AI agent identity, access and institutional authority
Instrument
Information Security Manual (ISM): Guidelines for system access, including expectations relevant to AI agents (identity, inventory and ownership themes described on the primary page).
Type and status
Cyber security guidance published by ASD. ISM controls express security policy for applicable systems; they are not a substitute for administrative law, sector regulation or organisational authority frameworks.
Applicability and dates
Relevant where your security policy adopts ISM controls for system access and automated or agentic execution. Map individual control statements from the current ISM release rather than relying on this summary.
Practical institutional implications
The ISM system-access guidelines state that security controls for identifying, authenticating, authorising and monitoring users also apply to non-human users such as services, applications, workloads and AI agents. Relevant themes include:
- ISM-2133: each AI agent is assigned a unique identity distinct from personnel accounts and other AI agents;
- ISM-2134: an AI agent register is developed, implemented, maintained and regularly verified;
- ISM guidelines narrative (2133 section): where an agent has multiple identities across environments or platforms, those identities should be recorded in the organisation's AI agent register, and agent identities should be managed similarly to service accounts;
- applying established access, logging and accountability disciplines rather than sharing human credentials opaquely.
These measures reduce ungoverned execution risk. They do not answer whether a particular action was authorised for the institutional purpose, on the evidence required, with accountable human judgement where discretion applies.
DataMPowered interpretation
DataMPowered separates identity, access, entitlement and authority. An authenticated agent may reach a system without permission to perform a specific institutional act. Governance of AI-supported work therefore complements cyber controls: establish legitimate purpose, applicable rules, establishment of facts, decision rights and accountable outcomes. See AI Governance & Assurance for how model and technology assurance relate to assurance of institutional work.
Primary sources
Read the ISM system-access guidelines directly and trace each cited control in context. Do not treat voluntary security guidance as a statutory logging or accountability obligation.
Related reading
- Is AI easier to weaponise than to institutionalise? discusses agent identity and institutionalisation asymmetry.
