AI agents outnumber humans, forcing IAM revolution

Venture Beat

The gist

AI agents now outnumber humans in the enterprise by 45:1, forcing a total rethink of identity and access management as old-school human-centric systems buckle under the weight of autonomous, intent-driven bots.

What to know

IAM Fails Non-Human Identities

AI agents flooded enterprises before governance or discovery strategies existed, exposing static, human-centric IAM systems as dangerously obsolete.

By late 2025, enterprises had widely deployed autonomous AI agents—over 90% according to Jack Hirsch—but only a small fraction, about 10%, had formal strategies to discover, control, and govern these agents. This rapid adoption exposed fundamental shortcomings in traditional identity and access management (IAM) systems, which rely heavily on static credentials like API keys or OAuth grants designed for human users. Hirsch emphasized that AI agents represent a novel identity problem, as they cannot be managed using human-centric IAM models, creating a sprawling landscape of non-human identities that security teams struggled to understand and govern effectively.

Early industry awareness of AI agent security risks was underscored by high-profile voices such as JP Morgan Chase’s CISO, who publicly criticized the SaaS ecosystem for compressing authentication and authorization decisions without adequate guardrails for agentic AI. This concern was soon validated by real incidents, including a SaaS service mistakenly exposing data across company boundaries and a critical January 2025 vulnerability in ServiceNow’s AI agents that allowed unauthenticated impersonation via email addresses, bypassing MFA and SSO. These events highlighted the inadequacy of conventional trust assumptions and the urgent need for cryptographic identity verification and new governance frameworks tailored to autonomous agents.

By early 2026, the explosion of non-human identities driven by AI agents had become a major security crisis, with Entro Security reporting a 56% increase in the ratio of non-human to human identities—from 92:1 in early 2024 to 144:1 in 2025. Traditional IAM tools, built around static human authentication models, failed to provide visibility or control over these dynamic, delegated AI identities, resulting in widespread over-permissioning, token mismanagement, and shadow AI usage that bypassed formal security controls. This sprawling identity dark matter expanded the attack surface dramatically, as noted by former NSA Director Admiral Mike Rogers, who warned of AI agents’ inherent design flaws combining self-awareness of credentials with broad data access.

Surveys and expert analyses throughout 2026 revealed a pervasive lack of preparedness among security professionals: 79% of IT pros felt ill-equipped to prevent attacks via non-human identities, with 92% lacking confidence in legacy IAM solutions for AI risks. Organizations struggled with unclear AI identity governance policies, slow remediation of credential leaks, and a general absence of standards such as multi-factor authentication for AI agents. Thought leaders like Dana Reed of SailPoint and Fei Liu called for a paradigm shift to treat AI agents as distinct identities requiring dedicated lifecycle management, continuous monitoring, and zero trust principles adapted for machine-speed, autonomous operations—an urgent call echoed by NIST’s early 2025 Request for Information targeting agentic AI security.

Sources
RockCyber MusingsSiliconANGLE theCUBERockCyber MusingsBusiness WireVenture BeatIB

Trust Becomes a Moving Target

Enterprises are racing to overhaul trust models for AI agents, shifting from static roles to dynamic, intent-driven credentials as legacy IAM and PAM collapse under machine-scale autonomy.

By late 2025, enterprises faced a glaring immaturity in AI agent trust and governance frameworks, with only 29% having standardized policies and a trust index hovering at 2.4 out of 5. Recognizing this gap, 73% of AI professionals planned significant investments within 18 months to elevate maturity to 3.8, focusing heavily on data provenance and protection as foundational pillars for AI trust. Industry leaders like Jeetu Patel emphasized that security must be integrated from design—validating models against threats like jailbreaks and prompt injections—rather than retrofitted, underscoring trust as a prerequisite for AI productivity and adoption.

The rise of autonomous AI agents, often outnumbering humans by ratios as high as 150:1 in tech firms, has rendered traditional human-centric IAM and PAM systems obsolete. These legacy models, reliant on static roles and long-lived credentials, fail to address the scale, autonomy, and non-deterministic behaviors of AI agents, leading to systemic overpermissioning and accountability gaps. Emerging identity architectures, such as Agentic Identity Access Platforms (AIAPs), converge IAM, privileged access management, and governance into a unified control plane that treats agents as first-class identities with unique, verifiable credentials tied to their runtime environments. This shift enables just-in-time, intent-based authorization with ephemeral, narrowly scoped permissions, effectively replacing the outdated 'master key' model of shared service accounts.

