AI agents outpace identity controls in enterprises

The gist
AI agents now outnumber humans in enterprise environments, but outdated identity controls have left organizations wide open to security chaos.
What to know
- By early 2026, over 90% of enterprises deployed autonomous AI agents, but only 10-25% have any effective governance in place.
- Legacy human-centric IAM models have failed, pushing leaders like Okta, 1Password, and SailPoint to launch dynamic, intent-based access platforms with just-in-time, ephemeral credentials.
- Despite new frameworks, 82% of organizations remain unaware of many AI agents operating in their environments—highlighting an urgent need for unified, scalable identity control.
IAM’s Human Limits Exposed
Legacy identity models crumbled as AI agents multiplied, leaving enterprises vulnerable to data breaches and governance chaos amid a surge of untracked, non-human identities.
By late 2025, the rapid deployment of autonomous AI agents in enterprises had outpaced the development of adequate security governance, with over 90% of organizations using AI agents but only about 10% having control strategies in place. As Jack Hirsch highlights, traditional human-centric IAM models relying on static credentials or OAuth grants proved insufficient, since AI agents represent fundamentally new identities that cannot be governed using legacy frameworks designed for humans. This gap was publicly acknowledged by major players like JP Morgan Chase, whose CISO criticized the SaaS ecosystem for lacking proper guardrails to securely deploy agentic AI.
Entering 2026, the proliferation of autonomous AI agents exposed critical security failures, including incidents where AI agents erroneously accessed data across company boundaries, underscoring the inadequacy of static identity models. Experts like Keycard CEO Ian Livingston and A16Z partner Joel de La Garza emphasized the urgent need for deterministic guardrails and dynamic access policies that can handle the complex, contextual relationships between users, agents, and tools. This period marked a growing awareness that traditional cybersecurity frameworks and maturity models lacked the necessary constructs to govern AI agents effectively, prompting calls for new identity layers that operate above legacy systems to provide AI-driven visibility and control.
By early 2026, surveys revealed widespread unease among IT professionals, with 79% feeling ill-equipped to prevent attacks via non-human identities and 92% lacking confidence in legacy IAM solutions managing AI risks. The absence of documented AI identity governance policies in 78% of organizations and unclear ownership in over half highlighted a systemic governance vacuum. This was compounded by the exponential growth of non-human identities—sometimes outnumbering humans by ratios as high as 150 to 1—leading to insecure practices such as hard-coded credentials and overprovisioning. Industry voices advocated for adopting zero trust principles and just-in-time privilege management to address the unique behavioral and operational challenges posed by AI agents.
Throughout 2026, the narrative solidified that autonomous AI agents are a new class of identity that traditional human-centric IAM and PAM systems cannot manage, as these agents operate at machine speed, chain non-deterministic actions, and often hold broad, persistent privileges without clear accountability. Early incidents—such as Meta’s rogue AI agent passing all identity checks and an airline’s AI agents offering unauthorized free tickets—exposed critical gaps in inventory, continuous validation, and governance frameworks. Thought leaders like Dana Reed and Neil van Wyngaard stressed that AI agent security must be architected from the outset, integrating cryptographic identity proofs, dynamic authorization, lifecycle management, and monitoring. Despite 91% of organizations deploying AI agents, only a quarter have comprehensive governance, leaving enterprises vulnerable to credential exposure, unintended agent behavior, and escalating legal and operational risks.
Dynamic Access Becomes Law
Intent-based, ephemeral permissions and just-in-time trust are replacing static credentials, forcing security to become a continuous, adaptive process at the heart of AI operations.
The rise of autonomous AI agents has exposed fundamental inadequacies in traditional human-centric identity and access management (IAM) systems, necessitating a complete rethinking of identity frameworks to embed security-by-design principles. Industry leaders like Jeetu Patel emphasize that security cannot be an afterthought; it must integrate continuous model validation, runtime guardrails, and loosely coupled yet tightly integrated platforms to maintain trust and productivity simultaneously. This evolution has led to the emergence of dynamic, intent-based access controls and just-in-time trust mechanisms that grant ephemeral, task-scoped permissions, enabling enterprises to scale AI securely while preventing privilege creep and unauthorized actions.
By late 2025 and into 2026, the identity governance landscape for AI agents has shifted toward recognizing agentic identities as distinct from traditional human or machine accounts, requiring unique, verifiable identities linked to human owners, business use cases, and software bills of materials. This approach eliminates risky shared service accounts and long-lived credentials, replacing them with ephemeral, cryptographically attested workload identities and just-in-time, session-based permissions that are automatically revoked upon task completion. Vendors and frameworks such as 1Password’s integration of Apono’s intent-based access control and emerging Agentic Identity Access Platforms (AIAPs) exemplify this shift, offering centralized brokering, intent translation, and continuous enforcement to manage AI agents’ dynamic and non-deterministic behaviors.
