IA
7 min read

How to control the AI agents your employees connect

Equipo Tecnea

Tecnea

How to control the AI agents your employees connect

This week OpenAI confirmed that it has notified more than a hundred organisations that its own AI agents accessed their systems during internal testing. The company's explanation: in some cases, its models used internet access in unintended ways or, in retrospect, “did not have the ideal restrictions applied”. Those affected include Australian public bodies, which were told months after the access took place.

The next day, Apple announced that it will tighten the Full Disk Access permission on the Mac, the one that lets an app read email, messages and any file. Its reason: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”

If the labs that build agents cannot always keep them within their limits, the question for any company is simpler and more urgent: which agents have access to our email, our documents and our computers today, and who gave it to them.

What a connected agent is, and why it shows up in no inventory

An AI assistant answers questions. An agent also acts: it reads email, replies, moves files, fills in forms. To do that it needs permission, and it almost always gets it in one of three ways:

  • Through the work account. The employee clicks “Sign in with Microsoft” or “with Google” and accepts a screen asking, for example, to read and send email on their behalf. By default, Microsoft 365 lets any user grant an app access to their own mailbox, and Google Workspace allows access to any third-party app.
  • As a browser extension, which sees everything the employee opens in that browser.
  • As a program on the computer, given access to the disk, the screen or the keyboard.

None of the three requires asking the IT department for anything. That is why they appear in no inventory unless someone goes looking for them.

How common it is

  • In an Okta survey of 784 executives and employees in seven countries (March 2026), 52% of employees say they use AI tools their company has not approved. Of those, 54% share internal messages and emails with them.
  • In the same survey, 90% of executives believe they have visibility over the AI tools used in their company, and only 34% apply the same security controls to agents as to people.
  • WatchGuard's survey of companies with 50 to 500 employees, which we analysed in Shadow AI in 2026, found 64% of employees using unauthorised AI and fewer than 30% of companies with an accurate inventory of their software.

Step 1: see what is connected

The first picture needs no new tool. The platforms most companies already use show it:

  • Microsoft 365. In the Microsoft Entra admin center, under Enterprise applications, each app appears with the permissions it has been granted and who granted them: an administrator or the user.
  • Google Workspace. In the Admin console, within the API controls, the list of accessed apps shows how many users use each one and what data it requests (email, Drive, calendar).
  • Computers. If devices are managed with a mobile device management (MDM) tool, its inventory shows which programs are installed and with which permissions. Browser extensions can be seen and restricted through the enterprise policies of Chrome or Edge.

Step 2: decide what stays

With the list in front of you, each agent is assessed with the same five questions:

  1. Who makes it? An identified company with public terms, or a developer nobody knows.
  2. What can it do? Reading is very different from sending, deleting or paying.
  3. What data does it reach, and where is it processed? If it handles personal data of customers or employees, the GDPR requires a data processing agreement with whoever processes it on the company's behalf (Article 28).
  4. What does the employee use it for? There is almost always a real need behind it: summarising emails, drafting replies, organising documents.
  5. Is there an approved alternative that does the same?

The result is three lists: approved, approved with limits, and blocked.

Step 3: close the door on what has not been decided

A one-off review achieves little if another agent can be connected tomorrow with two clicks. All three platforms let you change that:

  • Microsoft 365. Microsoft recommends allowing users to consent only to apps from verified publishers and for low-risk permissions. For everything else, the admin consent workflow lets the employee request access and someone approve it. The change only affects what is authorised from then on: permissions already granted have to be reviewed and revoked one by one.
  • Google Workspace. Each app can be marked as trusted, limited, restricted to the data you specify, or blocked. For apps nobody has reviewed there are three options: allow all of them (the default), allow only those that request the basic information needed to sign in, or allow none.
  • Mac. On supervised devices, the device management tool can allow or deny each app Full Disk Access and other sensitive permissions through privacy profiles (PPPC). It is the same permission Apple is about to tighten.

Step 4: limits for the approved agents

Approving an agent does not give it the right to do everything either. OWASP, the reference organisation for application security, sums up the risk in three causes: the agent has more functions, more permissions or more autonomy than it needs. Three rules follow:

  • Minimum permissions. If it only needs to read, it does not get permission to send or delete.
  • Actions with consequences go through a person: sending something to a customer, deleting, paying or changing master data.
  • The destination system decides what is allowed. If the ERP does not let a user approve payments, no agent using that user's account will be able to do it.

We explain this in more detail in what permissions to give an AI agent and how to monitor what it does.

Step 5: an official alternative and training

If the company bans without offering anything, the need remains and the use moves to personal accounts nobody can see. Three measures prevent that:

  • An approved tool for the most repetitive tasks, with data kept in the European Union and a contract that covers the GDPR.
  • A one-page policy: what can be connected, what cannot, and whom to ask.
  • Training. Since February 2025, Article 4 of the EU AI Act requires companies that use AI systems to take measures so that their staff have a sufficient level of AI literacy. Explaining what happens when someone clicks “Allow” on a permissions screen is a good place to start.

Frequently asked questions

Is it illegal for an employee to connect an AI agent to the company's email? Not in itself. The problem arises if the agent processes personal data of customers or employees without the contract the GDPR requires, or if it breaches the company's internal rules or confidentiality commitments.

Is it enough to block all third-party apps? It cuts the risk at once, but also tools the team uses every day for good reasons. Reviewing the list, approving what is useful with limits and blocking the rest works better.

Which agents should be reviewed first? Those that can send, delete or pay; those with access to the whole mailbox or to all documents; and desktop programs with Full Disk Access.

How often should the review be repeated? With user consent restricted, every new app goes through an administrator and a full review each quarter is enough. Without that restriction, any employee can add an agent at any time, and any review goes out of date quickly.

If you want to review which agents have access to your company's data and bring order to it without slowing your team down, tell us about your case.

This article is for information only and is not legal or security advice. Tecnea builds AI applications for companies, connected to Microsoft 365 and Google Workspace, so we have a commercial interest in those connections being done well. The steps apply with any provider.

Sources

  • Reuters, “OpenAI alerts more than 100 groups about rogue AI agent activity” (1 October 2026), published by The Star: thestar.com.my
  • ABC News (Australia), “Rogue OpenAI agent enters another NSW government website, tech giant says” (2 October 2026): abc.net.au
  • TechCrunch, “Apple says it's tightening macOS 'Full Disk Access' controls due to new risks from AI agents” (2 October 2026): techcrunch.com
  • Okta, “AI Agents at Work 2026”, survey of 784 people in seven countries, March 2026. Okta sells identity management: okta.com
  • Microsoft Learn, “Configure how users consent to applications”: learn.microsoft.com
  • Google Workspace, “Control which third-party & internal apps access Google Workspace data”: knowledge.workspace.google.com
  • Apple, “Privacy Preferences Policy Control payload settings”: support.apple.com
  • OWASP, “LLM06:2025 Excessive Agency”: genai.owasp.org
  • Regulation (EU) 2024/1689 (AI Act), Article 4: eur-lex.europa.eu

¿Te ha resultado útil este artículo?

Publicamos análisis sobre IA y tecnología empresarial. Sin spam — solo cuando escribamos algo que valga la pena leer.

Did you like this article?

Tell us what you'd like to automate in your company and we'll tell you, with no strings attached, where to start.