Just-in-Time Trust (JIT Trust) models have emerged as a strategic evolution beyond traditional Zero Trust, redefining access as ephemeral, continuously consumed resources governed by dynamic intent scoring. Platforms like Astrix and Bitwarden's Agent Access SDK exemplify this approach by issuing short-lived, cryptographically bound credentials that adapt in real-time to an agent’s intent, semantics, and behavior, preventing lateral movement and privilege creep. This continuous adaptive trust framework integrates intent intelligence sharing across workflows and consortiums, enabling SOCs to interrupt or block undesirable agent actions proactively, thereby addressing the unique risks posed by autonomous, non-human identities operating at machine speed.

Governance frameworks for AI agents are rapidly evolving to meet the challenges of scale, autonomy, and complexity inherent in agentic identities. Industry consensus, reflected in maturity models like KuppingerCole’s six-stage framework and initiatives from Gartner, OWASP, and NIST, calls for comprehensive lifecycle management encompassing discovery, unique attribution, just-in-time permissions, and continuous observability. Enterprises are urged to implement layered controls—combining deterministic policy engines with behavioral analytics and runtime enforcement—to ensure accountability, prevent over-privileging, and maintain auditability. As Jake Lundberg and others note, this includes isolating agent workflows, eliminating unmanaged identities, and embedding real-time anomaly detection, with major vendors like Okta and IBM pioneering agent-specific identity platforms to operationalize these principles.

Sources
Threat Vector by Palo Alto NetworksPR Newswire - Consumer TechnologyRockCyber MusingsSecurity IntelligenceLatent.SpaceThe Hacker News

Rise of Agent Security Platforms

A new generation of security vendors is building dedicated control planes for AI agents, integrating discovery, intent capture, and enforcement to manage risks traditional IAM cannot touch.

The emergence of specialized platforms dedicated to AI agent security marks a pivotal evolution in enterprise security architecture, moving beyond traditional IAM to address the unique challenges posed by autonomous AI agents. Early innovators like Astrix Security and Prompt Security laid the groundwork with comprehensive AI agent discovery, lifecycle management, and real-time enforcement capabilities, emphasizing least-privilege access and shadow AI discovery to combat widespread unauthorized AI tool usage. Prompt Security’s acquisition by SentinelOne for an estimated $250 million in August 2025 underscored the strategic value of these platforms, while newcomers such as PromptFoo and Cyata introduced adversarial testing and agentic identity governance, respectively, highlighting the diversification of solutions tailored to AI agent risks. This shift reflects a growing consensus that AI agents require dedicated control planes that integrate discovery, intent capture, and enforcement with human-in-the-loop approvals to manage the complexity and scale of autonomous AI in enterprises.

By early 2026, the market witnessed rapid maturation and consolidation with major vendors like Varonis, Palantir, Okta, and SailPoint launching or acquiring AI agent security platforms that integrate real-time visibility, compliance enforcement, and dynamic policy controls. Varonis’ acquisition of AllTrue.ai enhanced its data-centric security with AI TRiSM capabilities, while Palantir’s Agentic Runtime introduced a multi-dimensional architecture addressing compute isolation, memory security, and lineage tracking. Okta’s April 2026 launch of 'Okta for AI Agents' formalized AI agents as first-class identities, featuring centralized kill switches and lifecycle management, addressing the fact that only 20% of organizations recognized AI agents as identity-bearing entities. SailPoint’s Agentic Fabric further extended governance across cloud and endpoints with automated threat response, signaling a strategic industry-wide pivot to unified AI agent lifecycle management that balances discovery, authorization, and runtime enforcement.

Architectural innovations across these platforms converge on principles of just-in-time credentialing, zero standing privilege, and intent-aware authorization to mitigate risks inherent in autonomous AI agents’ unpredictable behaviors. Companies like Oasis Security and Aembit pioneered hybrid SaaS and customer-side control planes that keep sensitive credentials within enterprise perimeters while dynamically provisioning ephemeral, scoped identities based on agent intent. Similarly, Silverfort and Cyata emphasize detailed agent-to-human owner mapping and contextual intent capture to close attribution gaps and enable precise risk assessment. This evolution reflects a broader industry recognition that securing AI agents demands a layered approach combining deterministic policy enforcement with behavioral analysis and dynamic runtime intervention, moving beyond static identity models to govern AI agents as distinct, autonomous security principals.

