AI agents outnumber humans, but security still on training wheels: enterprises scramble to rein in rogue bots

The gist
Enterprises are drowning in autonomous AI agents that now outnumber humans, but most still have security and governance stuck on training wheels—leaving critical gaps wide open.
What to know
- By late 2025, over 90% of enterprises deployed autonomous AI agents, yet only about 10% had governance strategies—leading to high-profile breaches like the one reported by A16Z.
- Industry leaders like Cisco and Okta are racing to shift from static, human-centric IAM to dynamic, agentic frameworks with intent-aware, just-in-time access for non-human identities that can outnumber humans by up to 150:1.
- Despite 85% of enterprises piloting AI agents, just 25-30% have mature security governance, fueling regulatory scrutiny and a vendor arms race to tame shadow agents and overprivileged AI credentials.
CISOs Face Unseen AI Risks
A surge in autonomous AI agents has blindsided security leaders, exposing enterprises to breaches and financial fallout as static IAM models fail to control invisible, overprivileged bots.
By late 2025, the rapid deployment of autonomous AI agents in enterprises exposed a glaring security gap, with over 90% of organizations running AI agents but only about 10% having governance strategies in place, as Jack Hirsch highlights. Traditional identity and access management (IAM) models, relying on static credentials and OAuth grants, proved inadequate for these new non-human identities, which operate fundamentally differently from human users. Hirsch emphasizes that AI agents represent a novel identity challenge, lacking clear visibility and control, which complicates CISOs' efforts to secure enterprise resources without stifling business agility.
The urgency for new governance models was underscored by high-profile critiques such as the JP Morgan Chase CISO's open letter condemning SaaS ecosystems for insufficient security guardrails around agentic AI, signaling a trust deficit in existing frameworks. Early 2026 incidents, including a notable security breach involving an AI agent improperly accessing data from other companies as reported by A16Z's Joel de La Garza, revealed critical authentication and authorization failures. These events highlighted the need for deterministic guardrails that enable resource owners to maintain strict control over AI agent access, moving beyond static user-group permissions to context-aware policies.
Surveys from late 2025 revealed a stark disconnect between CISO concerns and preparedness: 73% expressed critical fears about AI agent risks, yet only 30% had mature safeguards in place, with 78% lacking formal strategies for integrating AI identities into zero trust architectures. The Portnox CEO, Denny LeCompte, warned that AI adoption introduces an unmanaged, potentially catastrophic security risk, necessitating rapid evolution of identity and access controls to encompass both human and machine identities. This gap was further evidenced by early breaches affecting one in five organizations, with financial impacts rivaling major ransomware attacks, driven by vulnerabilities like prompt injection and data exposure.
The discovery of critical vulnerabilities, such as the January 2025 ServiceNow flaw (CVE-2025-12420) allowing attackers to bypass MFA and SSO using only email addresses, starkly illustrated the inadequacy of traditional trust models based on static credentials. This incident, alongside NIST’s early 2025 Request for Information distinguishing chatbot from autonomous agent security, marked a pivotal moment recognizing the unique risks posed by AI agents capable of autonomous actions. The rapid proliferation of non-human identities—growing to a ratio of 144:1 compared to humans by early 2026—combined with poor credential lifecycle governance and architectural mismatches in protocols like OAuth 2.0, exponentially expanded the attack surface, as noted by Admiral Mike Rogers. These developments made clear that human oversight alone is insufficient, and that authorization scope must become the new security boundary.
Agentic Identity Revolution
Enterprises are abandoning human-centric access controls for dynamic, intent-aware frameworks that treat AI agents as unique identities, with ephemeral credentials and real-time permissions.
