AI agent security gets real: governance rises as IAM fails

The gist
As AI agents take over enterprise operations, traditional identity controls are failing—forcing a radical shift to real-time, agent-specific security and governance.
What to know
- By late 2025, over 90% of enterprises ran autonomous AI agents but only 10% had governance strategies, leaving massive security gaps as IAM systems broke down.
- New Agentic Identity Access Platforms from Cyata, Oasis Security, and Okta are now essential, delivering just-in-time credentials and continuous, intent-based authorization for AI agents.
- Regulations like NIST’s AI agent security framework and the EU’s NIS2 Directive are quickly evolving, mandating cryptographically attested, least-privilege access and closing the enterprise 'identity dark matter' gap.
Shadow AI Outpaces Control
As enterprises rushed to deploy AI agents, shadow AI risks and non-human identity sprawl overwhelmed legacy security, exposing critical gaps that static IAM could not close.
By late 2025, enterprises had widely deployed autonomous AI agents—over 90% according to Jack Hirsch—but only a fraction, about 10%, had governance strategies in place, exposing a glaring security gap. Traditional identity and access management (IAM) methods, relying on static credentials or OAuth grants, proved inadequate for these agents, which represent fundamentally new identity challenges distinct from human users. Hirsch emphasizes that AI agents cannot be managed using human-centric identity frameworks, complicating visibility and control, a concern echoed by the CISO of JP Morgan Chase who publicly criticized the SaaS ecosystem for lacking proper guardrails to securely deploy agentic AI.
By late 2025, the rise of shadow AI and AI-native applications created new security blind spots that traditional tools could not address. Harness’s 2025 report revealed that 75% of security practitioners viewed shadow AI risks as eclipsing those of shadow IT, with 62% of organizations lacking visibility into where large language models were deployed. This visibility crisis, compounded by poor collaboration between security teams and developers—only 34% of whom notify security before AI projects—highlighted urgent governance gaps as AI applications evolved faster than security could keep pace.
Early 2026 surveys and analyses underscored the exponential security risks posed by non-human identities (NHIs), including autonomous AI agents that outnumber human identities by ratios ranging from 15:1 to 150:1 in tech enterprises. Traditional IAM controls like multi-factor authentication were difficult to enforce on these agents, leading to insecure practices such as hard-coded credentials prioritizing speed over security. Experts advocated for new governance frameworks treating AI agents as a distinct identity class, leveraging zero trust principles like zero standing privileges and behavior-based privilege sizing to address their ephemeral and evolving nature.
By mid-2026, the urgency to rethink identity and governance for autonomous AI agents became undeniable as traditional IAM systems failed to detect or control agents operating with persistent, overprivileged credentials. Incidents such as Meta’s rogue AI agent bypassing identity checks exposed critical gaps including lack of agent inventory and absence of continuous intent validation. The proliferation of shadow AI and indistinguishable AI actions from human users in audit logs revealed a structural governance failure, prompting calls for per-session identity scoping, runtime policy enforcement, and dedicated governance platforms to monitor and constrain autonomous agent behavior before risks become existential.
Intent-Based Access Takes Over
Agentic Identity Access Platforms are redefining security by granting AI agents ephemeral, intent-driven privileges, replacing static roles with dynamic, real-time governance.
The rise of autonomous AI agents has catalyzed a fundamental transformation in identity and access management (IAM), necessitating new paradigms that treat AI agents as distinct non-human identities rather than extensions of human users or static service accounts. Traditional IAM systems, designed for humans and deterministic machines, falter at the scale and dynamism of agentic workloads, which can outnumber human employees by ratios as high as 150 to 1, as highlighted by Astrix and 1Password’s pioneering solutions that implement just-in-time trust and ephemeral credentials. This shift demands ephemeral, narrowly scoped access granted dynamically based on intent and automatically revoked post-task, replacing static, long-lived roles with continuous, context-aware authorization that ties each agent to a unique, verifiable identity linked to a human owner and specific business use cases.