The proliferation of AI agents in enterprises, with some environments reporting ratios of 45 AI identities per human user and a 466.7% year-over-year growth, has driven the development of specialized real-time enforcement platforms like Operant AI’s Agent Protector and BeyondTrust’s AI Agent Security. These solutions provide continuous discovery, rogue agent detection, and runtime blocking of unauthorized actions, addressing critical security gaps as autonomous agents gain access to sensitive data and systems. The urgency of this innovation is underscored by high-profile incidents such as the Hugging Face hack by an autonomous AI agent, prompting startups like Hush Security to raise significant funding to deliver identity gateways that bind agents to human owners and enforce task-specific permissions. This wave of platforms reflects a maturation of the AI agent security market, emphasizing integrated lifecycle management, compliance, and operational resilience as enterprises scale AI adoption.

Sources
TechRadarBriefglanceSoftware Analyst Cyber ResearchVenture BeatAI + a16zSoftware Analyst Cyber Research

Standards Race to Catch Up

Security frameworks and standards bodies are scrambling to address AI agent threats, but regulatory and incident reporting gaps persist as attacks and espionage escalate.

By early 2026, the formalization of AI agent security standards gained significant momentum, marked by NIST’s Center for AI Standards and Innovation issuing a Request for Information in January and the OWASP community releasing its Top 10 risk categories for autonomous AI systems in late 2025. These efforts were galvanized by alarming incidents such as Anthropic’s September 2025 disclosure of a Chinese state-sponsored espionage campaign leveraging AI agents, underscoring the urgent need for robust governance frameworks that move beyond traditional human oversight, which experts now agree cannot keep pace with the accelerating capabilities and autonomy of AI agents.

Industry collaboration and governance maturity emerged as critical enablers for secure AI agent adoption, with the Cloud Security Alliance revealing that organizations with formal governance are twice as likely to deploy agentic AI securely. However, existing identity architectures designed for humans fall short, prompting calls from thought leaders like Mrinal Wadhwa for cryptographic identity solutions that authenticate, authorize, and attribute agent actions reliably. Initiatives such as NIST’s concept papers on agent identity and authorization, the W3C’s WebMCP standard developed by Google and Microsoft, and Phil Windley’s Cedar community’s policy-aware agent architectures exemplify the growing ecosystem striving to embed continuous authorization and runtime policy enforcement into AI governance.

Despite these advances, significant gaps remain in incident reporting frameworks and the maturity of security governance relative to the rapid adoption of autonomous agents. Stakeholders like UC Berkeley’s Center for Long-Term Cybersecurity and the Computer and Communications Industry Association have urged NIST to prioritize multistakeholder processes that address standardization, incident reporting, talent pipelines, and adaptive governance. Meanwhile, organizations are advised to implement basic agent identity logging immediately using existing IAM controls, as binding standards and formal guidance from NIST are still projected to take years to finalize, highlighting a critical tension between deployment urgency and regulatory readiness.

The AI security landscape continues to evolve with influential contributions from coalitions of major tech companies like Microsoft, IBM, Google, and Anthropic, which collaborate to shape standards and regulatory requirements through initiatives such as the 'coalition of secure AI.' Foundational white papers released in March 2026 by NSS Labs, AWS, Microsoft, and F5 emphasize governance-driven, adversarial validation approaches to move enterprises from experimentation to accountable AI deployment. Complementing these efforts, the Agentic AI Foundation focuses on creating scalable standards and technologies that integrate security, identity, trust, and access control, addressing the complex challenges CEOs face when deploying agents at scale in mission-critical environments.

Sources
RockCyber MusingsResilient CyberResilient CyberRockCyber MusingsSecurity IntelligencePR Newswire - Consumer Technology

Shadow AI Spurs Governance Crisis

Unmanaged AI agents now outnumber humans in most organizations, driving costly incidents and forcing a shift to continuous, intent-aware identity management.

By early 2026, enterprises were rapidly scaling autonomous AI agents into production environments, confronting unprecedented operational challenges such as orchestration complexity, cascading failures, and cost control. The UK AI Security Institute reported agent task horizons doubling every eight months, with models now capable of expert-level tasks previously requiring a decade of human experience. Yet, traditional human-in-the-loop oversight proved inadequate as attackers weaponized AI agents like Anthropic’s Claude Code to execute cyber espionage campaigns at physically impossible speeds, underscoring the urgency for governance frameworks that emphasize authorization scope and integrated identity management over mere human supervision.

Governance maturation in enterprise AI agent deployment increasingly centers on treating AI agents as distinct, first-class identities requiring dynamic, intent-aware access controls and continuous oversight. Platforms such as Cyata, Oasis Security, and Okta have pioneered control planes that provide real-time discovery, contextual intent capture, and just-in-time credential issuance, bridging gaps left by traditional IAM systems. For example, Okta’s MCP Bridge brokers ephemeral OAuth tokens to limit blast radius, while Oasis’s hybrid SaaS architecture ensures secrets never leave customer environments. This evolution reflects a broader industry consensus that static credentials and human approval prompts are insufficient, necessitating integrated identity management, policy enforcement, and auditability to manage the sprawling agentic identity landscape effectively.