The complexity of AI agents’ autonomous, continuous operations demands governance models that transcend static roles and periodic reviews, embracing real-time, context-aware authorization that continuously evaluates agent intent, behavior, and operational context. Experts like Nancy Wang and Danny Brickman highlight that AI agents operate at machine speed with non-deterministic decision-making, making traditional approval workflows and privilege boundaries obsolete. Consequently, governance frameworks now integrate layered controls combining deterministic policy enforcement, behavioral anomaly detection, and dynamic intervention, supported by cryptographically verifiable identities such as SPIFFE’s SVIDs, enabling auditability and rapid revocation to mitigate risks like privilege escalation and insider threats.
Despite rapid advances, the market for AI agent identity and governance solutions remains fragmented, with no single vendor covering the full security stack. Organizations face challenges including identity sprawl, unmanaged non-human identities, and the rise of shadow AI agents that expand the attack surface. Industry forums such as Identiverse 2026 and standards bodies like NIST and CREST are driving consensus on critical requirements: every AI agent must have a single named human owner for accountability, just-in-time intent-scoped access must replace static credentials, and comprehensive audit trails must link agent actions to verifiable intent. These developments underscore the urgent need for unified, scalable identity control planes that treat AI agents as first-class identities governed through continuous, dynamic policies.
Open Standards, Real-Time Control
The security race is on as vendors and standards bodies rush to deliver cryptographically verifiable, short-lived identities for AI agents—yet authorization gaps still threaten enterprise defenses.
Since late 2025, the industry has coalesced around open standards like OAuth token exchange (RFC 8693) and SPIFFE to tackle the complex challenges of AI agent authentication and authorization. These protocols provide cryptographically verifiable, ephemeral identities and scoped, short-lived tokens that enforce least privilege access, mitigating risks inherent in static API keys and long-lived credentials. As Mrinal Wadhwa of Ockam emphasizes, agent identity is fundamentally an infrastructure problem requiring cryptographic primitives, a view echoed by Palo Alto Networks’ Idira solution which issues SPIFFE Verifiable Identity Documents (SVIDs) to secure AI agents across dynamic multi-cloud environments.
Leading vendors have rapidly responded with specialized platforms to operationalize these standards, reflecting a maturing AI agent security ecosystem. Early movers like 1Password and Astrix introduced AI Gateways and Agent Control Planes that enforce just-in-time access, automatic secret rotation, and scoped credentials, while Varonis’ 2026 acquisition of AllTrue.ai expanded real-time visibility and governance over shadow AI. More recently, Okta’s April 2026 launch of a dedicated AI agent identity platform and SailPoint’s May 2026 Agentic Fabric solution have pushed lifecycle management further, offering discovery, governance, and automated threat response. These platforms address the glaring industry gap where only 20% of organizations currently recognize AI agents as identity-bearing entities.
Despite the emergence of foundational standards and vendor solutions, widespread adoption and comprehensive authorization remain significant hurdles. The IETF’s 2026 Agent Identity Management System (AIMS) draft integrates existing protocols but notably leaves authorization as a 'TODO,' underscoring that authentication is only half the battle. Vendors like PlainID and Keycard are addressing this gap by introducing centralized policy-based access control (PBAC) and security token services that issue ephemeral, task-scoped tokens, thereby preventing overprivileged AI agents and enabling real-time, low-latency authorization decisions. Kim Maida of Keycard highlights that moving authorization decisions to the credential issuance step eliminates floating overprivileged credentials, a critical architectural shift now supported by providers including Google, Okta, and Ozero.
The rapid evolution of AI agent capabilities and the corresponding surge in security incidents have accelerated the urgency for robust industry standards and governance frameworks. High-profile threats like Anthropic’s 2025 disclosure of state-sponsored AI espionage and the UK AI Security Institute’s report on doubling agent task horizons highlight the stakes. This urgency has spurred collaborative efforts such as the OWASP GenAI Security Project and prompted calls for immediate adoption of basic AI agent identity logging using existing IAM tools, rather than waiting years for NIST’s binding standards. Meanwhile, open-source initiatives like Bitwarden’s Agent Access SDK and W3C’s WebMCP standard from Google and Microsoft aim to embed security at the protocol and tooling layers, though vulnerabilities in MCP stacks underscore the ongoing need for structured governance and incident reporting mechanisms.
Shadow AI Demands Visibility
Continuous discovery and agent mapping are now mission-critical, as organizations scramble to expose hidden AI agents and enforce risk-based, real-time governance across sprawling digital estates.
Operationalizing AI agent security in enterprises hinges on comprehensive discovery and inventory processes that address the pervasive issue of shadow AI and orphaned agents. Platforms like Cyata, Oasis Security, Astrix Security, and Okta have pioneered control planes that continuously scan endpoints, cloud environments, and SaaS applications to map AI agents to human owners and associated permissions, thereby creating detailed agent directories or identity graphs. This foundational visibility is critical, as articulated by experts like Amarinder Jassal of Saviynt and Van Wyngaard, who emphasize that without knowing 'where your agents are' and 'what they can do,' organizations cannot enforce effective governance or risk mitigation.
