI aren’t theoretical.

Kiteworks has adopted Claude internally, and Canavan said he is already using it throughout his work as a Solutions Architect.

“It helps me be more productive through my day-to-day,” Canavan said. “It helps me build architecture diagrams, it helps me analyze problem sets and provide solutions, and anything in between.”

Canavan told Baez that engineering, sales, finance and other areas of the company are being encouraged to determine how AI can improve their work. Employees are also sharing what they’ve learned with one another, including which approaches have worked and how others might adapt them.

“We trade skills internally,” Canavan said. “We swap skill stories. Did this work for you? Did it not work for you? Let me tweak this one for you.”

Canavan also said AI was being used within engineering to analyze code, double-check work before releases and assist in building new pieces of the Kiteworks product.

As companies begin relying on AI to do more than answer questions or generate content, those systems may also need access to the information required to complete the work. Deciding what an AI agent should be allowed to access and how that access is controlled creates another challenge.

When AI Needs Access to Do the Work

An employee using AI to help analyze a problem is one thing. An AI agent capable of performing tasks on that employee’s behalf may need access to the files, systems and information required to complete them.

That creates a different kind of security challenge.

Kiteworks used its Ai4 booth to illustrate what that challenge could look like.

The company partnered with Orlando-based immersive design studio OtherVRse to create “Evil Breach 2,” a virtual reality experience that placed conference attendees inside a fictional cybersecurity breach involving AI agents, sensitive information and excessive permissions.

Behind the theatrical experience was the same question Canavan raised with Baez: What happens when increasingly capable AI systems are given access to sensitive information?

Kiteworks’ activity since Ai4 provides additional context for where the company believes that question is heading.

On August 20th, Kiteworks announced an expansion of its Data Control Plane with Agent and Human Error Prevention. The company described a broader approach to governing sensitive data as it moves between people, applications and AI agents, applying policies to both human and agent interactions.

Companies have spent decades developing rules governing what employees can access and what they can do with sensitive information. Now that AI agents are starting to become participants in those same workflows, organizations increasingly have to decide what an agent should be allowed to access, what actions it should be permitted to take and what happens to the information once the agent begins working with it.

Kiteworks Chief Strategy Officer Tim Freestone further articulated that position later in August while discussing the company’s agentic AI technology ahead of AI Governance World in Las Vegas.

“Governing data at rest is no longer enough,” Freestone said.

Kiteworks’ position is that controls need to follow sensitive information as AI agents request, use and share it.

In other words, securing where information lives is only part of the problem. Companies also need to control what happens when an AI agent is allowed to interact with it.

Going All In Without Giving Up Control

Kiteworks isn’t advocating against aggressive AI adoption. Internally, Canavan described an organization actively encouraging employees to experiment with the technology and find ways to incorporate it into their work.

As companies move beyond employees prompting AI models and toward agents capable of completing increasingly complex tasks, Kiteworks recognizes those agents will need permissions to do useful work.

The question becomes how much permission they should receive.

Canavan described the emergence of AI as a “terrifyingly exciting proposition,” a phrase that captures both sides of the challenge.

There is enormous potential in giving people systems capable of helping them analyze information, write code, solve problems and eventually carry out increasingly complex work.

But those capabilities also mean organizations have another participant interacting with their information.

Developers.Net attends technology conferences across the country, every month, connecting with the people scaling their business while building and implementing emerging technology. To connect with our team at an upcoming conference, email [email protected]