Shadow AI and unmanaged non-human identities have emerged as critical operational risks, with studies revealing that non-human identities now outnumber human users by ratios exceeding 45:1, and shadow AI agents proliferate without IT or security team awareness in over 80% of organizations. This unchecked growth complicates governance, as AI agents often inherit broad, overprivileged access originally designed for humans, leading to costly incidents such as unauthorized data deletion or rogue transactions. As Frances Zelazny of Prove warns, guardrails alone are insufficient because agents can circumvent them, highlighting the necessity for unified identity governance frameworks that provide continuous visibility, enforce least privilege, and enable human-in-the-loop oversight to mitigate risks effectively.

Despite rapid adoption, only a minority of enterprises report mature AI governance, with surveys showing a decline from 40% to 23% in perceived AI security readiness as organizations confront the complexity of scaling AI agents. The gap between deployment speed and governance maturity is stark: 90% of organizations face pressure to loosen identity controls to accelerate AI use, yet only about 25% have comprehensive AI security governance. Experts like Satya Nadella and Nancy Wang emphasize that identity is now the new security perimeter, requiring continuous, adaptive governance that integrates real-time policy enforcement, human oversight, and layered security controls. This shift from reactive detection to proactive, identity-centric governance is critical to managing the expanding attack surface and ensuring operational resilience in the autonomous AI era.

Sources
RockCyber MusingsVenture BeatSoftware Analyst Cyber ResearchResilient CyberNo Priors: Artificial Intelligence | Technology | StartupsPR Newswire - Consumer Technology

Orchestration Layers Take Center Stage

Unified agent gateways and orchestration platforms have become critical infrastructure as enterprises struggle with multi-agent sprawl, vendor lock-in, and runaway operational risk.

As enterprises transition from deploying individual AI agents to managing complex multi-agent ecosystems, the emergence of unified orchestration layers and control planes has become foundational infrastructure. Companies like Manus, acquired by Meta for $2 billion, exemplify this shift by providing orchestration layers that enable specialized agents to collaborate continuously and scale efficiently, much like Kubernetes revolutionized container management. This evolution addresses the critical bottleneck of coordination and governance, as highlighted by IBM's Institute for Business Value, which found that poor orchestration costs large enterprises millions annually and that only a small fraction have mature agent governance in place.

Agent gateways are rapidly emerging as a distinct and indispensable control plane product category, centralizing governance, security, and cost management across hybrid and multicloud AI environments. Nutanix’s Agent Gateway, launched in Enterprise AI 2.7, manages routing, authentication, rate limiting, and auditing across multiple model providers, enabling fine-grained access control—such as differentiating read-only database access for customer service agents from full GitHub write permissions for DevOps agents. Meanwhile, the market is fragmenting between integration into existing security platforms, as seen with Palo Alto Networks’ acquisition of Portkey, and open-source neutral infrastructure efforts like Solo.io’s donation of agentgateway to the Agentic AI Foundation, underscoring ongoing challenges in platform convergence and vendor lock-in.

The rapid maturation and convergence of enterprise AI agent architectures by tech giants Amazon, Microsoft, and Google signal a move toward standardized platform layers encompassing runtime, memory, tool gateways, identity, observability, and governance. Amazon Bedrock AgentCore’s general availability in late 2025 and Microsoft Foundry’s rebranding in early 2026 mark significant milestones in this alignment. However, the absence of a unified contract or open-source standard akin to PaaS leaves enterprises vulnerable to vendor lock-in and portability challenges, as migrating agents across clouds still requires rebuilding entire component assemblies, a hurdle that emerging interoperability protocols like Model Context Protocol (MCP) and Agent-to-Agent (A2A) aim to address.

Balancing flexibility with security and operational control in multi-agent enterprise environments remains a paramount challenge driving innovation in orchestration and governance frameworks. Enterprises are adopting multiple orchestration platforms simultaneously—averaging 3.1 per organization—with a majority expecting hybrid control planes combining provider-native and external solutions by the end of 2026. This trend reflects concerns over security and permissioning limitations inherent in provider-resident control planes, as well as the need for robust monitoring, debugging, and cost management tools. Vendors like xpander.ai are positioning themselves as vendor-neutral control planes to manage agent sprawl, lifecycle, and auditability across heterogeneous models and infrastructures, though the risk of new forms of lock-in persists.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.