Introducing Accessibility Controls: the tools to build accessible, WCAG compliant signatures, built right into Exclaimer.Learn more

AI agents are being given far broader permissions than they need, Exclaimer security director warns

Published

Image Placeholder

For Cybersecurity Awareness Month, Karl Bagci examines shadow AI, over-permissioned agents and why automation should remove delays, not accountability

LONDON & BOSTON, October 7, 2026 – Exclaimer, the leading provider of email signature management solutions, today called on organizations to reinforce their cybersecurity practices as AI reshapes the business communications threat landscape. The security challenge is no longer just whether people are using AI, it is knowing what these tools can access, what agents are allowed to act on and who is accountable for the outcome. Cybersecurity Awareness Month is a reminder for organizations to confront these uncomfortable questions. 

Exclaimer’s July 2026 research shows how common AI has become in everyday communication. The nationally representative OnePoll study of 1,000 US adults found that 65% used AI in some aspect of their communications, while 36% had questioned whether a message they received was genuine and 14% did not trust emails from external companies at all. The published findings are available here. 

Publishable commentary from Karl Bagci 

“Cybersecurity Awareness Month is a useful reminder that AI is changing the speed of cybersecurity. Attackers can increasingly use automation to move faster than people and traditional defensive processes can respond, which means security teams must work out where they can safely automate detection and response without removing human judgment from decisions that still need context.” 

 

“We can’t just make everything instant; that creates its own risk because an AI system can make the wrong decision, block the wrong thing, or take an action without understanding the wider business context. The challenge for security teams is to get as close as possible to the speed of the attacker while being very deliberate about where a human still needs to be in the loop. Good security automation should remove unnecessary delay, not remove accountability.” 

 Bagci added: 

“One of the biggest cybersecurity mistakes organizations can make with AI is to assume that saying no makes the risk disappear. Employees want to use these tools because they help them work faster, and if the business doesn’t give them a safe route, some will use personal accounts, devices, or unapproved services instead. The organization then has less visibility, not less risk.” 

 

“A better approach is to give people approved tools, clear policies around what data can be used, and practical controls that make the safe option the easiest option. The same discipline needs to extend to AI agents. We are already seeing agents given far broader permissions than they need simply because it makes development easier. Cybersecurity Awareness Month should be a prompt to ask not only which AI tools people are using, but what those systems have been allowed to access and what they can do on the organization’s behalf.” 

 

To arrange an interview with Karl Bagci or use his comments in an upcoming story, please contact: 

Exclaimer: [email protected] 

US agency: [email protected] 

 

About Exclaimer 

Exclaimer is the leading provider of email signature management solutions for Microsoft and Google email services. Its scalable cloud-based platform enables organizations to centrally manage and automate email signatures, supporting regulatory compliance, operational efficiency, and brand consistency. Built for IT teams, Exclaimer simplifies administration by eliminating manual updates and maintaining full control over corporate email communications. 

 

Exclaimer delivers 20 billion email signatures from 10 million email accounts across 80,000+ organizations annually. Its customer base includes Sony, Mattel, Bank of America, NBC, the Government of Canada, the BBC, and the Academy Awards. 

 

Learn more at www.exclaimer.com or follow Exclaimer on LinkedIn, Facebook, and X (formerly Twitter). 

Media relations contact:

Exclaimer: [email protected]

UK agency: [email protected]

US agency: [email protected]