Govern the AI agent as the identity it is
AI agents are non-human identities. They hold credentials, carry permissions, and act on systems around the clock, usually with standing access nobody reviews. The Salesloft Drift breach reached more than 700 organizations through exactly that kind of over-scoped, non-expiring token, with no prompt injection involved. The controls already exist: inventory every agent, scope it to least privilege, expire its access, review it on a schedule, and detect when it's abused.