Cyber Assurance

Essential Eight in the Age of AI Agents

AI agents run code, hold credentials and act on our behalf. Here is how the Essential Eight still applies — and where assessors should be looking harder.

Muhammad Anwar
· 3 min read

The Essential Eight was written for a world of users, endpoints and servers. AI agents don’t fit neatly into any of those boxes. They execute code, call APIs, read mailboxes and — increasingly — hold privileged credentials. So does the framework still hold up?

Short answer: yes, but only if you apply it with intent.

Agents are just new principals

The most useful mental shift is to treat every AI agent as a non-human identity with a job description. Once you do, most of the Essential Eight maps across cleanly.

StrategyWhat it means for AI agents
Application controlWhich tools, plugins and scripts can the agent execute?
Restrict admin privilegesDoes the agent run with standing admin rights? It shouldn’t.
Multi-factor authenticationHow are agent credentials protected, rotated and scoped?
Patch applicationsAre agent frameworks, model runtimes and plugins in your patch cycle?
User application hardeningAre browsing and document-handling agents sandboxed?
Regular backupsCan you recover from an agent that deletes or corrupts data?

Where I look harder as an assessor

1. Privilege creep

Agents are usually deployed by enthusiastic teams moving quickly. The fastest way to get a proof-of-concept working is to give it broad access — and that access rarely gets reviewed. Ask for the agent’s permission set and compare it with what it actually needs.

2. Application control blind spots

Many agents can generate and execute code at runtime. If your application control policy allows the agent’s interpreter to run arbitrary scripts, you’ve created a sanctioned bypass. Look for allowlisting at the tool level, not just the binary.

3. Credentials in the wrong places

API keys in prompt templates, environment variables shared across agents, tokens that never expire. Phishing-resistant MFA protects humans; for agents, the equivalent is short-lived, narrowly scoped, centrally managed credentials.

Maturity is still about evidence

Nothing about AI changes the core of a good assessment: show me the evidence. Policies that mention AI are a start. Logs showing what an agent did, under which identity, with what approval — that’s maturity.

An AI agent with admin rights and no logging isn’t innovation. It’s an unmanaged privileged account with a chat interface.

Practical next steps

  • Add AI agents to your identity inventory as their own category.
  • Extend privileged access reviews to cover agent service accounts.
  • Include agent frameworks and plugins in vulnerability management.
  • Make sure agent activity is logged centrally and retained.

The Essential Eight remains one of the most practical baselines we have. The organisations that will do well are the ones that treat AI as a new kind of user — and hold it to the same standard.

Frequently asked questions

Does the Essential Eight apply to AI agents?

Yes. The strategies apply to any principal that runs code or holds privileges. Treat each AI agent as a non-human identity and assess application control, admin privileges, MFA (or credential controls), patching and backups against it.

What maturity level should AI agents meet?

Agents should meet the same target maturity as the systems and data they can reach. If an agent can act on ML3-protected systems, its own identity, logging and privilege controls need to support that level.

How can I get an Essential Eight assessment that covers AI?

An assessment can explicitly include agent identities, tool permissions and logging in scope. Learn about government security assessments or talk to the AI agent to discuss your environment.

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader specialising in the ISM, PSPF, NIST SP 800-53, SOCI Act and AI governance (ISO 42001). Views are my own.