Cyber Assurance
Essential Eight in the Age of AI Agents
AI agents run code, hold credentials and act on our behalf. Here is how the Essential Eight still applies — and where assessors should be looking harder.
The Essential Eight was written for a world of users, endpoints and servers. AI agents don’t fit neatly into any of those boxes. They execute code, call APIs, read mailboxes and — increasingly — hold privileged credentials. So does the framework still hold up?
Short answer: yes, but only if you apply it with intent.
Agents are just new principals
The most useful mental shift is to treat every AI agent as a non-human identity with a job description. Once you do, most of the Essential Eight maps across cleanly.
| Strategy | What it means for AI agents |
|---|---|
| Application control | Which tools, plugins and scripts can the agent execute? |
| Restrict admin privileges | Does the agent run with standing admin rights? It shouldn’t. |
| Multi-factor authentication | How are agent credentials protected, rotated and scoped? |
| Patch applications | Are agent frameworks, model runtimes and plugins in your patch cycle? |
| User application hardening | Are browsing and document-handling agents sandboxed? |
| Regular backups | Can you recover from an agent that deletes or corrupts data? |
Where I look harder as an assessor
1. Privilege creep
Agents are usually deployed by enthusiastic teams moving quickly. The fastest way to get a proof-of-concept working is to give it broad access — and that access rarely gets reviewed. Ask for the agent’s permission set and compare it with what it actually needs.
2. Application control blind spots
Many agents can generate and execute code at runtime. If your application control policy allows the agent’s interpreter to run arbitrary scripts, you’ve created a sanctioned bypass. Look for allowlisting at the tool level, not just the binary.
3. Credentials in the wrong places
API keys in prompt templates, environment variables shared across agents, tokens that never expire. Phishing-resistant MFA protects humans; for agents, the equivalent is short-lived, narrowly scoped, centrally managed credentials.
Maturity is still about evidence
Nothing about AI changes the core of a good assessment: show me the evidence. Policies that mention AI are a start. Logs showing what an agent did, under which identity, with what approval — that’s maturity.
An AI agent with admin rights and no logging isn’t innovation. It’s an unmanaged privileged account with a chat interface.
Practical next steps
- Add AI agents to your identity inventory as their own category.
- Extend privileged access reviews to cover agent service accounts.
- Include agent frameworks and plugins in vulnerability management.
- Make sure agent activity is logged centrally and retained.
The Essential Eight remains one of the most practical baselines we have. The organisations that will do well are the ones that treat AI as a new kind of user — and hold it to the same standard.
Frequently asked questions
Does the Essential Eight apply to AI agents?
Yes. The strategies apply to any principal that runs code or holds privileges. Treat each AI agent as a non-human identity and assess application control, admin privileges, MFA (or credential controls), patching and backups against it.
What maturity level should AI agents meet?
Agents should meet the same target maturity as the systems and data they can reach. If an agent can act on ML3-protected systems, its own identity, logging and privilege controls need to support that level.
How can I get an Essential Eight assessment that covers AI?
An assessment can explicitly include agent identities, tool permissions and logging in scope. Learn about government security assessments or talk to the AI agent to discuss your environment.