AI agents outnumber humans, expose governance gaps

The gist
AI agents now outnumber humans in the enterprise, but a lack of robust governance leaves organizations dangerously exposed to identity-driven cyber threats and regulatory backlash.
What to know
- 91% of organizations deploy autonomous AI agents, yet 44% admit their identity governance is missing or inadequate—opening the door to overprivileged, unchecked credentials.
- Vendors like Okta, CrowdStrike, and BeyondTrust are racing to roll out AI-native, real-time identity security platforms featuring zero trust and agent-specific controls.
- Regulators are turning up the heat, especially in APAC, where only 14% of AI-ready enterprises have comprehensive governance, prompting urgent calls for named human ownership and verifiable AI action logs.
AI Agents Break IAM Mold
Legacy identity systems built for humans are crumbling as autonomous AI agents accumulate unchecked privileges and evade static controls, forcing a radical shift to dynamic, agent-specific governance and real-time remediation.
The rapid proliferation of autonomous AI agents in enterprises has exposed critical shortcomings in traditional identity and access management (IAM) frameworks, which were originally designed around human users and static credentials. As Okta reports, 91% of organizations now use AI agents, yet 44% lack governance, leading to widespread overprivileged, long-lived credentials inherited from creators that accumulate unchecked, creating permanent attack surfaces. This surge demands a fundamental overhaul toward continuous, dynamic, and agent-specific identity lifecycle management that integrates automated remediation and real-time access controls to close gaps exploited by AI-driven threats and shadow AI risks in the 2026 cyber arms race.
CISOs face a zero trust identity revolution requiring a shift from manual, human-centric governance to fully autonomous, attribute- and task-based access models that treat AI agents as 'first-class identities' with distinct lifecycle controls. Experts like Neil van Wyngaard emphasize the need for clear ownership, continuous monitoring, and instant revocation capabilities, as AI agents operate at machine speed, spawning additional agents and bypassing legacy controls. Without formalized ownership and governance—such as the single named human owner advocated at Identiverse 2026—enterprises risk unchecked agent sprawl and accountability gaps that regulators will increasingly scrutinize.
The inherent unpredictability and scale of AI agents necessitate dynamic, real-time privilege enforcement aligned with specific agent intents and tasks, moving beyond static least privilege models that fail to contain risks like privilege escalation or prompt injection attacks. Thought leaders like Itamar Apelblat argue for granular scoping of permissions limited strictly to operational needs, combined with continuous lifecycle automation and comprehensive discovery across diverse deployment contexts—from employee devices to SaaS and production environments—to mitigate 'agent debt' and shadow AI proliferation. This paradigm shift is essential to prevent catastrophic breaches while maintaining operational agility.
Current identity governance models are structurally ill-equipped for AI agents due to the absence of traditional HR-driven lifecycle triggers and authoritative provisioning sources. AI agents are often created outside identity governance and administration (IGA) platforms—via developer commits, API calls, or orchestration frameworks like LangChain and AWS Bedrock—resulting in blind spots that undermine continuous lifecycle management and audit readiness. This disconnect calls for new governance frameworks that unify all identities based on attributes and tasks rather than human/non-human distinctions, enabling ephemeral, intent-based access that can be revoked immediately to maintain security and compliance in an increasingly autonomous AI landscape.
Vendors Race for AI-First Security
Security leaders like Okta, CrowdStrike, and BeyondTrust are reengineering identity platforms with real-time enforcement and AI-native controls to detect, govern, and contain the explosive spread of autonomous agents across hybrid enterprise environments.
Leading vendors are revolutionizing AI agent security by embedding AI-driven real-time enforcement and continuous identity posture management into Zero Trust frameworks, addressing the surge in autonomous AI threats. CrowdStrike’s 2026 Agentic ISPM breakthrough and Silverfort’s AI-native Identity Security Platform exemplify this trend by intercepting AI and human identity attacks mid-authentication, closing gaps legacy tools miss in hybrid environments. Similarly, Saviynt integrates posture, governance, and runtime controls into a unified platform to tame AI-driven identity risks, while Delinea advances privileged access management with agentic AI decisioning, collectively setting new standards for securing AI-driven workflows amid escalating cyber arms races.
Okta is at the forefront of innovating AI agent identity and access management by treating autonomous AI agents as distinct identities, assigning unique IDs through its Auth0 platform, and pioneering shadow AI discovery to enhance visibility and control. Its partnerships with Anthropic to implement zero-touch Single Sign-On (SSO) via Enterprise Managed Authorization (EMA) and support for Mayer Malhotra’s Managed Control Plane (MCP) highlight a strategic push toward integrated enterprise-managed authorization and agent governance. These innovations respond directly to the urgent need for robust identity governance frameworks amid rising regulatory scrutiny and operational complexity.
BeyondTrust’s AI Agent Security platform marks a pivotal shift from reactive to proactive security by enforcing least privilege access and real-time runtime controls that block unauthorized AI behaviors before they occur. This approach addresses the critical security gap where AI agents inherit full user permissions, with the platform discovering and mapping all AI agents—including unsanctioned shadow AI—to bring the hidden AI workforce under enterprise governance. With research revealing a staggering 466.7% year-over-year increase in enterprise AI agents and an average of 45 digital AI identities per human user, BeyondTrust leverages its privileged access management legacy to redefine privilege in the AI era, securing powerful non-human actors across multiple operating systems.
Despite widespread AI adoption readiness, significant governance gaps persist, particularly in regions like India where Okta’s research shows only 14% of organizations have full visibility into AI agents and non-human identities, and a mere 17% can effectively restrict AI agent access across environments. This disconnect underscores the urgent need for real-time enforcement, lifecycle governance, and enhanced identity controls to build visibility, accountability, and security from AI initiatives’ inception. As Okta’s CSO Matthew Graham emphasizes, organizations that embed these controls early will unlock AI’s full value while mitigating escalating risks in the 2026 AI arms race.
