Where AI Breaks Traditional Data Governance

Most AI pilots start safely, since teams test with public documentation or data that’s already anonymized, so traditional access controls hold up fine. The problem shows up later, once agents need access to sensitive data to do real work, and that’s when most access models start to crack.

The instinct is to ask “what does this user have access to?” and extend that same logic to the agent acting on their behalf. But that’s the wrong question. An agent doesn’t need a copy of someone’s permissions, it needs access scoped to a specific task, for a specific reason, for as long as that task takes. Anything broader creates exposure that wasn’t there before.

The usual fallback is to try to handle this with traditional tools: more roles, more groups, more granular permissions for every possible scenario. In this video, Immuta Field CTO Paul Myres explains why that approach falls apart fast, and what actually has to change about how organizations think about access once agents enter the picture.