img

JULIO RIVERA: Why we shouldn't regulate AI into submission

The important security question is not whether AI is intelligent. It is whether its authority is properly controlled.

The important security question is not whether AI is intelligent. It is whether its authority is properly controlled.

ad-image

Washington has no shortage of people ready to turn every new technology into an argument for more government oversight. Artificial intelligence has become the latest target, with debates about hypothetical dangers often drowning out a more immediate problem. AI systems are being connected to email accounts, company databases, cloud platforms and business applications, sometimes with permissions broad enough to cause real damage if something goes wrong. Before Washington dreams up another regulatory framework, businesses should ask a simpler question: who gave this machine the keys?

AI agents are no longer just chatbots that generate paragraphs or answer questions. They can search files, write code, execute workflows, communicate with customers and make changes across connected systems. That creates genuine economic opportunities. It also means a mistake, a stolen credential or a malicious instruction can have consequences far beyond a bad answer on a screen. The important security question is not whether AI is intelligent. It is whether its authority is properly controlled.

The Trump administration has argued that American AI leadership requires room for developers and businesses to innovate without unnecessary regulatory burdens. Its June 2026 executive order addresses cybersecurity while explicitly rejecting mandatory government licensing or preclearance for the development and release of AI models. The administration’s stated approach is to encourage innovation while strengthening defenses and cooperation with the private sector. That is a useful distinction: secure the technology and the systems around it without making government permission a prerequisite for progress.

Businesses should begin by examining what their AI agents can actually do. An assistant that schedules meetings has no obvious reason to access payroll records. A tool that summarizes contracts should not be able to transfer money or change production infrastructure. Yet AI agents often connect to multiple applications to complete tasks, and permissions can accumulate as organizations rush to automate work. A system built to save employees time can become a shortcut around the access controls companies spent years putting in place.

The problem is not limited to careless configuration. AI agents process outside information, and attackers can hide instructions in webpages, emails and documents in an effort to manipulate an agent’s behavior. This technique, known as prompt injection, can attempt to redirect a system toward disclosing information or performing unauthorized actions. Blocking suspicious content is useful, but no filter should be treated as perfect. Security must also limit the consequences when an agent gets manipulated.

That principle applies at home as well as at work. Individuals should think carefully before connecting AI tools to email, cloud storage, financial accounts or password managers. A convenient assistant does not need unrestricted access to every part of a digital life. Strong authentication, permission reviews and independent verification of payments remain essential. AI can help prepare a transaction or draft a message, but sensitive decisions should not become automatic merely because automation is available.

For businesses, the warning signs are already visible. A Cloud Security Alliance study published in April 2026 found that 53 percent of surveyed organizations had experienced AI agents exceeding their intended permissions, and 47 percent reported an AI-agent-related security incident during the preceding year. Those are survey findings, not universal rates, but they point to a practical problem: organizations are deploying agents faster than they are establishing visibility, accountability and controls over their behavior.

The solution is not to abandon AI or drown companies in paperwork. It is to apply familiar security principles consistently. Give every agent a distinct identity. Limit access to the task it performs. Keep records of its actions. Use short-lived credentials where practical, and make it possible to revoke access quickly. Require human approval before large payments, major system changes or disclosure of sensitive data, and consider a zero trust posture. Smaller businesses can start with these basic measures without hiring an army of compliance officers.

The same discipline matters for hospitals, banks, utilities and other critical infrastructure. AI may improve fraud detection, maintenance and vulnerability analysis, but an agent that recommends an operational change should not automatically have unrestricted authority to make it. Organizations need controlled interfaces, independent monitoring and tested recovery plans. Efficiency is valuable, but a shortcut that exposes essential services to disruption is a poor bargain.

The national security implications are equally clear. AI can help defenders identify vulnerabilities and respond to attacks, while criminals can use it to improve impersonation schemes and scale fraud. The FBI has warned that generative AI can facilitate financial fraud by making deceptive material easier to produce. Preventing criminal misuse requires effective defenses and enforcement against offenders, not the assumption that restricting legitimate development will stop adversaries from using the technology.

The Trump administration’s June 2026 order calls for voluntary collaboration among government, AI developers and critical infrastructure operators to identify vulnerabilities and coordinate remediation. Its success will depend on execution, but the broader principle is worth preserving: promote American innovation while improving the security of the systems that innovation touches.

Artificial intelligence will become more capable. That is precisely why permission matters. Individuals need control over their data, companies need confidence in their operations and the security of their endpoints, and America needs to defend its digital infrastructure without needlessly handicapping its technology sector. Give AI enough authority to be useful, then build safeguards around everything beyond that. The goal should be innovation with control, not regulation for its own sake.

Julio Rivera is a business and political strategist, cybersecurity researcher, and a political commentator and columnist. His writing, which is focused on cybersecurity and politics, has appeared in major publications around the world.


Image: Title: ai security

Opinion

View All

Hero pilot who saved Tel Aviv-bound passengers during attempted hijacking speaks to PM Modi

" I told everyone that I was doing it based on my own life. But at the same time, I also knew that I ...

Nearly 600 French schools disrupted, 2,000 arrested as students set fires, attack police, in mass violence over education funding

Over 560 schools and educational establishments have faced disruptions due to the protests and riots,...

EXCLUSIVE: JD Vance says H-1B visa program should be eliminated

“My view is the H-1B program is completely broken, and I’d be very supportive of just eliminating it....