Artificial intelligence guardrails have become a major focus for organisations deploying large language models (LLMs). They are designed to stop models producing harmful content, leaking sensitive information or following malicious instructions.

Artificial intelligence guardrails have become a major focus for organisations deploying large language models (LLMs). They are designed to stop models producing harmful content, leaking sensitive information or following malicious instructions.
As AI agents become more autonomous, however, the conversation is beginning to shift.
Unlike traditional chatbots, AI agents are increasingly being given access to email accounts, collaboration platforms, customer records and internal applications so they can complete tasks on a user’s behalf. That access also creates new opportunities for attackers.
Recent research has highlighted how prompt injection attacks can manipulate AI agents through malicious emails, documents or web pages. Instead of exploiting software vulnerabilities, attackers attempt to influence the agent into carrying out actions it should never perform, from exposing sensitive information to interacting with unauthorised systems.
The challenge is that these attacks target the agent’s decision-making rather than the underlying model. While guardrails remain important, they cannot compensate for excessive permissions or weak identity controls.
Security teams are therefore starting to treat AI agents like any other privileged identity. That means limiting access to only the systems an agent genuinely needs, monitoring its activity and ensuring every action can be traced back and audited.
The issue extends beyond prompt injection. As organisations deploy more AI-powered assistants across the business, managing non-human identities is becoming part of the wider identity governance conversation. Analysts have already warned that machine identities are growing much faster than human ones, and AI agents are likely to accelerate that trend.
For CISOs, securing AI is becoming less about the model itself and more about how those agents interact with the rest of the organisation. As AI gains access to more business systems, identity management is likely to become one of the most important controls for reducing risk.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543