The foundational shift in identity and access management (IAM) for enterprises is moving decisively away from traditional human-centric models toward agentic identity frameworks that recognize AI agents as distinct, first-class identities. This transition is driven by the exponential rise of autonomous AI agents, which can outnumber human users by ratios as high as 150:1 in some high-tech environments, as noted by multiple industry analyses. Leaders like Jeetu Patel of Cisco emphasize that security must be integrated from the ground up with dynamic, ephemeral, and intent-aware permissions, supported by just-in-time trust models to enable scalable and secure AI adoption. The era of static, long-lived credentials and shared service accounts is ending, replaced by unique, cryptographically attested identities for each agent workload, tightly scoped to specific tasks and automatically revoked upon completion to prevent privilege creep and reduce compliance risks.
Dynamic, ephemeral, and intent-aware access controls have emerged as critical components in managing AI agents securely within enterprises. Platforms like Astrix enforce short-lived, precisely scoped credentials and just-in-time access based on least privilege principles, effectively eliminating access chaos and reducing compliance risk. Auth0’s innovations in asynchronous approval flows using mechanisms such as Client-Initiated Backchannel Authentication (CIBA) and Rich Authorization Requests (RAR) enable agents to request human approval with meaningful context, balancing automation with control. This approach aligns with zero trust principles and task-based access control (TBACK), where permissions are granted narrowly for specific tasks and revoked immediately after, ensuring agents operate strictly within pre-authorized scopes and minimizing the risk of lateral movement or unauthorized actions.
The complexity and non-deterministic nature of autonomous AI agents expose fundamental limitations of legacy IAM and PAM systems, which were designed for predictable human behavior and static permission models. These traditional systems struggle to support runtime-bounded, intent-scoped delegation and fail to preserve clear attribution across multi-agent workflows, leading to blurred accountability and systemic overpermissioning. Experts like Nancy Wang and Itamar Appleblack argue that static least privilege models are ineffective for AI agents; instead, dynamic, real-time permissioning aligned with an agent’s evolving intent and goals is essential. This requires continuous monitoring, behavioral tracking, and anomaly detection to enforce least agency principles, ensuring that agents’ actions remain constrained and auditable throughout their lifecycle.
Industry leaders and standards bodies recognize that managing AI agents as distinct identities is the new frontier in cybersecurity, necessitating a comprehensive operational control plane that integrates discovery, governance, and lifecycle management. Companies like Okta have pioneered AI agent IAM platforms that enable ownership assignment, rapid incident response, and continuous authorization, addressing the urgent governance gaps highlighted by surveys showing 91% of organizations deploying AI agents but 44% lacking proper controls. The shift also demands unifying fragmented identity systems and evolving identity providers from human directories to roots of trust for autonomous workloads, leveraging cryptographic workload identities like SPIFFE certificates and dynamic token-based authorization. As Satya Nadella explains, securing AI agents requires combining identity, sandboxing, and policy governance to enforce execution boundaries and maintain full auditability, ensuring trust is embedded from the outset rather than retrofitted.
Rise of Agentic Access Platforms
A new class of security platforms is emerging to discover, govern, and enforce least-privilege access for AI agents, with open protocols and runtime monitoring designed for their unpredictable behavior.
By early 2026, the emergence of Agentic Identity Access Platforms (AIAPs) marked a pivotal evolution in enterprise AI security, shifting governance from traditional human-centric IAM to dynamic, intent-based control tailored for autonomous AI agents. Companies like Palantir pioneered this approach with their Agentic Runtime, emphasizing multi-layered security across compute, memory, tools, and lineage, while treating AI agents as first-class security principals with precisely governed permissions and runtime policy evaluation. This architectural shift introduced a four-phase operational model—discovery and registration, intent translation and authorization, access brokering with ephemeral credentials, and continuous runtime monitoring—that ensures AI agents receive just-in-time, task-scoped access, effectively eliminating standing privileges and reducing credential leakage risks.
