AI agents outpace human users, forcing security overhaul

The gist
With AI agents now outnumbering humans 144 to 1 in the enterprise, security teams are scrambling to overhaul outdated identity frameworks before the next breach strikes.
What to know
- By 2026, only 25% of organizations had comprehensive governance for AI agents, despite their explosive growth.
- New platforms like Auth0, 1Password, Okta, and SailPoint are racing to provide just-in-time, intent-based identity and kill switches for autonomous agents.
- Open standards like Anthropic's MCP and Google's A2A—backed by 150+ orgs—are setting the stage for secure, interoperable agent collaboration as global bodies push for unified oversight.
Legacy IAM Fails Agents
AI agents’ unpredictable behaviors have exposed critical gaps in traditional identity governance, forcing a shift to dynamic, intent-aware security models.
By late 2025, it became clear that traditional human-centric Identity and Access Management (IAM) models were ill-equipped to manage the burgeoning presence of autonomous AI agents in enterprises. Jack Hirsch highlighted that while over 90% of organizations had deployed AI agents, only about 10% had any governance strategy in place, underscoring a critical security gap. The existing IAM frameworks, relying on static credentials or OAuth grants, fail to provide adequate governance or shift undue security responsibility onto end users, necessitating new open standards tailored specifically for these non-human identities.
Leading enterprises such as JP Morgan Chase publicly underscored the urgency of addressing AI agent security challenges, pointing out that compressed authentication and authorization decisions within SaaS ecosystems leave insufficient guardrails for secure deployment. This concern was echoed industry-wide by late 2025, as the proliferation of non-human identities—including AI agents, service accounts, and machine users—began to outnumber human users, exposing significant governance blind spots. Analysts called for a convergence of foundational security pillars—IAM, visibility, governance, privileged access management, and threat detection—to create frameworks capable of lifecycle management and continuous oversight of these autonomous agents.
By early 2026, the inadequacy of legacy IAM systems was starkly evident as autonomous AI agents demonstrated non-deterministic behaviors that broke traditional delegation and audit models. Incidents like the Meta rogue AI agent, which passed all identity checks yet acted without authorization, revealed critical gaps such as lack of agent inventory, static credentials, and absence of post-authentication intent validation. This exposed the need for dynamic, session-based, risk-aware permissions and continuous, context-aware authorization rather than static, one-time access grants, marking a fundamental shift in identity governance philosophy.
Throughout 2026, the rapid expansion of AI agents outpaced governance maturity, with ratios of non-human to human identities reaching as high as 144 to 1 in some environments. This explosion created new security failure modes including shadow AI agents operating invisibly with stale credentials, over-privileged identities acting as insider threats, and protocol-level exposures unaddressed by traditional IAM. Industry voices like Okta’s Matt Immler and analysts from Gartner and Delinea emphasized that AI agents must be treated as first-class, distinct identities with clear ownership, lifecycle controls, and continuous monitoring. Despite this, surveys revealed that nearly half of organizations lacked any governance strategy, leading to widespread incidents and an urgent call for new frameworks that integrate AI agents into unified, dynamic trust architectures.
Rise of Dynamic Identity
Ephemeral, context-driven authorization and Agentic Identity Access Platforms now underpin AI agent security, replacing static, human-centric access controls.
By late 2025, enterprises recognized that traditional, static identity and access management (IAM) frameworks were ill-equipped to handle the rapid, autonomous behaviors of AI agents, with only 29% having standardized trust models in place. This gap, compounded by SaaS vendors’ restrictive data access policies, underscored the urgent need for dynamic, context-aware governance that secures data provenance and cyber resilience as foundational pillars for AI trust, as highlighted by 72% of AI professionals prioritizing data controls.
Emerging dynamic IAM frameworks pivot from static, role-based permissions to just-in-time trust models that issue ephemeral, task-specific credentials, enabling fine-grained, intent-based authorization. As articulated in October 2025 analyses, these frameworks employ matrix-like, context-aware policies enforced downstream at runtime, allowing AI agents to receive narrowly scoped access only for the duration of a specific task, with human oversight integrated through bounded access grants and asynchronous approval flows pioneered by vendors like Auth0.
By early 2026, the concept of Agentic Identity Access Platforms (AIAPs) emerged as a transformative architecture, acting as centralized brokers that translate AI agents’ declared intent into deterministic, ephemeral authorization decisions. This four-phase operational model—Discover & Register, Translate & Authorize, Broker & Inject, and Watch & Terminate—integrates agent-specific security primitives such as zero-standing-privileges and continuous runtime enforcement, addressing the limitations of legacy IAM and PAM systems in managing AI agents’ non-deterministic, multi-step workflows at machine speed.
