AI agents go mainstream: enterprises race to scale, but identity and governance gaps widen

Startup Pirate by Alex Alexakis ↗

The gist

Enterprises are racing to deploy agentic AI at scale, but identity and governance are lagging dangerously behind the adoption curve.

What to know

  • Accenture has trained over 500,000 employees in agentic AI since 2022, with enterprises leaning on MSPs and platforms like Google Cloud’s Gemini to accelerate adoption.
  • Traditional identity systems can’t keep up—only 10% of organizations deploying agents have governance strategies, fueling a scramble for new control planes from Okta and 1Password.
  • Despite AI agents automating over 99% of SOC alert investigations at leaders like Google and Block, just 29% of enterprises will have standardized AI governance by late 2025.

MSPs Fuel AI Workforce Surge

Enterprises are racing to scale agentic AI by partnering with managed service providers and distributors, who are orchestrating massive upskilling and ecosystem integration to outpace internal talent shortages.

Enterprise adoption of agentic AI is rapidly accelerating as organizations prioritize embedding AI into daily operations to achieve long-term ROI, a strategy emphasized by Accenture CEO Julie Sweet who highlights the critical interplay of business strategy, technology readiness, and organizational preparedness. However, internal teams alone cannot scale AI expertise fast enough, driving enterprises to rely heavily on managed service providers (MSPs) and service partners like Accenture, which has upskilled over 500,000 employees since late 2022 and now trains its entire 700,000-strong workforce in agentic AI basics to meet demand. This partnership-driven model reflects a broader industry trend where MSPs and service providers are essential in bridging skill gaps and accelerating AI-driven transformation at scale.

Partner ecosystems, particularly agency partners and distributors, have emerged as pivotal accelerators of AI agent adoption by leveraging trusted relationships and enabling scalable customer acquisition. Case studies such as echowin’s white-label AI voice-building platform demonstrate how onboarding agencies in controlled batches ensures pilot success and rapid scaling, while distributors like TD SYNNEX and Ingram Micro provide comprehensive AI literacy programs that empower MSPs and solution providers to navigate the compressed transformation window of 12 to 18 months. As GTDC CEO Frank Vitagliano notes, distributors uniquely orchestrate the AI ecosystem by connecting software vendors, hardware makers, and resellers, creating a multiplier effect critical for operational scaling.

Leading cloud providers and consulting firms are driving enterprise AI adoption through integrated, full-stack platforms and collaborative partnerships that move organizations beyond pilot projects to measurable business value. Google Cloud’s Gemini Enterprise Agent Platform exemplifies this shift by unifying AI agents with deep integrations into Oracle, Salesforce, and ServiceNow, offering low-code/no-code tools and governance frameworks that facilitate secure, scalable AI workflows. Partnerships like Accenture and Google Cloud’s Gemini Enterprise Acceleration Program combine thousands of AI-skilled engineers to develop industry-specific AI solutions, while ServiceNow’s collaboration with Google Cloud advances autonomous operations across industries, underscoring the critical role of ecosystem collaboration in overcoming AI integration challenges and operational complexity.

The path to scaling agentic AI workflows demands a holistic approach that balances modernization of foundational infrastructure with workforce readiness and operational excellence. Strategies from firms like Perficient emphasize a three-pillar model—reverse abstraction of tech stacks, right-sized orchestration, and AI-ready workforce development—to accelerate production-level results, while Deloitte’s Enterprise AI Navigator framework guides enterprises to identify AI opportunities, quantify impact, redesign workflows, and leverage trusted ecosystems. Meanwhile, MSPs like Kaseya illustrate the competitive advantage of building AI capabilities in-house, integrating AI natively within end-to-end platforms to predict and prevent issues rather than merely react, all while embracing openness and ecosystem data sharing to enhance cyber resilience and operational scaling. This comprehensive approach is crucial as enterprises navigate workforce disruption, technical debt, and the need for continuous mastery of evolving AI tools to sustain competitive advantage.

Sources
Bloomberg TechChannelholicChannelholicGlobeNewswire - Industry News on TechnologyGTM StrategistChannelholic

AI Agents Break Identity Models

The rise of autonomous AI agents is exposing critical flaws in traditional identity and access management, forcing a shift to new control planes and dynamic, risk-aware authorization frameworks.