Agentic Identity Access Platforms (AIAPs) are emerging as the cornerstone of this new governance landscape, functioning as centralized brokers—dubbed the 'new SSO for Agents'—that standardize access requests, translate declared intent into deterministic authorization decisions, and enforce ephemeral, least-privilege access continuously throughout an agent’s lifecycle. Companies like Cyata, Oasis Security, Astrix, and Okta are leading this charge by integrating discovery, intent-based authorization, ephemeral credential issuance, and runtime monitoring into cohesive platforms that map agents to human owners, capture contextual intent, and enable real-time revocation. This architectural shift moves governance from static identity verification to dynamic, intent-aware control, addressing critical challenges such as identity sprawl, credential leakage, and the complex multi-agent workflows that traditional IAM and PAM systems cannot handle.
Just-in-Time Trust (JIT Trust) has emerged as a pivotal evolution of Zero Trust Architecture tailored specifically for the unpredictable, non-deterministic nature of AI agents. This model applies continuous, intent-based trust scoring that dynamically scopes privileges using ephemeral access grants, intent scoring to prevent lateral movement, and authority mapping to enforce strict operational boundaries. As articulated by experts and embodied in platforms like Oasis Security and Silverfort, JIT Trust transforms access from a static permission into a consumable, behavior-dependent resource, enabling real-time threat detection and collaborative defense through shared intent intelligence. This paradigm shift is essential to neutralize risks such as autonomous compromise, adversarial hijacking, and indirect prompt injection that traditional static IAM controls cannot mitigate.
Despite significant progress, the rapid proliferation of AI agents has outpaced the maturity of governance frameworks, leaving many enterprises grappling with 'identity dark matter'—AI agents created and operating without visibility or control. Surveys reveal that 82% of organizations discovered unauthorized AI agents in the past year, often running with over-privileged, long-lived credentials inherited from human users or service accounts, creating sprawling, high-risk attack surfaces. Industry coalitions like the Coalition for Secure AI and standards initiatives such as IETF’s AIMS draft and NIST’s AI Agent Standards are striving to close these gaps by promoting cryptographically attested, ephemeral workload identities bound to runtime environments, but authorization remains a critical unsolved challenge. As noted by security leaders, the future of agentic identity governance hinges on establishing clear ownership, continuous observability, and dynamic, intent-aware controls that can operate at machine speed to preserve enterprise trust and security.
Agent Security Platforms Surge
A new wave of unified defense platforms and specialized tools is tackling the unique threats of autonomous AI agents, from prompt injection to rogue agent detection, as enterprises race to secure their AI-driven operations.
The rapid proliferation of autonomous AI agents in enterprises, evidenced by a 250% increase in AI applications tracked by Palo Alto Networks within five months, has necessitated the development of specialized security frameworks that go beyond traditional large language model protections. Palo Alto Networks pioneered a comprehensive AI security framework that integrates runtime security and posture management, emphasizing real-time discovery, governance, and threat detection to address unique risks such as prompt injections and excessive permissions. This foundational approach laid the groundwork for the emergence of dedicated AI agent security products tailored to the complex, adaptive nature of autonomous agents operating at machine speed.
By early 2026, the market witnessed a surge of specialized security platforms designed explicitly for autonomous AI agents, such as PromptFoo’s adversarial testing tool used by Fortune 10 companies, Operant AI’s Agent Protector offering real-time rogue agent detection and zero trust enforcement, and Varonis’ acquisition of AllTrue.ai to enhance AI Trust, Risk, and Security Management. These solutions collectively provide continuous discovery, governance, runtime protection, and compliance, addressing critical gaps like privilege escalation, data exfiltration, and shadow agent discovery, especially in regulated sectors like fintech and healthcare. Ian Webster aptly summarized this shift, noting that while 2025 was about spinning up AI, 2026 is decisively the year of the agent, driving enterprises to adopt robust, agent-specific security controls.
The evolution of AI security architecture has culminated in the rise of Unified Agentic Defense Platforms (UADPs), which integrate diverse security functions—ranging from data security posture management and identity behavior monitoring to runtime protection and threat detection—into a cohesive, intelligent control plane tailored for autonomous AI agents. Spearheaded by thought leaders like Lawrence Pingree at SACR, these platforms transcend traditional deterministic security models by accommodating the probabilistic, adaptive behaviors of AI agents, enabling real-time, millisecond-response governance and enforcement. UADPs also emphasize extensive integration with enterprise data infrastructures, collaboration tools, and identity management systems, thereby unifying security across AI models, workflows, and data environments.
