AI agents keep access to company data after their work is done - Help Net Security
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap.

DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software developers and their coding agents that can write, modify, and execute code on their behalf.
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap.
They also reported or suspected that an AI tool or agent had accessed sensitive data beyond what its task required in the past year.
Respondents often reported taking a day or longer to detect the most recent instance of an AI tool or agent accessing data outside its intended scope.
Most employees know formal approval is required to access company data, applications or systems through AI tools.
This ongoing access allows tools to continue reaching company systems and data until permissions expire or someone revokes them.
Fifty-seven percent said policies were documented and enforced well enough for them to understand what data AI tools were permitted to access.
The risk is real, as the recent OpenAI and Hugging Face incident showed, where AI agents were able to access and exploit external systems during testing,” said Ofer Rotberg , VP Product of DeepKeep.
Destructive commands are flagged and sent for human approval before they run, and teams can set custom key-phrase detection to flag sensitive code sections or internal repositories by name.
Hooks built into the coding agent intercept prompts, shell commands, file reads, and MCP tool calls before and after they run, and route each one to DeepKeep’s system for an allow, block, or audit decision.
What happened
DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software developers and their coding agents that can write, modify, and execute code on their behalf.
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap.
What changed
They also reported or suspected that an AI tool or agent had accessed sensitive data beyond what its task required in the past year.
Respondents often reported taking a day or longer to detect the most recent instance of an AI tool or agent accessing data outside its intended scope.
Who is affected
Most employees know formal approval is required to access company data, applications or systems through AI tools.
This ongoing access allows tools to continue reaching company systems and data until permissions expire or someone revokes them.
Why it matters
Fifty-seven percent said policies were documented and enforced well enough for them to understand what data AI tools were permitted to access.
The risk is real, as the recent OpenAI and Hugging Face incident showed, where AI agents were able to access and exploit external systems during testing,” said Ofer Rotberg , VP Product of DeepKeep.
Technical details
Destructive commands are flagged and sent for human approval before they run, and teams can set custom key-phrase detection to flag sensitive code sections or internal repositories by name.
Hooks built into the coding agent intercept prompts, shell commands, file reads, and MCP tool calls before and after they run, and route each one to DeepKeep’s system for an allow, block, or audit decision.
Companies give AI agents permissions that remain active after their work ends.
Response
RadarFirst has announced the general availability of Radar AI Incident Management, a purpose-built solution that helps organizations investigate, manage, and document AI-related incidents .
About 51% of organizations check AI access against policy in real time, and fewer than one in five detected the most recent instance of access outside an agent’s intended scope as it happened.
What security teams should do
DeepKeep’s AI Lens for Developers deploys guardrails and full-time monitoring that target how developers actually work, tracking and filtering what developers and their agents are doing.
Security teams must monitor every agent action and block harmful behaviour in real time, instead of sitting and waiting for the next incident.” AI Lens for Developers supports Cursor and Claude Code today, with GitHub Copilot, OpenAI Codex, Lovable, Windsurf, and more coming soon.
Attribution
Help Net Security: IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap.
Help Net Security: DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software developers and their coding agents that can write, modify, and execute code on their behalf.
Help Net Security: RadarFirst has announced the general availability of Radar AI Incident Management, a purpose-built solution that helps organizations investigate, manage, and document AI-related incidents .