What to do first when you get 90 days to secure AI agent data

What to do first when you get 90 days to secure AI agent data
AI agents create exposure by widening access to enterprise data paths, especially when they can rapidly retrieve and combine sensitive information from systems like ticketing platforms, CRM tools, shared drives, and chat history. Kelly Herrell of Nol8 recommends enforcing deterministic policy in the data path so organizations can control what data enters, leaves, and is disclosed by agents. #Nol8 #AIDataPlane #Salesforce #Jira

Keypoints

  • Focus on the data path, not just the list of deployed agents.
  • Ticketing systems, CRM platforms, and shared drives can expose years of sensitive context.
  • AI removes the friction that once limited how quickly data could be assembled and moved.
  • Start with visibility and runtime enforcement before attempting large-scale redesigns.
  • Apply policy to the data in transit so sensitive fields can be redacted or blocked per agent and role.

Read More: https://www.helpnetsecurity.com/2026/09/24/kelly-herrell-nol8-ai-agent-data-security/