PETALING JAYA: The next time an artificial intelligence (AI) assistant books your flight, fills in a form or accesses an online account, it may not just be following instructions – it could be acting as a digital identity with its own access rights and permissions.
These so-called non-human identities (NHIs), which enable AI agents and software to perform tasks autonomously, are becoming increasingly common.
But cybersecurity experts warn that without a clear legal framework, they could expose consumers and organisations to new privacy, security and accountability risks.
Cybersecurity expert Foong Choong Fook said the use of AI agents is expected to grow rapidly as businesses automate more tasks on behalf of humans.
“AI may understand the instructions it is given, but it does not always understand the broader context,” he explained.
“There are still major risks because AI can make mistakes or even hallucinate, and that risk will remain until the technology becomes more mature.”
He said clear rules are needed to define what AI agents can and cannot do, particularly when handling legal or financial matters.
“Without proper guidelines, disputes are inevitable. Someone could later claim they never signed a document because it was done by an AI agent.
“Questions over accountability and legal responsibility will become increasingly common,” he added.
Foong said legislation would be needed to define responsibility, prevent disputes and ensure AI agents are deployed responsibly as organisations increasingly rely on autonomous digital agents.
AI agents powered by NHIs are already being used to book services, process documents and access online accounts.
Researchers from the Massachusetts Institute of Technology and the Boston Consulting Group have described agentic AI as a new class of systems capable of planning, acting and learning independently.
Cybersecurity expert Emeritus Prof Datuk Dr Mohamed Ridza Wahiddin of the International Islamic University Malaysia said one of the biggest dangers is over-authorised delegation, where AI agents are given broader access than necessary.
He said attackers could exploit such access through prompt injection, stolen credentials, malicious tool calls or weaknesses in AI workflows.
“Once an agent has access to sensitive accounts, the damage can quickly expand into payment abuse, identity compromise, data theft or movement into other systems,” he noted.
He also said many digital identity systems are built for humans, not autonomous software capable of carrying out multiple tasks across different platforms.
“The risk is especially high where agents can access financial transactions, inboxes, API keys, customer records or digital identity recovery channels, as these are high-value targets for fraud and account takeover,” he said.
Emeritus Prof Mohamed Ridza advised consumers not to share banking passwords or account recovery codes with AI systems and to grant only limited, temporary and auditable access where necessary.
“A good rule is that if an agent can move money, reset identities or read sensitive emails, it should never have broad standing authority,” he said.
Assoc Prof Dr Nur Izura Udzir from Universiti Putra Malaysia’s Faculty of Computer Science and Information Technology said demand for faster and more convenient digital services is accelerating the adoption of AI agents.
However, she warned that managing them would become increasingly challenging as they gain the ability to handle sensitive information and operate across multiple platforms.
“We are now seeing a situation where one user could potentially have dozens of AI agents, and those agents can continue branching out into even more AI agents,” she said.
Assoc Prof Nur Izura has been working with a team of researchers at the Home Ministry through the Institute of Public Safety of Malaysia since last year on fighting cyber-enabled crimes.
