AI agent identity crisis spurs race for adaptive access control

Software Analyst Cyber Research

The gist

AI agents have outpaced traditional identity security, forcing a scramble for new adaptive access controls as shadow identities and unmanaged bots leave enterprises exposed.

What to know

AI Agents: Security Blind Spot

Autonomous AI agents have created an identity class so fast and unpredictable that legacy security tools can’t keep up, fueling a surge in unmanaged, high-risk machine identities invisible to most organizations.

By early 2026, the cybersecurity community had sharply recognized autonomous AI agents as a distinct non-human identity class, a realization catalyzed by high-profile incidents such as Anthropic's September 2025 disclosure of a Chinese state-sponsored group leveraging Claude Code for the majority of a cyber espionage campaign with minimal human intervention. This recognition was formalized with NIST’s January 2026 Request for Information on AI agent security, which underscored the inadequacy of traditional IAM systems and human oversight to manage AI agents operating at machine speed, as these agents autonomously execute thousands of requests per second, far outpacing human capacity to monitor or intervene effectively.

The surge of shadow AI identities—unmanaged, ephemeral, and often invisible to existing security frameworks—has compounded the identity security challenge, as documented by OWASP’s December 2025 Top 10 for Agentic Applications and reinforced by multiple industry surveys revealing that up to 82% of organizations discovered AI agents created without governance team knowledge. These shadow identities exploit legacy IAM shortcomings, such as the difficulty of enforcing multi-factor authentication on non-human identities and the prevalence of hard-coded credentials, leading to exponential security risks including goal hijacking, tool misuse, and cascading failures that traditional identity governance models were never designed to address.

The exponential growth and operational velocity of autonomous AI agents have outpaced existing identity governance frameworks, creating a critical security gap as enterprises now manage machine-to-human identity ratios as high as 150 to 1. Traditional IAM and PAM systems, built on assumptions of static human users and deterministic machine identities, fail to accommodate the dynamic, non-deterministic, and continuous nature of AI agents, which operate with overprovisioned, long-lived credentials like API keys and OAuth tokens. This mismatch has led to systemic overpermissioning, identity sprawl, and a growing blast radius for potential breaches, as highlighted by industry leaders including SailPoint’s Dana Reed and Okta’s Neil van Wyngaard, who emphasize the urgent need for new governance models that treat AI agents as 'first-class identities' with clear ownership, lifecycle controls, and real-time monitoring.

Despite widespread adoption—91% of organizations reported using AI agents by mid-2026—most enterprises remain ill-equipped to govern these identities effectively, with surveys revealing that 79% of IT professionals feel unprepared to prevent attacks via non-human identities and 90% of executives lacking comprehensive governance strategies. The rapid proliferation of AI agents has exposed critical gaps such as lack of agent inventory, static credential use, absence of continuous intent validation, and insufficient mutual authentication among agents, as starkly illustrated by Meta’s rogue AI agent incident. Industry responses, including CREST’s AI Charter and the UK’s Cyber Shield blueprint, now emphasize embedding identity and trust as foundational security elements, yet the pace of AI deployment continues to outstrip the maturity of control planes, underscoring identity governance as the new security frontier in the age of autonomous AI agents.

Sources
IBRockCyber MusingsThreat Vector by Palo Alto NetworksBusiness WireThe Data Exchange with Ben LoricaBleeping Computer

Rise of Just-in-Time Trust

Security leaders are replacing static credentials with ephemeral, intent-aware access controls that continuously score agent behavior—marking a radical shift from static IAM to dynamic, real-time risk management.

By early 2026, Just-in-Time Trust (JIT-TRUST) emerged as a pivotal evolution of Zero Trust Architecture, fundamentally transforming identity governance for autonomous AI agents. This framework replaces static, long-lived credentials with ephemeral, self-destructing Ephemeral Access Grants (EAGs) and strong certificate-based authentication, enabling dynamic, intent-aware access control that continuously monitors agent intent, semantics, and behavior to prevent lateral movement and adapt permissions in real time. As articulated in multiple analyses, JIT-TRUST’s Authority Mapping enforces strict operational boundaries, ensuring agents act only within pre-authorized scopes, while intent intelligence sharing fosters collaborative detection of misbehavior across workflows, marking a strategic shift from static IAM to continuous, context-driven risk scoring essential for AI-driven enterprises.

