None
EN
The First Federal Guidance on AI Agents Is Here. Most Agencies Can’t Meet It Yet.
['Meritalk Staff']
MeriTalk
Its core instruction: before granting an AI agent access to data or systems, know exactly what that agent can reach, and revisit that inventory as its footprint changes.
In August 2025, attackers stole OAuth tokens belonging to Drift, an AI sales chat agent built by Salesloft and connected into customer Salesforce instances.
Those tokens carried the same broad, rarely revisited access Drift used for its own workflows.
Yet 78 percent agree that AI agents and tools should be treated as managed entities within a zero trust environment, not exceptions to it.
Agencies now have federal guidance telling them to ask what their agents can reach before the next incident forces the question.