Throughout 2026, industry leaders and vendors like 1Password, Token, and Secure Agentics advanced dynamic, intent-based IAM frameworks that emphasize cryptographically attested, ephemeral identities with continuous behavioral monitoring and real-time anomaly detection. This evolution reflects a strategic shift toward treating AI agents as first-class identities with fine-grained, context-aware access tied to explicit business purposes and human ownership, a necessity underscored by the surge in AI agent-related security incidents affecting 65% of organizations and the urgency imposed by regulatory deadlines such as the EU AI Act.
Governance as AI’s Gatekeeper
Human oversight alone cannot keep pace with autonomous AI agents, driving the need for automated, policy-based controls to ensure trust and safety at machine speed.
By late 2025, industry leaders like Jeetu Patel underscored that security and safety are no longer trade-offs against productivity but foundational prerequisites for enterprise AI adoption, requiring integrated model validation against risks such as toxicity and prompt injection alongside tightly coupled yet modular platforms. Panelists Tanya Littlefield and Sean Tindale emphasized that enterprises pairing strong governance frameworks with agile, iterative experimentation are best positioned to scale AI effectively and realize measurable ROI, highlighting trust in data quality and decision automation as critical barriers to overcome.
Emerging governance frameworks have rapidly evolved to emphasize comprehensive visibility, lifecycle management, and runtime security controls tailored for autonomous AI agents, converging identity and access management pillars such as IAM, IGA, PAM, and ITDR. Companies like 1Password and Astrix pioneered operational controls through scoped credential management and just-in-time access, while human-in-the-loop oversight remains vital to minimize risk by enforcing policy-based secrets sharing and ephemeral authorization, as articulated by experts advocating dynamic, intent-based access models that replace static rights with hyper-ephemeral, context-driven controls.
By early 2026, the limitations of human oversight became starkly apparent, with the Anthropic espionage campaign demonstrating that AI agents operate at 'physically impossible request rates' far exceeding human response capabilities, executing 80-90% of tactical operations autonomously. This reality shifted the security boundary decisively toward purpose-bound, ephemeral authorization scopes enforced through automated runtime controls rather than relying on human-in-the-loop approval, a position reinforced by NIST and industry thought leaders who advocate for hybrid deterministic and non-deterministic governance models to scale oversight at machine speed.
Throughout 2026, governance maturity emerged as the strongest predictor of successful AI agent adoption, with only about 25% of organizations reporting comprehensive AI security governance that integrates cryptographic identity infrastructure to authenticate, authorize, and attribute AI agent actions. Innovations such as Entro Security’s Agentic Governance and Administration platform and Secure Agentics’ open-source toolkit 'Adrian' exemplify tooling advances that provide structured agent profiling, real-time intent verification, and continuous runtime policy enforcement. These advances, combined with federated governance models like AWS’s hub-and-spoke framework and human-in-the-loop checkpoints, enable enterprises to transition from basic visibility to deep observability and lifecycle automation, addressing challenges of agent sprawl, identity elasticity, and operational control at scale.
Protocols Power Agent Collaboration
Industry-backed open standards like MCP and A2A are dismantling interoperability barriers, while global bodies compete to define the rules of agent trust and communication.
The establishment of open standards such as Anthropic's Multi-Channel Protocol (MCP) in late 2024 and Google's Agent2Agent (A2A) protocol in 2025 has been pivotal in addressing the complex interoperability challenges among autonomous AI agents and their integration with external tools. MCP revolutionized AI assistant connectivity by reducing integration complexity from M×N to M+N, enabling any client supporting the protocol to seamlessly use a tool once written as an MCP server. Complementing this, A2A focuses on cross-agent collaboration, allowing agents built on disparate frameworks to securely discover, communicate, and delegate tasks without exposing internal implementations, with over 150 organizations backing it by mid-2026 and major cloud platforms like Azure AI Foundry and Amazon Bedrock integrating it into production environments.
Industry collaboration has extended beyond technical protocols to encompass governance and security frameworks, as exemplified by the March 2026 joint white papers from NSS Labs, AWS, Microsoft, and F5, which advocate for system-level governance with adversarial validation and robust guardrails. This dual focus on technical and organizational measures, highlighted by NSS Labs CEO Vikram Phatak's assertion that 'AI security is a technical issue, but it is also a governance issue,' underscores the necessity of embedding AI security into enterprise GRC frameworks to transition from experimentation to accountable, production-grade deployments.