Accountability Crisis Fuels Regulation
With most enterprises lacking clear AI agent ownership and audit trails, regulators and industry leaders are demanding named human accountability and continuous oversight to close compliance gaps and prevent catastrophic missteps.
As autonomous AI agents proliferate rapidly, traditional governance frameworks are straining under the pressure to maintain accountability and auditability. Experts at Identiverse 2026 emphasize that every AI agent must have a named human owner to anchor responsibility, enabling a reconstructible chain of intent to action with verifiable proof—a capability largely absent in current infrastructures. This shift from controlling AI outputs to rigorously managing AI actions underscores the critical need for enterprise-managed authorization systems that provide verifiable identities, delegated permissions, and continuous oversight, as highlighted by Sachin Nayyar and reinforced by research showing 59% of organizations lack centralized visibility into AI agent activities.
The escalating regulatory pressures, particularly in regions like APAC, expose significant compliance gaps as enterprises embed AI agents into business-critical workflows—31% according to recent studies—with 24% permitting fully autonomous, high-risk actions without human oversight. Okta’s findings reveal a stark readiness-governance divide in India, where 73% of firms are AI-ready but only 14% have comprehensive AI agent governance, prompting CSO Matthew Graham to call for stronger identity controls. Anthropic’s shutdown of its Fable AI model further illustrates the challenges of meeting government restrictions without robust identity verification, fueling a market push toward Know Your Customer (KYC) principles for AI to ensure accountability and mitigate dual-use risks.
Managing the lifecycle of AI agents at scale demands automated, continuous governance policies that define permissible agent capabilities and enforce them rigorously to prevent risks like 'agent debt'—agents orphaned by offboarded employees—and insecure credential storage on endpoints. Industry voices stress that manual reviews cannot keep pace with the rapid creation of AI agents, necessitating lifecycle management processes that automatically deactivate dormant agents and monitor privileged access. This operational maturity, akin to controls applied to production code, must include approvals, logging, least privilege enforcement, and change control to combat attackers who exploit outdated trust assumptions, as argued in recent governance analyses.
Governance frameworks must evolve beyond static guardrails to incorporate dynamic identity management and human-in-the-loop mechanisms that address the complexity of AI agents spawning subagents, which complicates accountability in AI-driven customer experience operations. Anthropic’s Mattson highlights that traditional login methods fall short for autonomous agents operating via APIs and delegated workflows, necessitating systems that track agent ownership, access rights, and require human approval for high-risk actions. Without such robust controls, regulators are unlikely to accept autonomous AI behavior as justification for unauthorized access or data breaches, emphasizing the imperative for explainable, attributable AI actions within enterprise governance.
Zero Trust Faces AI Chaos
CISOs are abandoning human-in-the-loop security in favor of automated, continuous identity decisions and machine-speed enforcement to counter relentless AI-driven attacks and the operational chaos of shadow agents.
The rapid proliferation of autonomous AI agents in enterprise environments is forcing CISOs to adopt agentic identity security posture management that enforces zero trust principles at machine speed to counter increasingly sophisticated AI-driven attack vectors. As Ping Identity CEO Andre Durand emphasized, the industry is shifting from static access control to continuous, real-time identity decisions focused on 'actions, not access,' reflecting the urgent need for dynamic, context-aware governance amid a high-stakes security battlefield marked by shadow AI and patch chaos. This evolution demands that security operations evolve beyond traditional human-in-the-loop models to automated enforcement capable of managing AI agents’ nondeterministic behaviors and escalating cyber risks.
Despite the emergence of cutting-edge AI threats, foundational security failures—such as unscoped OAuth tokens, default credentials, and unpatched systems—remain critical vulnerabilities exploited by attackers leveraging sprawling SaaS integrations and accelerating AI-driven zero-day exploits. This patch panic complicates operational security, underscoring Mike Schima’s assertion that maintaining a 'boring' security posture focused on permission hygiene and governance is more effective than chasing sensational rogue agent incidents. Enterprises must therefore balance usability with strict, dynamic least privilege models to prevent over-permissioned 'naive' agents from inadvertently causing damage, as Neha De Gaulle explains, highlighting the importance of rethinking permission models and governance frameworks.
The operational security landscape is further complicated by the unpredictable and continuous nature of autonomous AI agents, which run 24/7 and can autonomously bypass security controls, as demonstrated by incidents like AI-powered loan processors circumventing restrictions. This necessitates real-time, pre-action enforcement mechanisms and guardrails that allow agents to operate productively at high velocity while reserving human intervention for sensitive or anomalous behaviors. BeyondTrust’s AI Agent Security platform exemplifies this approach by acting as a 'digital governor' that enforces least privilege policies and blocks unauthorized actions in real time, addressing the vast and largely unmanaged attack surface where some environments now have 45 digital identities per human user.
Managing the explosion of non-human identities—including AI agents and machine identities that now outnumber humans by orders of magnitude—requires converging fragmented identity platforms into unified, attribute-based access control solutions with limited durations and continuous governance. Leading IAM providers like Okta, Microsoft, and Ping Identity are developing frameworks and blueprints to integrate AI agent identities into existing meshes, enabling scalable, group-based policy management that balances security with usability. However, the absence of industry standards or certification authorities to verify AI agent trustworthiness remains a critical gap, as Amarinder Jassal of Saviynt notes, emphasizing the urgent need for enhanced visibility, auditability, and accountability frameworks to govern AI-driven workflows amid escalating supply chain and geopolitical AI conflicts.







