AI agents at your vendor: 10 questions to ask
A supplier's AI agent that can read your data, send messages or change records is acting with access you granted to the supplier. These are the questions that tell you whether it's under control.
- Do you use AI agents (software that takes actions, not just answers) that can access, process or act on our data or systems? Which, and for what?
Why: Agents act with real access, so each one needs limits we can see. - Does a named person approve agent actions that affect our data or systems (sending, changing, deleting, paying) before they take effect?
Why: Human approval stops one wrong or manipulated instruction from becoming an action. - Can you stop an agent immediately and revoke its access (a kill switch)? Who can do it, and how fast?
Why: An agent behaving unexpectedly must be stoppable at once. - Is every agent action on our data logged with the agent's identity, and will you give us those logs on request?
Why: Logs are how an incident involving our data gets investigated. - Does each agent have its own identity and only the permissions its task needs, reviewed at least quarterly?
Why: Shared or over-privileged agent credentials widen the damage of a mistake. - Do agents hold credentials to our systems? If so, which scopes, where are they stored, and how often are they rotated?
Why: Credentials to our systems held by a vendor's agent are our risk. - How do you protect agents from prompt injection in content they read (emails, documents, web pages, tickets)?
Why: Instructions hidden in content are the main way agents are manipulated. - Are agents tested before release, and after changes, for prompt injection, data leakage and actions outside their purpose?
Why: Testing catches unsafe behaviour before it reaches our data. - Will you tell us before introducing agents that act on our data, or widening what they can do?
Why: We need to assess new agent access before it happens. - How quickly will you notify us of an incident involving an AI agent and our data?
Why: Sets the clock for our own incident response and notifications.
Answers to worry about
- Agents act on our data or systems without human approval.
- No way to stop an agent and revoke its access at once.
- Agent actions on our data are not logged or not available to us.
- Agents share identities or hold more access than their task needs.
- Agents are not tested for prompt injection or data leakage.
- No notice before agents start acting on our data.