Agentic AI introduces a fundamentally new identity challenge in enterprise security, as these autonomous agents represent non-human identities that traditional human-centric IAM systems cannot effectively manage. As Jack Hirsch observes, 'agentic AI is an identity problem' because AI agents require unique, verifiable identities distinct from static roles or OAuth grants, which currently dominate but fall short in governance and security. This gap is starkly evident even in large enterprises like JP Morgan Chase, where an $18 billion security budget has not sufficed to contain sprawling AI agent activity, with over 90% of organizations deploying agents but only 10% having governance strategies in place.

The rapid shift from chatbots to autonomous AI agents demands a fundamental redesign of security architectures, emphasizing security-by-design principles with integrated model validation, runtime guardrails, and continuous authorization. Jeetu Patel highlights that security must be embedded in the development lifecycle, noting, 'security and safety is not looked at at odds with productivity. It’s actually looked at as a prerequisite of productivity.' This approach is critical to counter emerging vulnerabilities like prompt injection and jailbreaks, which exploit the conversational and dynamic nature of AI agents, vastly expanding the attack surface beyond traditional LLM risks.

New identity control planes and runtime protections are urgently needed to address the complex, dynamic access requirements of agentic AI, which operate across multiple tools and data sources with non-deterministic behaviors. Industry leaders like Okta, 1Password, and Astrix are pioneering open standards and secure token exchange mechanisms to provide CISOs with visibility and enforce least-privilege, just-in-time access. Meanwhile, emerging frameworks such as SPIFFE/SPIRE and policy-as-code platforms like Cedar enable continuous, context-aware authorization, moving beyond static roles to session-based, risk-aware permissions that automatically revoke access post-task completion.

The proliferation of autonomous AI agents has outpaced existing security controls, creating a sprawling attack surface exacerbated by shadow AI, unmanaged API keys, and fragmented governance. This has led to real-world incidents such as OpenClaw’s breach, where exposed API keys allowed attackers to commandeer agents, and AI agents improperly returning data across company boundaries due to authentication failures. Consequently, new security solutions like Operant AI’s Agent Protector, Check Point’s Lakera integration, and Orca Security’s AI-SPM are emerging to provide continuous discovery, real-time threat detection, and comprehensive governance, underscoring the critical need for integrated identity management and runtime protections tailored to agentic AI environments.

Sources
SiliconANGLE theCUBEVenture BeatThe AI-Native Product TeamCyberWire DailyPractical AIAI + a16z

Governance Lags as AI Spreads

With only a fraction of organizations implementing standardized AI governance, shadow AI and compliance chaos are accelerating, prompting urgent calls for embedded security, audit tools, and board-level oversight.

By late 2025, it was clear that governance and trust frameworks for AI agents were significantly underdeveloped, with only 29% of enterprises having standardized frameworks and a maturity index of just 2.8 out of 5. Data governance emerged as a top priority, given that data is the lifeblood of AI systems, yet regulatory complexities and fragmented SaaS environments compounded compliance challenges. Experts like Jeetu Patel underscored that security must be integrated from the outset, embedding runtime guardrails and validation mechanisms rather than being an afterthought, to build foundational trust necessary for scaling AI adoption.

The rapid proliferation of AI agents has outpaced existing security controls and governance frameworks, creating a visibility crisis and new classes of risks such as shadow AI, which 75% of security practitioners now view as eclipsing traditional shadow IT threats. This gap is exacerbated by poor collaboration between development and security teams, with only 34% of developers notifying security before AI projects, and traditional tools failing to address the dynamic, evolving nature of autonomous AI. Industry leaders like Adam Arellano emphasize the need for governance frameworks that embed security throughout the AI lifecycle and enforce board-level accountability to manage these emerging risks effectively.

As agentic AI tools like OpenClaw surged in enterprise environments by early 2026, the urgency for robust AI-specific policies, oversight mechanisms, and board-level accountability intensified. Rajiv Dattani of AIUC highlighted the critical risk of autonomous agents operating beyond intended boundaries, stressing the necessity of certification standards like AIUC-1 to build institutional trust and enable insurance backing. Concurrently, organizations grappled with fragmented AI strategies and regulatory uncertainty, prompting the emergence of AI audit tools, mandatory AI training akin to phishing awareness, and legal teams crafting 'responsible AI usage' contract language to address compliance complexities.

