Cyber Security Information Security

BigID Extends Data Access Governance to AI Agents

Cyber Security  /  Information Security  |  5 min read


BigID has announced the expansion of its Data Access Governance (DAG) capabilities to cover AI agents — the autonomous, non-human entities now operating inside enterprise environments with broad data access and little oversight. As agentic AI moves from emerging consideration to everyday enterprise reality, BigID argues that the next wave of insider risk is not human: it is the agents organisations deployed to help them, operating without visibility or guardrails, at machine speed, continuously, and across systems that cross organisational boundaries.

"Access governance has always focused on people. Identity governance was built for humans, and agents aren't humans. They don't log off, don't forget, and don't stop when something looks wrong. They operate at a scale and speed that makes traditional review cycles irrelevant. BigID extends the same data-centric governance model we apply to humans directly to agents."

— Nimrod Vax, Chief Product Officer and Co-Founder, BigID

Why Existing Governance Frameworks Fall Short

Agentic AI is already operating in enterprise environments — browsing internal systems, retrieving sensitive records, writing to databases, and acting on behalf of users — often with permissions that were set months ago, never reviewed, and scoped far too broadly. Most enterprise governance frameworks were designed for human employees, not for entities that never log off, never hesitate, and operate across systems continuously at machine speed. BigID's position is direct: other vendors are retrofitting human IAM tools to handle agents. BigID governs agents at the data layer — understanding not just who accessed what, but what that data is and whether that access should have happened at all.

Three New Capabilities for AI Agent Governance

  • Agent Identity Discovery and Mapping — BigID automatically discovers AI agents operating in the environment, cataloguing the data stores they access, the permissions they hold, the systems they touch, and the scope of their activity. If an agent is interacting with organisational data, BigID knows about it
  • Access Right-Sizing for Non-Human Identities — applies least-privilege principles to AI agents the same way they are applied to human users. BigID compares provisioned access against actual access behaviour and surfaces remediation paths for over-permissioned agents before a misconfiguration creates an incident
  • Real-Time Agent Activity Monitoring — continuous monitoring of agent data access, surfacing anomalous behaviour, unauthorised data movements, and policy violations with full classification context — providing the audit trail that most agent deployments currently lack entirely

The Broader AI Governance Challenge: Employee AI Use Too

The AI agent governance announcement accompanies a related BigID announcement for a broader integrated AI governance solution covering employee AI use — combining Data Loss Prevention (DLP), Data Access Governance, and Data Activity Monitoring in a single platform. Employees are using Copilot, ChatGPT, and dozens of embedded AI tools every day, with sensitive files pasted into AI interfaces, PII flowing into tools never scoped to handle it, and regulated data reaching AI systems with no audit trail. Most organisations know their employees are using AI. Almost none know what data it is touching.

"Most teams know their employees are using AI. Almost none know what data it is touching. BigID gives security teams the visibility and control to govern employee AI use at the data layer, where the exposure actually happens."

— Dimitri Sirota, CEO and Co-Founder, BigID

BigID will be showcasing its full AI and data security capabilities at RSA Conference 2026 at Booth N-4427, with live demos and exclusive previews available. The company has been recognised as a World Economic Forum Technology Pioneer, named to the Forbes Cloud 100, and is a Market Leader in Data Security Posture Management (DSPM) and an RSA Innovation Sandbox winner.

Key Takeaways

  • BigID has expanded its Data Access Governance (DAG) capabilities to cover AI agents — the autonomous, non-human entities now operating at machine speed inside enterprise environments, often with over-broad, never-reviewed permissions.
  • Three new capabilities: Agent Identity Discovery and Mapping, Access Right-Sizing for Non-Human Identities (least-privilege for agents), and Real-Time Agent Activity Monitoring with full data classification context.
  • BigID governs agents at the data layer — not the identity/IAM layer — understanding not just who accessed what, but what that data is and whether that access should have happened at all.
  • A companion integrated AI governance announcement combines DLP, DAG, and Data Activity Monitoring to govern employee AI tool use (Copilot, ChatGPT, embedded AI tools) — stopping sensitive data from reaching AI interfaces without oversight.
  • BigID will be demonstrating these capabilities live at RSA Conference 2026 (Booth N-4427). The company is a WEF Technology Pioneer, Forbes Cloud 100 member, and DSPM Market Leader.
Tags: AI News Cybersecurity AI Governance Data Security AI Tech Trends Agentic AI