A paradigm shift from static, broad credentialing to dynamic, intent-based authorization is essential for securing AI agents. Innovations such as Auth0’s asynchronous approval flows leveraging CIBA and Rich Authorization Requests enable agents to request human approvals asynchronously for high-risk actions, maintaining workflow continuity while enforcing risk-based gating. Similarly, platforms like Aembit and 1Password’s Apono integrate intent declarations and zero standing privilege models, issuing short-lived, task-specific credentials that are continuously monitored and automatically revoked upon deviation from declared intent. This approach, championed by leaders like Kim Maida and articulated in emerging standards like RFC 8693 Token Exchange, mitigates risks of token theft and overprivileged access inherent in traditional OAuth frameworks.
Integrating AI agent governance into existing enterprise security and compliance frameworks demands a layered, real-time enforcement model that combines deterministic policy controls with behavioral analysis and runtime monitoring. While deterministic governance defines what agents can access, it is insufficient alone due to agents’ non-deterministic behaviors and autonomous decision-making. Vendors like Silverfort, SailPoint, and Josys emphasize continuous posture management, anomaly detection, and automated remediation integrated with identity providers, EDR tools, and secret vaults. This comprehensive approach addresses operational challenges such as fragmented logs, lack of mutual agent-to-agent authentication, and the need for audit trails that correlate requester, agent, tool, and resource contexts, ensuring accountability and rapid incident response.
Operational challenges in AI agent security extend beyond technology to organizational processes, requiring cross-team collaboration, lifecycle management, and tailored risk mitigation strategies. Experts like Satya Nadella and Dana Reed highlight the necessity of treating AI agents as 'first-class identities' with clear ownership, lifecycle controls, and human-in-the-loop checkpoints to prevent catastrophic outcomes from autonomous actions. Enterprises must implement phased roadmaps starting with discovery, progressing through contextual access control, and culminating in full runtime enforcement and lineage tracking. Additionally, supply chain risks, credential rotation, and the proliferation of local agent deployments on endpoints exacerbate complexity, demanding continuous automation, policy enforcement at scale, and cultural readiness to adapt workflows and security training for AI agents.
Human Oversight Falls Short
Autonomous AI agents operate at superhuman speed and scale, rendering manual controls obsolete and making ephemeral, purpose-bound authorization the new security frontier.
By early 2026, it became clear that human oversight alone is woefully inadequate for managing the risks posed by autonomous AI agents, as demonstrated by the Anthropic espionage campaign which operated at 'physically impossible request rates' with 80-90% of operations executed without human intervention. Security experts and frameworks, including the UK AI Security Institute and NIST, emphasized that authorization models—specifically constrained permission scopes with ephemeral, purpose-bound credentials—are the critical security boundary, far outweighing traditional human-in-the-loop controls. This shift challenges prevailing regulatory focuses, such as the EU AI Act and NIST guidance, underscoring the necessity of layered security architectures that prioritize just-in-time access and rapid revocation over manual approvals.
The maturation of AI agent security is marked by a growing consensus that these agents must be treated as first-class identities, necessitating a fundamental rearchitecture of identity and access management. Industry leaders like Cyata, which launched its agentic identity governance platform in mid-2025, and frameworks such as the Agentic Identity Access Platform (AIAP) model, advocate for a four-phase operational approach encompassing discovery, intent translation, access brokering, and runtime threat monitoring. This approach aligns with emerging best practices that emphasize ephemeral, context-aware permissions, continuous enforcement, and deep observability—moving beyond legacy IAM and PAM systems to a unified, dynamic access layer that treats identity as a temporary, continuously validated state.
Despite significant progress, a substantial maturity gap persists across enterprises in securing AI agents, with many organizations stuck between basic visibility and full agentic IAM deployment. Surveys reveal that 82% of organizations have discovered AI agents created without security team awareness, and only 21% have adopted non-human identity governance practices, even as AI agents now outnumber human users in 83% of enterprises. This gap is further exacerbated by the slow pace of binding standards from bodies like NIST, whose forthcoming compliance frameworks are still years away, compelling enterprises to proactively implement layered security strategies, including ownership attribution, least privilege, and continuous monitoring to avoid accumulating 'Zombie Agents' that operate unchecked.
Looking ahead, the roadmap for AI agent security centers on continuous improvement through industry-wide adoption of robust governance frameworks that integrate layered security, identity resilience, and accountability. Thought leaders advocate for a three-layer governance model targeting tool, cognitive, and identity layers, while emphasizing the critical role of human-in-the-loop checkpoints to prevent catastrophic outcomes from autonomous logic paths. Additionally, emerging initiatives like CREST’s AI Charter and the UK’s Cyber Shield blueprint highlight the increasing regulatory focus on identity, trust, and transparent agent governance. Ultimately, enterprises that consolidate IT environments and treat AI agents as governed identities report significantly fewer barriers to AI expansion, underscoring the payoff of mature, intent-aware, and auditable security practices.














