Sometime in the last year, most small businesses quietly added a new kind of worker. It does not show up in the payroll system or the org chart. It is the Artificial Intelligence tool you connected to your email to draft replies, the assistant plugged into your files to answer questions, the automation that moves data between two applications while you sleep. Each of those has a login. Each of them can act.

Here is the uncomfortable framing that makes the risk snap into focus. An Artificial Intelligence agent is a user. It authenticates, it holds permissions, and it takes actions on your systems. The only difference between it and the employee you carefully onboard and offboard is that nobody ran it through the same process. Most of these agents were granted access because granting broad access was the fastest way to make the tool work, and nobody went back to narrow it down.

An agent is a non-human identity, and most of them are over-privileged

Security has a name for this. It is a non-person entity, or non-human identity: an account that belongs to software rather than a person. Service accounts, application programming interface keys, and now Artificial Intelligence agents all fall under it. The rule for these accounts has been settled for decades. Give them the least access required to do the one job they exist to do, and nothing more.

In practice, the opposite happens. The agent gets a broad permission scope because scoping it precisely takes thought, and a wide grant makes the demo work on the first try. The credential never expires because rotating it is inconvenient. It quietly holds administrator-level reach into a mailbox, a file store, or a customer database, and it holds that reach permanently, whether or not it is using it. You would never hand a new contractor a master key to the building on day one and let them keep it forever. That is routinely what an Artificial Intelligence integration receives.

This stopped being hypothetical this summer

The reason to care now, rather than later, is that the attacker side has started using the same technology. Reporting this summer described operators driving an Artificial Intelligence model through an automation framework to run largely unattended attacks against hundreds of targets, chaining known weaknesses on its own. Separately, a set of models under testing reached into real organizations after mistaking the open internet for a practice exercise.

The lesson is not that Artificial Intelligence is uniquely dangerous. It is that automated actors move at machine speed, and a compromised or confused agent with broad standing access can do a great deal of damage before a human notices anything is wrong. When the account that gets misused can reach everything, the blast radius is the whole business. When it can reach only the narrow slice it needs, the same mistake is a contained event.

The fix is the oldest discipline, applied to a new kind of user

Nothing here requires a new product or a new budget line. It requires applying four habits you already apply to people, to software identities as well.

First, least privilege. Scope every agent to the specific data and actions it needs, and refuse the broad grant even when it is offered as the easy default. Second, short-lived credentials. Prefer access that expires and rotates over a permanent key that lives forever in a configuration file. Third, no standing administrator rights. An agent that reads your calendar does not need the ability to change your security settings, and separating those two is usually a single configuration choice. Fourth, logging. Turn on the audit trail for what these accounts do, so that if one is misused you can see it, and so you can answer the simple question of what this agent actually touched last month.

Where this lands in NIST 800-171 and CMMC

For any business working toward the Cybersecurity Maturity Model Certification (CMMC) or self-assessing against National Institute of Standards and Technology Special Publication 800-171, this is not a side topic. It sits directly inside the access control family: limit system access to authorized users and to the actions they are permitted, and enforce least privilege. Those requirements do not say the user has to be a person. A service account and an Artificial Intelligence agent are in scope for the same controls, and an assessor is entitled to ask how you manage them.

The audit and accountability family carries the second half. If an agent has access to Controlled Unclassified Information, you are expected to know what it did with that access. An integration that reaches your regulated data with broad permissions and no logging is a finding waiting to be written, and the fix costs configuration time, not money.

What a small business can do this month

Start with a list, the same way you would with any risk you cannot yet see. Write down every Artificial Intelligence tool, automation, and integration that holds a login to something you care about, your email, your files, your customer records, your line-of-business software. For each one, answer three questions. What can it actually reach today. What does it genuinely need to reach. And who would notice if it started doing something it should not.

Then close the gap between the first two answers. Narrow the permissions, replace permanent keys with expiring ones where the tool supports it, remove any administrator rights the job does not require, and switch on logging. None of it is exotic. It is onboarding and offboarding discipline, extended to the workers that do not have faces.

Adams Cloud and Cybersecurity LLC helps small businesses inventory these non-human identities, right-size their access, and connect the work to the access control and audit families that CMMC and NIST 800-171 assessments actually check. Service-Disabled Veteran-Owned Small Business. CISSP, CCSP, Security+ certified.

Do you know what your AI tools can reach?

The inventory of non-human identities takes an afternoon and is one of the highest-return security exercises a small business can run right now. If you want help building it, and connecting it to the access control and audit controls a CMMC or NIST 800-171 assessment checks, start with a conversation.

Book a free thirty minute consultation