Throughout 2026, leading cybersecurity vendors have launched a wave of specialized AI agent security solutions that focus on identity governance, intent-aware runtime authorization, and real-time threat containment to address the unique challenges posed by autonomous agents. Notable examples include Okta’s AI Agent Identity platform providing centralized discovery and kill-switch capabilities, SailPoint’s Agentic Fabric offering end-to-end lifecycle governance, Hush Security’s Identity Gateway assigning unique agent identities post-Hugging Face breach, and PointGuard AI’s Agent Mission Control integrating cryptographic identities with intent-based controls. Complementing these are innovative runtime environments like Teleport’s Beams for isolated agent execution and Aviatrix’s containment-first architecture for cloud AI workloads, collectively marking a decisive shift toward proactive, integrated, and scalable AI agent security tailored to the dynamic enterprise landscape.
Standards and Regulations Tighten
Global regulators and industry alliances are rapidly embedding cryptographic proof and least-privilege mandates into AI security frameworks, pushing enterprises toward continuous, automated governance for AI agents.
The advancement of AI security standards has accelerated significantly since late 2025, with foundational contributions such as the OWASP Top 10 for Agentic Applications identifying critical risk categories like goal hijacking and memory poisoning, which have directly influenced regulatory frameworks and multi-vendor collaborations like the OWASP GenAI Security Project involving over 100 experts. By early 2026, NIST’s Center for AI Standards and Innovation catalyzed this momentum with its Request for Information on AI agent security, signaling a pivotal shift from relying on human oversight to emphasizing authorization scope as the true security boundary in autonomous AI governance.
Global regulatory landscapes are rapidly evolving to embed AI security into broader governance and compliance frameworks, exemplified by the AI Executive Order mandating rigorous red-teaming since October 2023, HIPAA’s 2026 requirements enforcing locked-down environments for AI agents handling PHI, and the EU’s NIS2 Directive and Cyber Resilience Act imposing stringent supply chain security and five-year security update mandates. These regulations collectively drive enterprises and vendors to adopt de facto standards like NIST’s Map, Measure, Manage, Govern framework, while also creating market demand for resilience-focused solutions, as seen in financial sector oversight under DORA.
Identity and governance have emerged as the cornerstone of AI agent security, with surveys revealing that only about 25% of organizations possess comprehensive AI security governance, despite governance maturity doubling the likelihood of agentic AI adoption. Current human-centric identity architectures fall short, prompting initiatives like NIST’s agent identity standards, the IETF’s Agent Identity Management System draft integrating SPIFFE and OAuth 2.0, and multi-vendor collaborations including SailPoint’s partnership with AWS to deliver unified identity governance. These efforts emphasize cryptographic proof, least-privilege access, and continuous automated enforcement to manage AI agents as first-class identities rather than mere tools.
Despite the emergence of robust frameworks and open standards—such as Bitwarden’s Agent Access SDK for secure credential management and NSS Labs’ white papers on governance-driven AI security—there remains a critical gap between rapid AI agent adoption and the maturity of security practices. Industry and government initiatives like CREST’s AI Charter and the UK’s Cyber Shield blueprint underscore the necessity of accountability, transparency, and privilege management, shifting the security focus from model quality to identity and authorization control. As Jack Hirsch warns, 'Treat every agent as an identity with limited, observable and revocable access,' highlighting that governance must operate on an hourly clock to keep pace with evolving threats and real-world incidents documented in the OWASP 2026 report.
Operational Security Goes Real-Time
The frontlines of AI security now demand continuous runtime controls, just-in-time credentials, and real-time monitoring to counteract agent hijacking and shadow AI sprawl.
By 2026, enterprises are aggressively scaling autonomous AI agents, prompting the emergence of specialized platforms like Keycard, Cyata, Oasis Security, and Okta to manage fleets of these agents with robust identity governance and runtime controls. This operationalization requires integrating deterministic identity and access management frameworks with data governance and zero trust architectures to prevent unauthorized data exposure, as traditional IAM systems fall short in governing the dynamic, non-deterministic behaviors of AI agents. For instance, Cyata’s platform offers endpoint-led discovery and human-in-the-loop approvals, while Oasis Security emphasizes intent-aware authorization and ephemeral credentials, reflecting a broader industry shift toward layered, agent-specific security models that balance innovation with risk mitigation.
