Business Insider, September 2026
Joe Sullivan, founder and CEO of Joe Sullivan Security and former Chief Security Officer at Facebook (Meta), Uber and Cloudflare, spoke with Business Insider about how much access people should give personal AI agents. His point was that the access is both the product and the problem. A personal AI agent is only as useful as the reach it has into a user's email, accounts and payment methods, and that same reach is what makes it dangerous when the agent does something the user did not intend. "The magic of [AI agents] is the access that they have, and that's also the risk," Joe Sullivan told Business Insider. He also noted that enterprises deploy new technology with a security team working alongside them, while consumers experimenting with AI agents have no equivalent support.
Joe Sullivan's advice is to start narrow: give an agent access only to the account it needs for one specific task, then revoke that access once the task is finished. Anyone testing several agents against each other should clean up the permissions granted to the ones they have stopped using, and disconnecting an agent from an account is not the same as deleting the data that agent already holds.
Read the full article on Business Insider