By mid-2026, governance maturity became the strongest predictor of successful agentic AI adoption, yet only about a quarter of organizations had comprehensive AI security governance frameworks in place. The inadequacy of human-centric identity models for AI agents drove calls for cryptographic identity infrastructures, as emphasized by Mrinal Wadhwa, to authenticate and authorize agent actions reliably. Frameworks like CARE and RISE emerged to guide organizations in encoding risk appetites into machine-enforceable policies, while new market solutions such as Unbound AI's Agent Access Security Broker provided real-time visibility and control, signaling a shift toward integrated, continuous governance essential for managing AI risks at scale.

Sources
SiliconANGLE theCUBEThe AI-Native Product TeamPR Newswire - Consumer TechnologyVenture BeatFocused ChaosResilient Cyber

Security Vendors Race to Adapt

IAM and security vendors are launching agent-specific solutions and open standards to address the dynamic, non-human identities and permissions AI agents demand, changing the enterprise security landscape.

IAM and security vendors are launching agent-specific solutions and open standards to address the dynamic, non-human identities and permissions AI agents demand, changing the enterprise security landscape.

AI Agents Transform SOCs

AI-driven automation is revolutionizing Security Operations Centers by handling over 99% of alert investigations, shifting analysts’ focus to complex threats and making data quality and orchestration the new maturity benchmarks.

By late 2025 and early 2026, AI agents began fundamentally reshaping Security Operations Centers (SOCs) by automating alert triage and detection engineering, significantly reducing manual workloads while still requiring substantial engineering effort for deployment, as David Seidman observed. This evolution is marked by the emergence of AI-generated detection rules capable of covering thousands of attack variants beyond human capacity, and a shift towards unified threat intelligence platforms that integrate internal and external data sources to provide richer contextual risk postures. Recorded Future forecasts that 25% of enterprises will embed threat intelligence into workflows beyond the SOC, leveraging AI-driven automation to enable machine-speed correlation and enrichment, thus allowing analysts to focus on higher-level judgment rather than routine tasks.

Throughout early 2026, leading organizations like Google and Block demonstrated the transformative impact of AI-driven SOCs by automating over 99% of security ticket investigations and achieving near-perfect efficacy in alert triage through semantic analysis of historical data. Google's approach balances AI autonomy with human oversight, reserving AI for nuanced judgment tasks while maintaining deterministic automation for routine workflows. Similarly, Block’s Goose agent democratizes detection engineering by enabling non-security teams to contribute, yet insists on human accountability by tying AI actions to internal identities and requiring human approval for code deployment. This AI-human collaboration model enhances operational efficiency while preserving responsibility and trust.

The architecture underpinning security data management is undergoing a profound transformation as mature SOCs move away from monolithic SIEMs toward flexible, AI-optimized data lakes, exemplified by Microsoft's launch of a dedicated security data lake feature. This shift enables intelligent data pipelines that act as decision engines—normalizing, enriching, and filtering telemetry before storage—resulting in 40-60% reductions in ingestion costs and improved detection visibility. As AI agents become integral to SOC workflows, data discipline and telemetry flow control emerge as key maturity metrics, emphasizing the importance of high-quality, structured data to fuel agentic reasoning at scale and support continuous improvement cycles linking threat modeling, detection, and agent performance.

Despite the rapid advances in AI-driven automation within security operations, widespread adoption of fully autonomous remediation remains cautious due to trust and resilience concerns. Security leaders emphasize that AI agents currently augment remediation by providing context and recommendations rather than executing changes autonomously, underscoring the critical need for adherence to change management processes with rollback plans to prevent outages. This cautious stance reflects a broader industry tension between the urgency to keep pace with AI-powered attackers and the imperative to maintain operational stability, with many organizations preferring human-in-the-loop models that balance automation benefits with accountability and risk management.

Sources
The Cybersecurity Pulse (TCP)Detection at ScaleDetection at ScaleSoftware Analyst Cyber ResearchDetection at ScaleVenture in Security

Data Lakes Power AI Defense

Enterprises are abandoning legacy SIEMs for AI-optimized security data lakes and intelligent pipelines, slashing costs and enabling continuous improvement in agentic threat detection and response.

Enterprises are abandoning legacy SIEMs for AI-optimized security data lakes and intelligent pipelines, slashing costs and enabling continuous improvement in agentic threat detection and response.

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.