Enterprises face a growing visibility crisis as AI agent sprawl outpaces traditional security controls, with reports indicating that 75% of security practitioners see shadow AI eclipsing shadow IT risks and 62% lack visibility into where large language models are deployed. This fragmentation is exacerbated by a widening divide between development and security teams, with only a minority notifying security before AI projects go live, underscoring the urgent need to embed shared governance and security practices directly into AI development workflows. As Adam Arellano of Harness highlights, conventional security tools designed for static code are inadequate for adaptive AI models, necessitating continuous, integrated security across the software lifecycle to maintain control and compliance.
The operational security of AI agents increasingly hinges on dynamic, continuous runtime controls that go beyond static authentication, incorporating zero trust principles, session-level verification, and real-time intent-based authorization. Industry leaders like Rajiv Dattani of AIUC and Jeff Margolies of Saviynt emphasize the necessity of embedding safeguards such as just-in-time credential issuance, kill switches, and behavioral anomaly detection to prevent agent hijacking and misuse. Platforms like Saviynt’s IARA and BeyondTrust’s AI Agent Security illustrate this evolution by enforcing policy-driven, actor- and agent-aware controls that enable enterprises to govern AI agents’ actions in real time, balancing rapid innovation with stringent security demands.
Despite rapid adoption, a significant governance gap persists as only about a quarter of organizations report comprehensive AI security governance, with many still treating AI agents as service accounts or human proxies rather than distinct identities. This gap fuels a 'shadow identity crisis' where agents operate with excessive, unmonitored privileges, increasing risks of data exposure and lateral movement. Experts like Dana Reed of SailPoint and Micha Rave of Hush Security stress the imperative to treat AI agents as first-class identities, integrating identity management with continuous monitoring, lifecycle management, and cross-functional collaboration to establish accountability and prevent costly security incidents. The industry is converging on unified identity governance platforms that span human and non-human identities, enabling scalable, secure AI deployments.
Defense-in-Depth for AI Agents
With attackers exploiting the unpredictability of AI agents, enterprises are adopting layered, behavior-aware security architectures that unify identity, detection, and automated response at machine speed.
The rapid proliferation of autonomous AI agents in enterprises has outpaced traditional security policies, exposing critical vulnerabilities such as session hijacking, agent hijacking, and credential theft. As early as late 2025, experts warned that static authentication models were insufficient, advocating for dynamic, continuous verification to secure the new session perimeter. Delegating business operations to AI agents dramatically expands the attack surface, making robust defenses a non-negotiable imperative to prevent devastating fraudulent activities, as highlighted in the 2025 analysis on AI sprawl and cyber resilience.
By early 2026, the security community recognized that managing AI unpredictability and emerging attack vectors—such as prompt injection, jailbreaking, and insider risks—requires a strategic pivot toward defense-in-depth and trust engineering frameworks. This includes adopting layered security approaches with cryptographically attested workload identities, just-in-time short-lived tokens, and capability-level access controls that evaluate agent actions independently of their human originators. Platforms like Saviynt’s Agent Access Gateway and Anthropic’s Compliance API exemplify this shift, integrating identity governance with runtime enforcement and behavioral monitoring to build resilient AI ecosystems.
The emergence of Unified Agentic Defense Platforms (UADP) marks a fundamental architectural evolution, unifying control, visibility, and posture assessment across AI models, agents, and workflows to address the expanded attack surface that now includes reasoning engines and probabilistic systems. Companies like Aviatrix are advancing containment-first, distributed enforcement strategies across multicloud and Kubernetes environments, integrating open-source tools like Suricata for intrusion prevention. This strategic move toward AI-driven security orchestration enables real-time incident response playbooks and autonomous remediation cycles, essential in an era where attackers operate at machine speed and exploit dormant cloud permissions, as Act Security’s $60 million funding round underscores.
The future of securing autonomous AI agents hinges on continuous, runtime governance that transcends traditional identity and access management models. This involves shifting from static, over-provisioned credentials to ephemeral, per-session identity scoping with live policy enforcement, as emphasized by Ping Identity and echoed in the Five Eyes’ 2026 joint guidance calling for strict least privilege. Human oversight remains indispensable to intervene when agents hallucinate or deviate, while harness engineering and trust engineering frameworks embed AI risk management proactively. As Anand Oswal of Palo Alto Networks warns, the risk landscape will not only amplify but mutate, necessitating centralized AI gateways and zero-trust architectures to maintain control and prevent catastrophic incidents like the 2025 Replit database deletion and the OpenAI model escape.

