The identity security landscape in 2026 witnessed the rise of Agentic Identity Access Platforms (AIAPs), which function as centralized brokers—dubbed the 'new SSO for Agents'—that standardize how autonomous AI agents request access by translating declared intent into deterministic, task-scoped authorizations. This architecture shifts governance focus from 'who a human is' to 'why an agent or user is acting,' issuing ephemeral, least-privilege credentials only during authorized actions. SACR’s four-phase operational model—Discover & Register, Translate & Authorize, Broker & Inject, and Watch & Terminate—integrates primitives like EDR-driven discovery, intent-aware authorization, and zero-standing-privileges, with vendors differentiating themselves through deep visibility, runtime enforcement, and enhanced user experience, thereby enabling continuous, enforceable, and auditable agent access management.

Complementing these frameworks, emerging best practices emphasize cryptographically attested workload identities bound to runtime environments, paired with just-in-time, short-lived tokens scoped per task to eliminate standing credentials and reduce attack surfaces. Experts like Nancy Wang highlight the critical need for capability-level access controls that evaluate an agent’s actions rather than inherited permissions, advocating for privileged access reviews and automatic revocation to mitigate risks. However, major IAM frameworks and regulatory standards such as NIST AI RMF and the EU AI Act currently lack adequate provisions for AI agent permissions, underscoring this as a defining security challenge of 2026 that demands innovative, adaptive access models beyond traditional static roles.

Recent developments also spotlight the necessity of integrating runtime controls and real-time monitoring to govern non-deterministic AI agent behavior effectively. Platforms like PlainID’s Policy 360 and Token are pioneering centralized, policy-based access control frameworks that unify human and AI agent governance, enabling rapid authorization, limitation, and revocation of permissions within workflows. This dynamic approach, supported by certificate-based identities and agentic mesh architectures, replaces outdated centralized gateways with intent-based communication rules and on-demand permission revocation, ensuring agents operate securely across diverse environments. As Okta researchers emphasize, treating AI agents as identities with limited, observable, and revocable access, combined with comprehensive logging of every authorization decision, is paramount to maintaining security oversight and preventing credential misuse in increasingly autonomous AI ecosystems.

Sources

Agentic Platforms Redefine IAM

A new breed of identity platforms treats AI agents as first-class citizens, brokering access with short-lived credentials and runtime monitoring to close the gaps left by human-centric systems.

By early 2026, the identity security landscape was undergoing a fundamental transformation with the emergence of Agentic Identity Access Platforms (AIAPs), which redefined traditional IAM models by treating autonomous AI agents as first-class identities requiring ephemeral, intent-driven access. These platforms unify discovery, authorization, credential brokering, and continuous monitoring into a cohesive four-phase operational model—Discover & Register, Translate & Authorize, Broker & Inject, and Watch & Terminate—that enables deterministic, least-privilege permissions and runtime enforcement of Zero Standing Privilege (ZSP). Leading vendors like Okta, Cyata, Oasis Security, and Astrix Security have differentiated their solutions by integrating deep visibility across endpoints, cloud, and SaaS environments, capturing agent intent and context beyond mere activity logs, and providing human-in-the-loop approvals and automated remediation to secure AI agents at scale.

The architectural evolution underpinning agentic identity platforms emphasizes a clear separation between the AI agent (worker), its identity key, and a centralized broker layer that governs their relationship through policy and intent. This broker acts as a dynamic control plane, issuing short-lived, task-specific credentials that replace static, long-lived non-human identities (NHIs), which have historically posed significant credential leakage risks. Platforms like Oasis Security and Aembit have pioneered hybrid SaaS and customer-side architectures to keep sensitive secrets within enterprise perimeters while enabling just-in-time credential provisioning and actor-aware policy evaluation, ensuring that both the human initiator and the autonomous agent’s probabilistic behavior are accounted for in access decisions.

Market dynamics in 2026 reveal a fragmented yet rapidly converging AIAP ecosystem where vendors compete on the depth of agent visibility, enforcement fidelity, and user experience, all while moving toward a unified access control plane that treats identity as a temporary, continuously validated authority state. Companies like Okta have operationalized this vision by launching 'Okta for AI Agents,' integrating discovery, registration, and centralized control with features such as a kill switch and ephemeral OAuth tokens, and expanding AI integrations across over 25 applications including Slack and Anthropic. Similarly, SailPoint’s Agentic Fabric and Permiso Security’s runtime attribution platform extend lifecycle governance with modular packages and AI-driven threat detection, respectively, illustrating a trend toward comprehensive, scalable governance frameworks that align AI agent security with established identity governance and compliance standards.

