Least privilege for AI agents
Least privilege for AI agents is the security principle that each AI agent should have only the access, tools, and actions it needs to complete its assigned task, for only as long as it needs them. In a hospital, that means scoping what records an agent can read, what systems it can change, and under whose authority.
Where the principle comes from
Least privilege is a long-standing security principle. NIST SP 800-53 Rev. 5 control AC-6 directs organizations to "employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks." An AI agent is exactly such a process acting on behalf of users.
In healthcare, HIPAA points the same way. The Security Rule's access control standard requires technical policies that "allow access only to those persons or software programs that have been granted access rights" (45 CFR 164.312(a)(1)). The minimum necessary standard requires reasonable efforts to limit protected health information "to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request" (164.502(b)).
Why agents need tighter scoping than people
Agents change the risk profile in three ways. They act quickly and repeatedly, so an over-broad permission can be misused many times before anyone notices. They can be manipulated through prompt injection, where text in a document or message instructs the agent to do something else. And they are often connected through shared service accounts, which grant far more than a single task needs.
The OVERT runtime evidence specification captures the agent-specific version of the principle. Its TOOL-2 requirement states that "AI agents SHALL be restricted to approved functions with validated parameters," and TOOL-1 requires that every tool call be "evaluated against policy" before execution.
What least privilege looks like in practice
- Scope by action, not just by system. "Read appointment slots" and "cancel appointments" are different permissions, even in the same scheduling system.
- Scope by data. Limit an agent to the patients, fields, or record types its task requires.
- Use short-lived credentials. Issue access that expires, rather than long-lived keys the agent holds indefinitely.
- Give each agent its own identity. Avoid shared accounts so every action traces to one agent and one owner.
- Gate sensitive actions. Require human approval for high-impact steps such as sending messages to patients or changing orders.
- Deny by default. Anything not explicitly granted is refused, and new tools require a new review.
- Review regularly. Remove permissions an agent no longer uses, and recheck scopes whenever the agent's model, vendor, or task changes.
The same principle applies to what an agent passes to other agents or tools. If one agent can delegate work to another, the delegate should not inherit more authority than the original task required.
How Skovos handles this
Skovos applies least privilege at runtime. Each registered agent has explicit scopes, actions checked through Skovos are compared against them before they run, and anything outside scope is denied and logged. The hospital can narrow scopes or recall the agent at any time.
Frequently asked questions
Is least privilege required by HIPAA?
HIPAA does not use the phrase, but its access control standard and minimum necessary standard require limiting access and PHI to what is needed.
How is least privilege different for agents than for staff?
The principle is the same, but agents act faster, can be manipulated through their inputs, and often run under shared accounts, so permissions need to be narrower and checked on every action.
What is a practical first step?
Inventory each agent's current credentials and connections, then remove anything its documented task does not need.
Related reading
- HIPAA compliance for agentic AI in health systems
- AI agent registry for hospitals
- How to stop an AI agent in a hospital
Sources
- NIST SP 800-53 Rev. 5, AC-6 Least Privilege (OSCAL catalog): https://github.com/usnistgov/oscal-content/tree/main/nist.gov/SP800-53/rev5
- NIST CSRC Glossary, least privilege: https://csrc.nist.gov/glossary/term/least_privilege
- 45 CFR 164.312, HIPAA technical safeguards: https://www.law.cornell.edu/cfr/text/45/164.312
- 45 CFR 164.502(b), minimum necessary: https://www.law.cornell.edu/cfr/text/45/164.502
- OVERT v1.1 standard text, TOOL-1 and TOOL-2: https://overt.is/latest.md