Partner Spotlight
Georgy Ovanesyan
Chief Executive Officer
Axidian
The Service Account Did It – Three Questions Your AI Agent Must Answer
An AI agent updates a supplier’s payment details. Later, someone asks what happened. The business application has one answer: a service account made the change.
That is not an answer. It does not say who requested it, which agent interpreted the instruction, or whether the action stayed inside its approved authority.
Most organizations cannot say how many AI agents have access to their systems. Every one of them can act.
Saudi Arabia has already set out what good looks like. In July 2026 the National Cybersecurity Authority opened its draft AI Cybersecurity Guidelines (AICG-1:2026) for public consultation — four domains, fifteen subdomains and forty-two guidelines covering generative and agentic AI. They are recommended practice rather than mandatory controls, but NCA advises every entity adopting AI to apply them.
Preparing does not require a new compliance programme. Three questions cover most of it.
Who is acting?
Every agent needs an identifiable owner and a defined purpose, and its actions must connect back to the person or approved process that initiated them. AICG asks for an inventory of all AI system components with defined owners and lifecycle status (2-1-1, 2-1-2), and for agent actions to be classified by impact, likelihood and reversibility (1-1-2).
What is it allowed to do?
An agent reaches corporate systems through service accounts, API tokens or other machine credentials. AICG asks for role-based permissions defined explicitly for human users, service accounts and AI agents alike, under least privilege and segregation of duties (2-2-1), and for periodic review of the identities, access rights, tokens and service accounts those systems use (2-2-2).
What did it do?
The organization must be able to reconstruct which systems, data and tools the agent reached, what it did and what resulted. AICG asks for logging of authentication and access events, privileged actions, data access, prompt configuration changes and tool invocations (2-8-1), and of AI-initiated actions affecting confidentiality, integrity or availability (2-8-2).
Together these create a traceable chain connecting identity, permission and action — and make graduated autonomy under continuous human oversight (1-2-7) enforceable rather than aspirational.
Start now. Take one high-impact agent and trace a single action from instruction to outcome.
Can you name the initiator, the agent, the credential, the permissions it used and the result it produced?
If the only answer is a service account, the work starts there.