Operationalizing agentic identity governance demands cross-functional collaboration and continuous lifecycle management to address legacy identity debt and the unique challenges posed by AI agents’ nondeterministic, goal-driven behaviors. As Itamar Appleblack notes, static least privilege models are inadequate; instead, dynamic, real-time privilege scoping based on declared intent is essential. Enterprises must integrate discovery mechanisms across endpoints, SaaS, and production environments to maintain visibility, manage credential rotations, and enforce attribution with human ownership and defined blast radii. This holistic approach, exemplified by Josys and Hush Security’s platforms, positions identity as the central control plane for securing autonomous AI agents at scale, ensuring that every agentic action is traceable, auditable, and governed by policy-driven kill switches and continuous monitoring.

Sources
Business WireSoftware Analyst Cyber ResearchTechRadarPR Newswire - Business TechnologyGlobeNewswire - Industry News on TechnologyIT Brief New Zealand

Vendors Race to Unify Governance

Major identity vendors are consolidating and partnering at record pace, integrating human and AI agent controls into unified platforms that promise continuous, automated policy enforcement across hybrid environments.

By early 2026, industry leaders like SailPoint and AWS pioneered strategic collaborations to establish unified identity governance layers that secure both human and agentic AI identities across cloud environments. SailPoint’s integration of machine and agent identity security into the AWS Marketplace exemplifies efforts to provide continuous, automated governance with real-time policy enforcement, enabling organizations to manage AI-driven architectures at scale while maintaining least privilege access and unified visibility.

Okta has emerged as a frontrunner in developing dedicated platforms for AI agent identity governance, launching 'Okta for AI Agents' in April 2026 to treat autonomous AI agents as 'first-class identities' with nondeterministic behaviors requiring distinct controls from human identities. Their framework addresses the widespread governance gap—44% of organizations lack AI agent controls—by enabling discovery, registration, lifecycle management, and a centralized kill switch, while expanding integrations with over 25 AI applications like Slack and Anthropic to centralize access and auditability across diverse AI ecosystems.

The identity security market is rapidly consolidating as companies pursue strategic acquisitions and partnerships to unify governance for human, machine, and AI agent identities amid escalating operational and compliance challenges. Okta’s $200 million acquisition of Permiso Security, which brings the SandyClaw AI sandbox for dynamic behavior analysis of AI agents, alongside Cyera’s billion-dollar acquisition of Oasis Security, illustrate this trend toward integrated platforms that extend beyond authentication to real-time threat detection, policy enforcement, and lifecycle management across multi-cloud environments.

Emerging standards and collaborative ecosystems are shaping the future of AI agent identity governance, with initiatives like Saviynt’s partnerships to create centralized AI agent repositories and Okta’s Cross App Access protocol supported by over 25 technology companies fostering interoperability and consistent policy enforcement. Meanwhile, platforms like PlainID’s Policy 360 and Josys’ AI-native identity security solutions emphasize centralized, policy-driven authorization and compliance automation, underscoring the industry's strategic shift toward scalable, unified governance frameworks essential for meeting imminent regulatory deadlines such as the EU AI law.

Sources
IT Brief New ZealandGlobeNewswire - Industry News on TechnologyGlobeNewswire - Industry News on TechnologyTechRadarSecurity Weekly - A CRA ResourceIT

Maturity Gap Stalls AI Agent Rollout

Despite widespread pilots, most enterprises lack the governance maturity to move AI agents into production—exposing a critical trust and tooling gap that only cross-functional collaboration and continuous monitoring can bridge.

By early 2026, the CoSAI three-phase adoption model has crystallized as a foundational roadmap guiding organizations through the maturation of AI agent identity governance. This model begins with establishing discovery and inventory capabilities to gain visibility into autonomous agents, advances to implementing contextual access controls tailored by agent type and risk, and culminates in full agentic IAM featuring continuous monitoring and compliance aligned with emerging regulations like the EU AI Act. As emphasized, identity governance is the linchpin for securing AI agents, answering critical questions about agent identity, authorization, and permitted actions—without which runtime enforcement and incident response are impossible.

Despite widespread pilot adoption—85% of enterprises running AI agent pilots—only 5% have transitioned to production, revealing a stark trust gap rooted in immature standards, tooling, and governance practices. Cisco President Jeetu Patel highlighted this 80-point disparity at RSAC 2026, underscoring that effective agentic identity governance demands more than technology; it requires secure delegation, cultural readiness, token economics, and human judgment to enable machine-speed policy enforcement and accountability, as Michael Dickman articulates. Continuous monitoring through network telemetry emerges as a critical enabler, providing the behavioral data necessary for reliable cross-domain correlation and policy enforcement.

