security
May 27, 2026
By Teun
Microsoft pushes tools to track and govern AI agents
Microsoft is adding security and governance features for AI agents as enterprises deploy more AI tools and connectors. PwC says the goal is to help companies move quickly without accumulating new security risks, or “AI security debt.”
Each new AI model, connector, and agent can expand access, expose sensitive data, and create new attack paths. That risk is becoming harder to manage as companies roll out AI tools faster than security frameworks and controls can keep up, according to PwC and Microsoft.
Vimal Navis, principal with PwC focused on cyber, data and tech risk, said AI has moved from single-modal foundation models to multimodal, reasoning, and agentic systems. “Industry frameworks, standards, and cybersecurity controls are taking time to catch up,” Navis said. “The gap becomes debt.”
That “debt” is what PwC and Microsoft are calling AI security debt: the risks that accumulate when organizations adopt AI quickly but do not fully track what was deployed, what it can access, and who is responsible for it. The problem can show up both in approved tools and in shadow AI, where employees use AI apps or agents without IT approval.
Navis said the issue is not limited to standalone tools. New AI features are also being added inside existing business software, such as chatbots or query engines in a CRM system, or connectors to external applications. Those features may improve productivity, but they can also open up new ways to move data or trigger actions that security teams were not expecting.
Microsoft is now treating AI agents more like enterprise assets that can be inventoried, governed, and monitored. With Agent 365, IT teams can see registered agents that interact with an organization’s Microsoft stack and set policies for who can create, onboard, and manage them.
Microsoft said Agent 365 works with Microsoft Defender to help organizations observe, secure, and govern AI agents across the enterprise. According to Microsoft, the tools can help detect suspicious or malicious agent activity, map possible attack paths from agents to critical assets, and support remediation of misconfigurations, exposure risks, and related vulnerabilities.
Microsoft Purview is also part of the stack. The company said it can identify incorrect or excessive permissions on sensitive data and apply stricter controls. Purview DLP, or data loss prevention, can help stop sensitive information from leaking through prompts, chat histories, connectors, and retrieval paths.
Microsoft Entra now includes identity and network access controls for AI agents as well, aimed at applying zero trust principles to non-human actors. Zero trust is a security model that assumes no user or system should be trusted by default and requires verification before access is granted.
Microsoft Defender for Cloud Apps can also help govern agent-related SaaS and genAI usage. According to Microsoft, it can discover shadow AI apps, assess risk, control unsanctioned apps, govern OAuth access, and apply real-time session and data protection controls.
PwC, a Microsoft Agent 365 launch partner, says it is helping companies assess the threat field and identify where AI security debt is building fastest. Navis said PwC helps translate requirements into controls that align with Microsoft’s expanding capabilities, while keeping innovation moving.
The companies’ message is that AI adoption is no longer just a deployment question. It is also a governance and security tracking problem, especially as more agents and connectors are added to enterprise systems.