Companies using artificial intelligence (AI) to carry out everyday business tasks need to set clear limits on what these tools can access and do, Fortinet executives said during the company’s AI Cybersecurity Summit APAC 2026 Philippines Edition.
These tools, called AI agents, can do more than answer questions. They can connect to company applications, retrieve information, and complete tasks.
“Do you know what your employees are using? Do you sanction everything or are they also using unsanctioned AI tools or AI apps?” said Bambi Escalante, country manager, Fortinet Philippines during her opening remarks.
Escalante said companies need to know whether employees are using AI applications without approval. This practice, known as shadow AI, can put confidential information at risk when workers enter company data into public AI tools.
For businesses developing their own AI agents, the concern includes which company systems those tools can enter and what actions they can take.
During his presentation, Sheu Hau Leong, App, Cloud, and AI Security sales lead, APAC, Fortinet, explained how AI agents can access databases, use business applications, and plan the steps needed to complete a task. If one approach fails, they can try another.

He said companies should treat these agents like employees with assigned duties. Each should have access only to the information and tools needed for its work. Being able to connect an AI agent to several systems does not mean it should have permission to use everything.
Another risk is that someone could trick an AI agent into following harmful instructions. This is called prompt injection: An attacker uses words to get the AI to reveal confidential information or do something it should not.
Leong explained that simply blocking certain words may not stop the attack. Someone seeking access to an account, for example, could phrase a request without using words such as “password” or “credentials.”
He said protections need to examine what the request means, alongside controls that limit the agent’s actions.
Fortinet demonstrated tools designed to check requests sent to AI applications and block harmful instructions. The company also outlined steps for identifying AI tools in use, limiting access, recording activity, and testing agents before letting them handle business tasks.
Keeping records matters because companies need to trace what an agent did if something goes wrong, Leong said. They should also control requests an agent sends to other applications to retrieve information or perform an action.
AI use can affect spending, too. Leong said excessive requests could disrupt services and drive up costs. Companies therefore need limits on usage and budgets as they expand their AI applications.
Escalante said security needs to differ depending on how a company uses AI, whether employees use public tools or the business develops its own applications.
Leong encouraged companies to bring AI use into the open so it can be managed. His advice was to identify the tools being used, set clear permissions, test new agents, and keep reviewing the controls as the company’s use of AI develops.