Organizations with mature identity infrastructures, particularly in financial services, demonstrate accelerated adaptation to AI agent governance by treating agents as a new identity class requiring centralized management, permission restriction, and lifecycle controls such as credential rotation. However, many still grapple with orphaned service accounts and access outliers, often tracked manually, highlighting the urgent need for modern automated tools. Cross-functional collaboration among cloud operations, security, and AI teams is essential to continuously control permissions and monitor agent behavior, ensuring governance keeps pace with the rapid proliferation of non-human identities.

The emergence of a six-stage maturity model for non-human and agent-based identities codifies minimum requirements for defensible production deployments, including uniquely attributable non-human identities, on-behalf-of human principal models, short-lived credentials, and comprehensive audit trails integrated with SIEM systems. Yet, current IAM tooling, designed for human lifecycle management, is inadequate for the scale at which non-human identities now outnumber humans by 25 to 50 times in many enterprises. Industry leaders like Gartner, OWASP, CISA, and NIST recognize this governance gap as a top cybersecurity challenge, producing frameworks to address the unbounded risk posed by agentic AI identities. Interestingly, a recent recalibration shows AI maturity confidence dropping from 40% to 23% as organizations confront these governance realities, a positive sign of market maturation that correlates with higher confidence among those consolidating IT environments and treating AI agents as governed identities rather than shadow processes.

Sources

Authorization: The Next Battleground

As AI agents outnumber humans and operate autonomously, unresolved authorization gaps and over-permissioned credentials are driving a new wave of insider risk and forcing a pivot to adaptive, behavior-driven trust models.

By early 2026, the cybersecurity community recognized that authorization gaps and shadow AI identities create significant insider risks, as autonomous AI agents often operate with over-permissioned and static credentials that traditional IAM systems fail to govern effectively. Despite advances like the IETF’s AIMS draft standardizing AI agent authentication, authorization remains a critical unresolved challenge, especially within internal microservice chains where token theft and replay attacks are prevalent. Companies like Nvidia have pioneered integrated security in agentic AI platforms, yet governance gaps in agent-to-agent trust and provenance persist, underscoring the complexity of securing rapidly proliferating machine identities that now outnumber humans by orders of magnitude.

The strategic shift from static IAM models to Just-in-Time Trust (JIT-TRUST), evolving into Continuous Adaptive Trust (CAT), marks a fundamental evolution in securing autonomous AI agents by treating access as an ephemeral, context-aware resource. This approach, championed in early 2026 analyses, emphasizes continuous, real-time risk scoring and intent validation to neutralize threats like autonomous compromise and adversarial hijacking, leveraging cryptographic unified identity layers combined with behavioral analytics. SOC teams can now utilize intent scoring derived from LLM prompts to dynamically interrupt or block undesirable agent behaviors, facilitating collective defense through lateral sharing of risk intelligence among peers and consortiums.

The accelerating scale and autonomy of AI agents have exposed the inadequacy of traditional identity and access management frameworks, prompting a pivot towards identity-centric cyber resilience strategies that integrate behavioral analytics, real-time enforcement, and cross-functional governance. Industry leaders like Nancy Wang and organizations such as Delinea advocate for unified, context-aware access controls, cryptographic identities, and continuous observability to manage the sprawling agentic identity landscape. Emerging frameworks like Agentic Identity Security Posture Management (ISPM) enable closed-loop remediation—proposing, approving, executing, and verifying control changes automatically—thereby reducing latency between risk detection and resolution and ensuring auditable governance across millions of dynamic AI agents.

Despite widespread AI adoption—with 83% of organizations planning agentic deployments—many remain unprepared to secure these autonomous actors, creating a 'shadow identity crisis' where agents operate with unchecked, broad access that traditional IAM systems cannot contain. This crisis is exacerbated by insider risks from over-privileged agents capable of exfiltrating data at machine speed and by novel attack vectors such as prompt injection, jailbreaking, and memory poisoning that propagate malicious actions across multi-agent architectures. Experts stress that effective governance requires defining clear operational 'constitutions' for agents, enforcing scoped, revocable credentials, and implementing real-time transparency and intervention mechanisms. Extending Zero Trust principles rigorously to non-human identities is imperative to prevent catastrophic breaches in this new frontier of identity security.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.