
By Raymond Todd Blackwood, President of QuickLaunch
Twenty years ago I co-wrote a book called Techno Security's Guide to Managing Risks for IT Managers, Auditors, and Investigators. I have had a soft spot for auditors ever since. Not because they are fun at parties. Because they are the only people in the building who are paid to ask whether the records match the reality.
This week I read internal audit work plans the way other people read box scores. Florida A&M's board-approved audit plan now lists an engagement on artificial intelligence strategy. The University of Kentucky's internal auditors put artificial intelligence at the top of their work priorities, in more than one category. And New York's state comptroller has already audited a university system's AI governance, start to finish. The AI agent audit did not announce itself with a keynote. It got added to the work plan.
If that lands like a threat, let me reframe it, because the preparation is more familiar than you fear. Getting ready for an AI agent audit means producing five artifacts, all of them under your control: an inventory of every agent acting on your campus, a named owner for each one, a record of what each agent is allowed to touch, an activity log that separates what the agent did on its own from what it did on a person's behalf, and evidence that somebody reviewed that access and can revoke it fast. No new regulation is required to ask you for any of that. Most of it was already required.
Last week I closed the integrations column with a promise: the agents meet the auditors. This is that meeting, and I want you seated on the right side of the table.
New York's comptroller audited the State University of New York's AI governance and published the findings. SUNY's administration, the auditors wrote, does not have an effective AI governance framework, a standard definition of AI, or documented policies and procedures. None of the four campuses examined had procedures to test whether their AI systems' outputs were accurate or biased. One community college had no AI inventory at all. Read the report and notice what the auditors asked for. Not a philosophy of artificial intelligence. Artifacts. A framework. Definitions. Policies. Testing records. An inventory. The findings exist because nobody could hand those over.
That is the pattern I have been tracking all year. Earlier this fall I wrote that state auditors had started reading offboarding logs, and the season since has kept proving the point. Maryland's auditors found a university that processed 264 of 598 terminations late and paid roughly $150,000 to eight people who no longer worked there, six of whom the university did not know about. Florida's auditor general found a college ERP that could not produce the date access was removed for 104 separated employees, because the system deletes the role record when the person leaves. Illinois found a university where one in five terminations never reached IT on time, and where the access review only checked whether dormant users were still employed. A review built to find nothing, and it succeeded.
Hold those two threads together and the picture sharpens. The audit profession is adding AI to its work plans, and ISACA has published a how-to for auditing agentic workflows. Meanwhile the institutions being audited cannot yet evidence the removal of a human's access. The agents are joining that environment. Sometimes governed. Usually logged nowhere. Always moving faster than the paperwork.
Here is the part most vendor decks skip: you do not need an AI law for the AI agent audit to reach you, because the records regime is already in force.
Under the Gramm-Leach-Bliley Safeguards Rule, your institution must periodically review access controls so authorized users touch only the customer information their duties require, and must monitor and log the activity of those authorized users. Federal Student Aid checks Safeguards compliance through the annual Title IV compliance audit, and findings get resolved with the Department through corrective action plans. An AI agent running on institutional credentials is an authorized user by any reading an auditor will accept. Its activity is exactly the activity the rule says you monitor and log.
FERPA gets there by a different door. A third party that touches education records as a school official must be under your institution's direct control with respect to those records. When an agent reads a student record in Banner and writes a note into your CRM, either it is operating under your direct control, with the records to prove it, or you have a FERPA problem wearing a productivity costume. The registrar's data does not care how clever the software is.
And if you think I am moralizing, the federal government just failed this test in public. The Department of Education's own inspector general reported that separated privileged accounts were not disabled within the required one business day, and scored the Department's identity and access management as having slid backward after deep staff cuts. I take no joy in that finding. I take the lesson: this discipline is hard at every scale, nobody passes on good intentions, and the records are the only thing that saves you.
Now the strongest argument against this whole column, at full volume.
The audit profession itself says agents are not standard scope yet. The Institute of Internal Auditors ran a webinar this year reassuring members that agentic AI does not need to be on their current audit plan. The sector's top-risk surveys still rank cybersecurity first and do not name AI agents as a category. So a skeptic can fairly ask whether audit-ready agents are vendor-created urgency. And the skeptic can go further, because access certification, the centerpiece ritual of identity governance, was theater on plenty of campuses before the first agent logged in. A Netwrix survey found four in ten organizations running access reviews manually without involving the business at all, which in practice means approving whatever already exists. That Illinois review scoped to find nothing was certified, after all. An agent also breaks the ritual's central prop: there is no manager to attest for it, because nobody manages it. ISACA's new guidance names the structural gaps plainly: agent instructions live outside change management, non-deterministic behavior defeats sample-based testing, per-system reviews miss an agent's combined cross-system reach, and the vendor can change the model under you without a change ticket.
The identity industry is racing at the gap, visibly mid-stride. Microsoft gave agents sponsors and routes their recertification through time-boxed access packages rather than its classic access reviews. Okta announced certifications for agent permissions, and a major analyst's recap still called the governance details unclear. SailPoint runs certification campaigns over agent access today. Another legacy identity vendor announced an agent platform whose governance module is still on the roadmap. When half the market ships and half the market promises, you are watching a category get built in real time.
