AI agents outnumber humans, exposing identity governance crisis

Venture Beat

The gist

Autonomous AI agents now outnumber humans inside enterprises, exposing identity chaos, rampant shadow AI, and a skyrocketing risk of insider threats that legacy security just can’t handle.

What to know

  • By mid-2026, AI agents surpass human users in the enterprise, but only 26% of firms have mature governance to control them.
  • Credential sharing and static API keys run rampant—69% of companies allow it, correlating with a 63.5% rate of security incidents.
  • Despite 82% of organizations deploying AI agents, 70% face shadow AI and 54% have reported AI-linked security events, fueling urgent calls for zero standing privileges and real-time oversight.

AI Agents Fuel Identity Chaos

Legacy access controls are crumbling as autonomous AI agents demand dynamic, identity-first governance to prevent catastrophic insider threats and supply chain exploits.

By mid-2026, enterprises are grappling with an unprecedented surge of autonomous AI agents that now outnumber human users, creating a sprawling and complex identity landscape that traditional privileged access management (PAM) systems struggle to contain. As Eric Kong emphasizes, organizations must extend the same rigorous identity-first governance frameworks applied to human privileged users to these AI agents, whose broad and persistent access demands dynamic security measures such as zero standing privileges and continuous behavioral monitoring, as highlighted by CrowdStrike's Mitesh Shah. This rapid proliferation has ignited what industry experts term the '2026 identity arms race,' underscoring the urgent need for adaptive, identity-centric controls to prevent catastrophic insider threats and security meltdowns amid escalating global AI regulatory and cybersecurity crises.

Current enterprise practices reveal a troubling reliance on legacy authorization methods—such as shared human logins, static API keys, and traditional service accounts—to authenticate AI agents, which severely undermines auditability and inflates security risks. Fei Liu from Help Net Security warns that this approach blurs the identity fabric, making it difficult to track agent actions and exposing organizations to shadow AI usage where unsanctioned tools accessed via personal accounts evade IT oversight. Okta and OWASP advocate for treating AI agents as managed non-human identities with dedicated lifecycle management, scoped credentials, and integrated governance controls, ensuring every agent’s access is explicitly tied to authenticated identities and subject to continuous review.

The expanding privileges granted to AI agents—often through broad API keys, environment file access, and extensive use of external plugins—transform privileged access management into a complex supply chain security challenge. Kim Maida highlights the risks of over-privileged agents inadvertently causing significant damage, while token exchange protocols like RFC 8693 offer promising solutions for issuing ephemeral, task-specific tokens that enforce least-privilege access. This identity-first governance approach, combined with robust agent guardrails and continuous logging of every authorization and access attempt, is essential to detect and mitigate sophisticated attacks such as living-off-the-land exploits and social engineering manipulations that exploit AI agents’ unpredictable behaviors.

Research from VentureBeat reveals that 69% of companies allow AI agents to share credentials, correlating with a 63.5% rate of security incidents or near-misses, compared to 40.9% where agents have scoped identities. This stark contrast underscores the critical importance of assigning each AI agent a unique, scoped identity, especially those interacting with production systems, to reduce risk exposure. Despite knowing these governance gaps, many enterprises rushed AI deployments ahead of adequate identity controls, highlighting a systemic challenge that can only be addressed through centralized identity layers integrated with single sign-on and comprehensive governance frameworks that provide visibility, control, and revocation capabilities.

Sources

Human Oversight: The Last Line

Continuous human-in-the-loop monitoring and adversarial testing are now essential to curb AI agent hallucinations and operational sprawl before they trigger security failures.

As autonomous AI agents proliferate rapidly within enterprises, experts emphasize that human-in-the-loop oversight is indispensable to prevent these agents from operating unchecked and escalating vulnerabilities. Industry leaders like Tanvi Mittal highlight the critical need for continuous adversarial testing and measurable governance to bridge AI trust gaps, ensuring that evolving threats and hallucinations are detected and mitigated before causing harm. This approach counters the uncontrollable sprawl of autonomous AI identities by embedding human judgment directly into the operational loop.

The National Institute of Standards and Technology (NIST) advocates a dynamic, continuous red teaming model that integrates adversarial discovery, ongoing hardening of defenses, and operational resilience to maintain AI security in a fast-changing threat landscape. This continuous loop requires human oversight to identify novel attack vectors—such as language obfuscation and multi-turn escalation—that static guardrails cannot anticipate, underscoring that AI security is never a finished product but an evolving process demanding real-time vigilance.

Real-time monitoring combined with actionable human intervention mechanisms—such as kill switches, audit logs, and anomaly detection—forms the backbone of effective governance for autonomous AI agents. Companies like NCS have operationalized this by deploying technologies like Sunshine.guardian, a flight simulator for AI agents that stress-tests chatbots through thousands of synthetic conversations before live deployment, ensuring that unusual or unsafe behavior can be swiftly escalated and contained within strict accountability frameworks.

Embedding governance controls directly into AI system architectures enables bottom-up enforcement of policies, restricting autonomous agents to operate strictly within defined permissions and boundaries. This architectural visibility translates into operational control, allowing organizations to maintain trust and safety in AI-driven workflows by ensuring every action is traceable back to human accountability, thereby closing critical gaps in AI governance amid the accelerating AI arms race.