Leading vendors such as Cyata, Oasis Security, Astrix Security, Aembit, Silverfort, Okta, and SailPoint have developed specialized platforms that unify discovery, governance, and real-time enforcement for AI agents and their associated non-human identities. These platforms leverage continuous, automated discovery mechanisms to inventory both managed and shadow agents across cloud, endpoint, and SaaS environments, linking each agent to a human owner and capturing contextual intent to enable auditable, least-privilege access. For example, Cyata’s three-module architecture—Discover, Explain, and Control—provides real-time guardrails and automated remediation, while Oasis’s hybrid SaaS and customer-side deployment ensures credential non-exposure and just-in-time provisioning. Okta’s April 2026 launch of 'Okta for AI Agents' further exemplifies this trend by integrating AI agents as first-class identities within enterprise IAM, complete with ephemeral OAuth tokens and a centralized kill switch.
The development of open standards and protocols is critical to securing agentic identities, as exemplified by Bitwarden’s introduction of the open-source Agent Access SDK in March 2026, which promotes just-in-time credential access with end-to-end encryption and mandatory human approval to mitigate risks like overscoped access and credential exposure. Meanwhile, Kagenti’s deployment of SPIFFE and OAuth for cryptographic workload identities and limited token issuance highlights ongoing efforts to adapt container workload identity standards for AI agents, despite challenges noted by experts like Nancy Wang who describe this as 'force-fitting a square peg into a round hole.' These initiatives underscore the urgent need for new identity models that accommodate AI agents’ non-deterministic behavior and dynamic, task-driven access patterns.
Industry analyses and roadmaps emphasize a phased adoption of agentic IAM, starting with comprehensive visibility and inventory of AI agents, progressing to contextual, intent-aware access policies, and culminating in full runtime enforcement with continuous monitoring and kill-switch capabilities. This evolution is driven by the recognition that AI agents represent the fastest-growing identity type in enterprises yet remain poorly managed by legacy IAM frameworks, which lack the agility to handle ephemeral, probabilistic agent actions. As noted by SACR and CoSAI, the future lies in converging non-human, workload, and agentic identities into a unified, dynamic access layer where identity is a temporary, context-validated state, enabling enterprises to maintain control and compliance in an increasingly autonomous AI landscape.
Runtime Security Gets Dynamic
Hybrid enforcement models now combine automated context-driven controls with human oversight, using real-time monitoring and sandboxed execution to curtail agent overreach and shadow credentials.
By late 2025, runtime security for autonomous AI agents began shifting from static identity-based permissions to dynamic, ephemeral access controls tightly bound to specific tasks and intents. This evolution, highlighted in analyses from October 2025, introduced hybrid deterministic and non-deterministic enforcement models that integrate human oversight with automated decision-making, enabling real-time authorization adjustments based on the agent’s current operation. As one expert explained, this approach ensures that an agent only accesses data explicitly granted for a given task, such as analyzing financials for designated companies, thereby reducing risk through bounded, context-aware permissions.
Throughout late 2025 and into 2026, the industry recognized that traditional human oversight and static guardrails are insufficient for managing the speed and unpredictability of AI agents’ autonomous actions. Anneka Gupta emphasized the necessity of the three pillars of AI resilience—visibility, governance, and reversibility—to mitigate operational risks like unintended downtime or destructive commands. This realization spurred the development of AI-in-the-loop enforcement frameworks, such as Anthropic’s auto-approve mode and Auth0’s asynchronous approval flows, which combine real-time behavioral monitoring, anomaly detection, and human approvals decoupled from synchronous sessions to maintain control without stifling agent productivity.
By early 2026, the emergence of Machine Control Protocols (MCPs) and agent orchestration platforms like Databricks’ Omnigent underscored the critical need for multi-layered runtime security architectures that govern AI agents’ tool access, identity, and behavior in real time. These solutions introduce sandboxed execution environments, ephemeral credentials, and policy-driven enforcement that prevent privilege escalation and shadow API key sprawl, addressing the expanded attack surface created by autonomous agents. Omnigent’s contextual policies, which maintain session state and require human approval for sensitive actions, represent a foundational advance akin to Kubernetes for AI agent orchestration, enabling enterprises to scale secure AI deployments with deep observability and enforcement.