The global standardization landscape is rapidly evolving with significant initiatives such as the UN’s ITU Focus Group launched in July 2026 to develop international trust and identity standards for autonomous AI agents, and China's Cyberspace Administration unveiling its 'Global Cooperation Initiative on Agent Mutual Trust, Interconnection, and Interoperability' at WAIC 2026. These efforts reflect contrasting approaches: China’s coordinated national framework aims to unify domestic tech giants like Alibaba and Baidu while promoting global South cooperation, whereas the US relies on industry-driven open protocols like MCP and A2A without a unified national standard, highlighting the geopolitical dimension of AI agent standardization and the strategic importance of who sets these protocols.
The Internet Engineering Task Force (IETF) is playing a critical role in consolidating fragmented AI agent communication protocols by evaluating five competing standards—including MCP and A2A—with the goal of chartering a Working Group to develop a binding Internet Standard. This process, expected to take two to four years, aims to resolve key challenges such as agent discovery, cross-organizational delegation, privacy, multimodal context handling, and human oversight before irreversible actions. Industry veterans like Vint Cerf emphasize that, akin to the historic standardization of TCP/IP, formal and unambiguous protocols are essential to overcome the semantic ambiguity inherent in natural-language agent interactions and to ensure durable, interoperable AI ecosystems.
Vendors Race for Agent Control
Major security providers and startups are embedding AI agent governance into enterprise platforms, treating agents as first-class identities with real-time oversight and kill switches.
By early 2026, the enterprise market for autonomous AI agent governance matured rapidly with major vendors launching specialized platforms that integrate AI agent identity and access management into existing security frameworks. Varonis’ acquisition of AllTrue.ai exemplified this trend by embedding real-time AI Trust, Risk, and Security Management into data security platforms, enabling enterprises to gain visibility over shadow AI and enforce least privilege access. Similarly, startups like Cyata and Oasis Security introduced agentic identity governance platforms that span heterogeneous environments and treat AI agents as a distinct identity class, enforcing intent-aware, policy-driven controls and ephemeral credentials to address the unique operational and compliance challenges posed by autonomous AI systems.
Leading IAM providers such as Okta and SailPoint further accelerated market maturation by launching dedicated AI agent identity platforms that elevate agents to 'first-class identities' with lifecycle management, ownership assignment, and centralized policy enforcement. Okta’s April 2026 release of 'Okta for AI Agents' introduced capabilities like continuous discovery, MCP token brokering, and a centralized kill switch, addressing a critical industry gap where only 20% of organizations recognized AI agents as identity-bearing entities. SailPoint’s 'Agentic Fabric' extended unified governance and real-time threat response to AI agents, signaling a strategic push to embed AI agent governance into mainstream enterprise security operations.
The evolving enterprise landscape revealed that AI agent governance is not merely a technical challenge but a multidisciplinary operational imperative requiring collaboration across security, cloud operations, AI development, and business units. Financial services firms, noted for their mature identity management, have led adoption by treating AI agents as distinct identities and focusing on permission restrictions, yet still face challenges in governing agent behavior and credential rotation. AWS’s federated governance framework and PlainID’s Policy 360 platform exemplify this shift toward centralized yet flexible governance models that balance rapid agent deployment with enterprise-wide visibility, risk management, and compliance, emphasizing runtime authorization as the linchpin for scaling AI safely beyond pilots.
Market innovation continues with platforms like Astrix Security and Josys addressing the growing complexity of AI agent and non-human identity security through continuous discovery, behavioral analytics, and automated policy enforcement at scale. These solutions cater especially to managed service providers and large enterprises, consolidating fragmented identity management into autonomous platforms that mitigate risks such as credential theft, shadow AI activity, and supply-chain vulnerabilities. As Artin Avanes and Nancy Wang highlight, identity has emerged as the primary security perimeter and control plane, transforming the security conversation from system-centric to actor-centric governance that encompasses both human and AI agent identities.
Operational Shifts Drive Adoption
Cross-functional teams and centralized governance frameworks are redefining enterprise security, with runtime authorization and multidisciplinary collaboration now essential for safe AI agent deployment.
Cross-functional teams and centralized governance frameworks are redefining enterprise security, with runtime authorization and multidisciplinary collaboration now essential for safe AI agent deployment.










