5 min readAI Agents · Cybersecurity
Access Control vs Action Control: What AI Agents Changed
By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

TL;DR: Action control decides what an AI agent may do inside a system. Access control only decides what it can reach. "Can read your email" and "can send email on your behalf" are different permissions, and most AI rollouts only enforce the first. RSAC 2026 made this split its central theme, from the keynotes to the top innovation award.
Last updated October 5, 2026. Rebuilt for verifiedagents.ai: the definition, the RSAC evidence, the Zero Trust extension, and the five decisions a CEO can make this quarter.
What is action control for AI agents?
Action control governs what an agent is permitted to do within the systems it reaches. Access control governs which systems it reaches at all. The two sound alike and behave nothing alike once software starts acting on its own.
"Can access the email system" is access control. "Can send email on your behalf" is action control. An agent with the first permission and no limits on the second can do anything email can do, at machine speed, under your name. Cisco's Jeetu Patel called this move from access to action the defining shift, from the RSAC 2026 keynote stage. Most deployments haven't made it yet.
Why did RSAC 2026 make this the theme?
Because the field converged on the same diagnosis from different stages. Microsoft laid out a four-part model of continuous agent governance. CrowdStrike's George Kurtz described the three failure patterns he keeps finding inside enterprises. Splunk's John Morgan called for "an agentic trust and governance model" outright. And the Innovation Sandbox's top award went to Geordie, a platform whose only job is finding the agents you don't know you're running.
Kurtz's three patterns are worth keeping on one slide:
Invisible reasoning.
The agent decides and acts, then moves on, with no record of why. When something goes wrong, there's nothing to trace.
No kill switch.
Kurtz asked executives how they'd stop a compromised agent. Most couldn't answer.
Speed mismatch.
You act in minutes. The agent acts in milliseconds. By the time an alert fires, 50 more actions already happened.
Most enterprises have all three at once.
Has anyone actually attacked agent infrastructure?
Yes. ClawHavoc was the first known supply chain attack on agentic AI infrastructure. It targeted the OpenClaw platform and poisoned 1,100 skills that agents could download and execute. Not a research proof of concept. A real attack, in the wild, against the parts agents trust automatically.
Your agents are already a target. The question is whether you'd know when they're hit.
How does this extend Zero Trust?
Zero Trust stays the foundation: never trust, always verify, on every request. Agents add one requirement on top, because the original model verified entities that act at human speed with stable behavior.
What gets verified | Human employee | AI agent |
Identity | One person, consistent | A credential that can be shared or spoofed |
Behavior | A steady baseline | Changes with every instruction |
Speed | Slow enough to catch | Milliseconds per action |
Control that fits | Access control | Action control on top of access control |
John Kindervag, who created Zero Trust, put it to me this way at RSAC: no single identity signal is enough. Real security comes from evaluating the full collection of signals together.
The Agentic Trust Framework packages exactly that addition: action-level controls and live behavioral monitoring on top of the Zero Trust base, across five elements from Identity Management through Incident Response. The keynotes described its pieces without naming it. Microsoft's engineering team built their Agent Governance Toolkit against the spec 30 days after CSA published it, and Berlin AI Labs documented 12 production deployments across all five elements. Neither was asked.
What should a CEO decide this quarter?
Five decisions. No new vendor, no six-month program.
Require a full agent inventory.
Every agent, its approver, its reach, its permitted actions. More than 72 hours to produce it is a board agenda item. The method is in
.
Require a kill switch policy before go-live.
The build spec is in
how to build an AI agent kill switch
.
Separate access from action.
Read and send are different permissions. Treat them that way.
Require a logged reason for every agent decision.
No record of why means it doesn't run in production.
Put one human name on every agent.
Accountability changes behavior, even when a machine sets the behavior.
Frequently asked questions
Isn't access control enough if it's strict?
No. Strict access still grants everything inside the door. An agent allowed into email can read one message or send ten thousand. Only action control tells those apart.
What was Geordie's award about?
Visibility. The industry's top innovation prize went to a tool that finds agents IT doesn't know about, which says plainly where the industry thinks the problem sits.
Does action control slow agents down?
The checks run in milliseconds, same as the agent. What it slows down is the one action that shouldn't happen, which is the point.
Where do I see how my controls score?
The free ATF assessment walks the five elements in about ten minutes and shows which half of the access-versus-action split you've covered.
Key takeaways
Access control opens doors. Action control governs what happens inside them.
RSAC 2026's keynotes converged on the same diagnosis from different stages.
ClawHavoc proved agent supply chains are already being attacked.
Zero Trust stays the foundation. Agents add action-level verification on top.
Five CEO decisions cover the ground this quarter, with tools you already own.
Make the split real this week
Governed agents earn trust. Trusted agents get more autonomy, and that's where the productivity lives.
Your agents already have access. What they're permitted to do with it is still your call to make.