← Back to Technomalist
Philippines & Southeast Asia/news/3 min read

Fortinet to Philippine Firms: Treat AI Agents Like Employees and Limit Their Data Access

Fortinet executives warn that AI agents pose data and cost risks, urging companies to scope access, detect shadow AI, and guard against prompt injection.

Featured image for Fortinet to Philippine Firms: Treat AI Agents Like Employees and Limit Their Data Access
Featured image for Fortinet to Philippine Firms: Treat AI Agents Like Employees and Limit Their Data Access

Security vendor Fortinet told an industry gathering in the Philippines that organizations adopting AI agents must be deliberate about what those tools are allowed to reach and do, according to Back End News. The guidance came during the company's AI Cybersecurity Summit APAC 2026 Philippines Edition.

AI agents differ from chatbots in scope. As described at the event, they can connect to business applications, pull information from databases, and carry out multi-step tasks, trying alternate approaches when one path fails. That autonomy creates exposure that traditional question-and-answer tools do not.

Bambi Escalante, Fortinet's country manager for the Philippines, opened the session by focusing on visibility. She asked whether companies actually know which AI tools their employees use, or whether workers rely on unsanctioned applications. That unmanaged usage, often called shadow AI, can expose confidential data when staff enter company information into public tools. Escalante said security measures should be tailored to how a business adopts AI — whether employees are using outside services or the company is building its own applications.

Sheu Hau Leong, Fortinet's App, Cloud, and AI Security sales lead for APAC, outlined how organizations should constrain agents. His comparison: treat an AI agent like an employee with a defined job, granting access only to the systems and information required for that role. According to the report, being technically able to connect an agent to multiple systems is not a reason to let it use all of them.

The event also highlighted prompt injection, in which an attacker phrases instructions that lead an agent to expose confidential information or take actions it should not. Leong noted that simple keyword blocking is inadequate: someone trying to reach an account could phrase a request without using terms like "password" or "credentials." Detection therefore has to look at the meaning of a request, he said, working alongside controls that restrict what the agent can do.

Fortinet demonstrated tools designed to inspect requests sent to AI applications and block malicious instructions. The company recommended a sequence of steps for customers: find out which AI tools are in use, limit access, keep activity logs, test agents before assigning them business tasks, and control the requests agents send to other applications when retrieving data or triggering actions.

Cost and availability are part of the picture. Leong said excessive requests could strain services and inflate spending, so companies need usage and budget caps as their AI deployments expand.

Keeping records matters for accountability. Without logs, tracing what an agent did when something goes wrong becomes difficult, Leong said. Escalante and Leong both framed the goal as bringing AI use into the open so it can be governed, rather than banning it outright.

The event's advice rests on a straightforward premise: as AI agents move from answering questions to acting on company systems, permissions, monitoring, and testing become operational requirements. However, the specific effectiveness of Fortinet's own detection tools and any cost impacts on Philippine enterprises were not independently verified in the source material, and the recommendations remain vendor guidance rather than demonstrated customer outcomes.

REPORTING NOTES

Sources and further reading

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all ↗