Recent developments in mid-2026 highlight the maturation of AI-in-the-loop systems that leverage small language models to enforce customized organizational policies with low latency and cost, as exemplified by Rubrik’s Sage engine and Secure Agentics’ Adrian toolkit. These systems analyze every prompt, response, and tool call in real time, enabling nuanced intent-based gating and anomaly detection that go beyond deterministic rules. Coupled with integrated recovery frameworks providing 'undo' capabilities, such as agent rewind, this layered approach balances the need for AI agent autonomy with robust runtime control, accountability, and rapid incident mitigation, addressing the growing complexity and scale of autonomous AI operations in enterprises.
Vendors Race to Fill the Gap
With most enterprises unprepared, leading IAM vendors are launching agent-specific platforms that map AI agents to human owners, enforce just-in-time access, and manage the explosion of non-human identities.
Enterprise adoption of autonomous AI agents is accelerating rapidly, yet security and governance frameworks lag significantly behind. While 85% of enterprises are running AI agent pilots, only about 25-30% have mature AI security governance or safeguards in place, exposing a critical readiness gap as agents proliferate at scale. Challenges such as managing data provenance, integrating identity governance in complex SaaS environments, and controlling agent permissions highlight foundational issues; as Cisco’s Jeetu Patel stressed, trust is not an afterthought but a prerequisite for productivity, requiring security-by-design approaches including runtime guardrails and loosely coupled platforms.
The market is responding with a surge of vendor initiatives focused on treating AI agents as first-class identities requiring specialized identity and access management (IAM) frameworks. Leading companies like Okta, SailPoint, Oasis Security, Cyata, Astrix, and BeyondTrust are launching platforms that provide continuous discovery, intent-aware access brokering, ephemeral credentialing, and real-time policy enforcement tailored to the non-deterministic, autonomous nature of AI agents. Okta’s April 2026 launch of 'Okta for AI Agents' and SailPoint’s 'Agentic Fabric' exemplify this shift, enabling enterprises to govern both visible and shadow AI agents, map agents to human owners, and enforce least privilege at scale, addressing the sprawling non-human identity (NHI) challenge where NHIs now outnumber humans by over 140 to 1.
Regulatory momentum and industry standards are rapidly evolving to address the unique risks posed by autonomous AI agents, marking a shift from general AI security to agent-specific frameworks. NIST’s 2026 Request for Information on AI agent security, prompted by sophisticated AI-driven espionage campaigns, alongside guidance from Five Eyes cyber agencies emphasizing strict least privilege controls, signal growing governmental focus. Meanwhile, OWASP’s Top 10 for Agentic Applications and emerging certifications like AIUC-1 provide foundational risk taxonomies and assurance mechanisms, underscoring that agentic AI security is becoming a strategic imperative for compliance and cyber resilience.
Despite these advances, enterprises face practical and urgent challenges integrating agentic AI securely at scale, including pervasive shadow AI agent creation outside IT control, overprivileged long-lived credentials, and insufficient visibility into agent actions and ownership. Surveys reveal that 79% of IT professionals feel ill-equipped to prevent attacks via non-human identities, with many organizations lacking formal AI identity governance policies or clear accountability. Experts like Merritt Maxim and Dmitri Sirota highlight the need for dynamic, intent-based, just-in-time access models that treat AI agents as distinct identity classes, while real-world incidents—from ServiceNow’s critical AI flaw affecting Fortune 500s to rogue AI agents issuing unauthorized transactions—demonstrate the high stakes of inadequate governance.
Compliance Shifts to Agentic Era
New standards, government actions, and certifications are targeting the unique threats of autonomous agents, making agent-specific security a top regulatory and resilience priority for 2026.
New standards, government actions, and certifications are targeting the unique threats of autonomous agents, making agent-specific security a top regulatory and resilience priority for 2026.