So yes: if your access reviews are rubber stamps, bolting agents onto them scales the theater. That is an argument for fixing the review, not for skipping it. And here is the honest advantage nobody mentions: unlike your humans, the agent writes down everything it does. The cleanest audit trail on your campus can belong to its newest workforce. The Cloud Security Alliance's maturity guidance puts the real metric well: not what percentage of agents you have inventoried, but how fast you can revoke one. The OWASP list of non-human identity risks reads like this column's greatest hits: improper offboarding, overprivilege, identity reuse that destroys attribution. The same ghosts I have been writing about all year. New bodies.
Back in August I wrote about what to know before you audit your AI agents . This season answered the question of when, so everything above collapses into one piece of advice: for every agent, be able to produce the file. It exists. It has an owner. These are its scopes. This is its log, with the agent's own actions distinguished from the ones it took on a person's behalf. This is when its access was last reviewed. This is how fast we can shut it off.
This is the layer we have been building, so let me state our stake plainly. In our latest release, QuickLaunch ships first-class identities for AI agents : agents get registered like employees, with their own credential, a named owner, deliberately scoped roles and entitlements, lifecycle states with an emergency revocation action, and an agent-level audit log that separates autonomous actions from on-behalf-of actions. Alongside it ships access review and certification : campaigns that pull entitlements straight from the identity store, notify managers, capture approve, deny, or change decisions, and build the certification reports your next audit will ask to see. Underneath both, the reporting layer keeps the provisioning audit trails and flags the access nobody has used.
The limits, in print, as always. As our documentation describes it today, those certification campaigns are built around managers reviewing their people; for the agents themselves, the review loop today is the named owner, the audit log, and the revocation switch. And one line from our own announcement deserves to be the standard you hold every vendor to, ours included: where our console shows what an agent is declared to be able to do, it will not dress that up as what is enforced. Declared is not enforced. Make every vendor show you which is which. Beyond that, no product, ours included, can name the owner, pick your review cadence, or sit in the interview chair when the auditor asks who approved this.
The audit is not the enemy. Amnesia is. The institutions that fear audits are the ones that cannot produce their own records, and an agent generates a perfect record of everything it does. Whether anyone can produce that record on demand is a decision, and it is far cheaper to make it this term than in the management-response column of a public audit report. Put your agents on the inventory before somebody's work plan does it for you. Next week we stay in this neighborhood: privileged access management in higher education, and how campus temporary access compares to the corporate world. That conversation is next Wednesday.
Primary: Start the agent's file this week: download the AI Agent Inventory Tracker workbook and the CIO Guide for Managing AI Identities on Campus , then see how first-class identities for AI agents turn that inventory into a governed system of record. Current capability detail lives in the release notes .
Secondary: Follow the weekly column on the QuickLaunch blog . Next week: PAM in higher education, how institutions compare to the corporate world on temporary access.
How do you prepare for an AI agent audit in higher education?
Preparing for an AI agent audit means being able to produce five artifacts for every AI agent acting at the institution: an inventory entry, a named human owner, a documented record of the systems and data the agent can touch, an activity log that distinguishes autonomous actions from actions taken on a person's behalf, and evidence of periodic access review with a tested revocation path. Auditors evaluating AI governance, such as the New York comptroller's 2026 audit of SUNY, ask for governance artifacts (frameworks, policies, inventories, testing procedures) rather than opinions about AI.
Do AI agents need access reviews and certification?
Yes. An AI agent holds standing access like an employee but has no manager to attest for it in a certification campaign, so governance programs assign each agent a named owner who answers for its access. The identity industry is building this capability now: SailPoint documents certification campaigns covering agent access, Okta has announced resource access certifications for agent permissions, Microsoft Entra routes agent recertification through time-bound access packages with human sponsors, and QuickLaunch ships first-class agent identities with owners, scoped entitlements, and agent-level audit logs.
Does GLBA apply to AI agents at universities?
Yes. The GLBA Safeguards Rule (16 CFR 314.4) requires institutions to periodically review access controls and to monitor and log the activity of authorized users on systems holding customer information, and Federal Student Aid verifies compliance through the annual Title IV compliance audit. An AI agent operating on institutional credentials is an authorized user, so its access falls under the periodic review requirement and its activity falls under the monitoring and logging requirement. FERPA separately requires third parties handling education records as school officials to remain under the institution's direct control.
What did the New York State Comptroller's AI governance audit of SUNY find?
The New York State Comptroller's audit of SUNY's artificial intelligence governance, issued August 11, 2026, found that SUNY's administration lacked an effective AI governance framework, a standard definition of AI, and documented policies and procedures. None of the four campuses examined (University at Albany, Stony Brook, Upstate Medical, and Onondaga Community College) had procedures to test AI outputs for accuracy or bias, and Onondaga had no AI risk-management plan or formal AI inventory.
**Raymond Todd Blackwood is the President of QuickLaunch and writes about identity, agentic AI, and the messy reality of higher-ed IT. #ItsExistential*