Sources

Global AI Arms Race Escalates

Geopolitical tensions and weaponized AI are exposing critical supply chain vulnerabilities, forcing enterprises to overhaul operational controls and embrace adaptive governance.

By 2026, the global AI arms race has transformed operational controls into a critical frontline defense amid escalating cybersecurity risks and geopolitical tensions. China's pioneering AI agent regulations expose glaring security flaws in autonomous tools, underscoring a widening governance and trust crisis as enterprises scramble for accountability. Meanwhile, non-state actors like Boko Haram weaponize AI, complicating the geopolitical landscape and amplifying the urgency for adaptive, identity-first governance frameworks supported by trusted vendor partnerships that can navigate complex regulatory environments and supply chain vulnerabilities.

The rapid proliferation of autonomous AI agents has shattered traditional security paradigms, with CrowdStrike's Bagley warning of a significant loss in risk visibility and Accenture's Satterwhite framing the situation as a cyber arms race demanding rapid defense deployment. AI-powered attack automation has surged, exposing critical vulnerabilities in coding agents and accelerating ransomware assaults, which forces enterprises into urgent global cyber defense overhauls. This dynamic environment requires operational controls that go beyond static measures, incorporating continuous lifecycle management and strategic regulation to keep pace with evolving threats.

The shift from human to semi-autonomous AI coding agents in software supply chains introduces unprecedented security challenges, as nearly half of imported dependencies harbor known vulnerabilities and a third are hallucinated package names, creating fertile ground for supply chain attacks like slopsquatting. With malicious open-source packages rising 75% year-over-year, traditional human-driven security controls falter, necessitating novel operational safeguards such as lockfile pinning, package firewalls, sandboxed execution, and least-privilege identity scopes. Platforms like Cosmos and tools like Auggie CLI exemplify how integrating semantic dependency analysis and human-in-the-loop approval gates can restore control and mitigate risks in agent workflows.

The complex interplay of export-control laws and divergent regulatory frameworks, as seen in Anthropic's global shutdown of Claude Mythos 5 due to U.S. Commerce Department restrictions, highlights new operational risks tied to geopolitical factors and vendor reachability. This regulatory patchwork complicates AI service continuity and underscores the necessity for robust contingency planning and compliance agility. Moreover, the dynamic nature of AI agent trustworthiness—requiring continuous, adaptive operational testing across purpose, persona, and policy dimensions—demands that enterprises evolve beyond static benchmarks to behavioral credit rating-like governance models that ensure reliability, security, and safety in real-world deployments amid the intensifying AI arms race.

Sources

Governance Gaps Invite Risk

Widespread shadow AI, lagging compliance frameworks, and underfunded governance leave organizations blind to escalating security incidents and regulatory exposure.

By mid-2026, enterprises are grappling with a stark disconnect between the rapid deployment of autonomous AI agents and the maturity of governance frameworks needed to manage them. While 82% of firms have integrated AI agents (Eric Kong, SailPoint), only 26% have governance structures that keep pace with adoption (Smarsh and FTI), and 87% lack visibility into AI compliance activities (Drata). This governance lag is compounded by widespread shadow AI usage, with 70% of companies harboring unsanctioned AI tools that evade IT oversight, creating significant compliance blind spots and security vulnerabilities (Vanta).

Security incidents linked to AI agents have surged, with 54% of enterprises reporting such events, often exacerbated by risky practices like credential sharing and insufficient investment in AI security relative to risk exposure. Despite dominant control frameworks from OpenAI, Google, and Microsoft, spending on AI governance lags behind the escalating threat landscape, leaving organizations vulnerable to data leaks and compliance failures (Unknown sources). This gap is particularly acute in sectors like banking, where legacy system complexity and opaque asset relationships hinder accurate risk assessment, prompting calls for graph-based risk models to better map exposure (Paul Forte, Jupiter One).

Organizations are responding by evolving governance strategies that balance innovation with risk management, emphasizing human-in-the-loop oversight and iterative change management. Leaders like CISO Matt Hillary advocate shifting toward agentic AI frameworks that enable accountable governance, risk, and compliance outcomes, while audit professionals stress maintaining human skepticism to avoid overreliance on AI outputs (Matt Hillary; Effective Change Management). Additionally, embedding AI-driven security testing into DevSecOps pipelines with human oversight is emerging as a best practice to bridge the gap between rapid AI adoption and governance maturity (NowSecure).

The pervasive shadow AI phenomenon and lack of centralized oversight have prompted organizations to shift from outright blocking AI tools toward accelerating risk review processes through empowered governance bodies and continuous monitoring. Firms are establishing chief AI officers or cross-functional AI risk committees with authority to dynamically manage AI model lifecycles, supported by centralized inventories and automated controls to detect model drift and evolving compliance challenges. As Miriam Vogel of EqualAI warns, operationalizing AI principles into practice, fostering AI literacy, and building feedback loops are critical to closing governance gaps and mitigating liability, especially as courts increasingly hold deployers accountable for AI-related harms.

Sources

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.