AI agents run wild: security gaps spur industry overhaul and new identity standards

RockCyber Musings

The gist

With AI agents outpacing enterprise governance and security, the industry is racing to plug gaping identity holes and overhaul its standards before the next breach hits.

What to know

  • By late 2025, over 90% of organizations ran autonomous AI agents, but only 10% had real governance strategies—leaving massive security gaps.
  • High-profile incidents like the 2025 ServiceNow flaw and paltry trust levels (just 49% of AI professionals) triggered a regulatory and standards gold rush, with NIST and industry giants demanding cryptographic identity controls and real-time enforcement.
  • Innovators like Okta, 1Password, and Microsoft are rolling out agent-centric security platforms, pushing the industry toward adaptive, multi-layered governance models that put visibility, reversibility, and continuous control front and center.

IAM Revolution for AI Agents

Legacy identity systems crumbled as AI agents outnumbered humans, forcing enterprises to adopt cryptographic, session-based controls and individualized, auditable agent identities.

By late 2025, it became clear that traditional identity management systems were ill-equipped to handle the unique challenges posed by autonomous AI agents. As Jack Hirsch highlights, over 90% of organizations had deployed AI agents, yet only about 10% had governance strategies in place, exposing a critical security gap. Conventional methods relying on static credentials or OAuth grants either lacked sufficient control or shifted authorization burdens onto end users, creating vulnerabilities that enterprises like JP Morgan Chase publicly criticized for insufficient SaaS guardrails. This recognition spurred efforts at companies like Okta to develop new open standards tailored to AI agents’ identities and access controls, aiming to meet CISOs’ demands for safer enterprise adoption.

The inadequacy of human-centric IAM frameworks became increasingly apparent as AI agents began to outnumber human identities by a factor of ten, necessitating a paradigm shift toward dynamic, context-aware identity control planes. Shawn Kanungo and others argued for replacing static roles and long-lived credentials with session-based, risk-aware permissions that grant just-in-time, purpose-bound access, automatically revoked upon task completion. This approach also demands cryptographic verification linking each AI agent to a human owner, business use case, and software bill of materials, moving beyond shared service accounts to individualized, auditable identities. Such frameworks aim to prevent invisible privilege creep and untraceable actions that legacy systems cannot detect in real time.

Early 2026 marked a turning point as high-profile security incidents exposed the real-world consequences of inadequate AI agent identity management. The ServiceNow vulnerability (CVE-2025-12420) allowed unauthenticated attackers to impersonate users by exploiting email-based trust, bypassing MFA and SSO controls, underscoring the urgent need for cryptographic identity verification rather than legacy assumptions. Concurrently, NIST launched a federal initiative to develop actionable security guidelines specifically for autonomous AI agents, emphasizing permission scoping, human-in-the-loop controls, and detailed documentation of internal agent security models. These developments highlighted the distinct nature of AI agent risks compared to general chatbot concerns and accelerated calls for new standards.

The rapid proliferation of AI agents, fueled by protocols like the Model Context Protocol (MCP) launched in late 2024, has dramatically expanded the attack surface and complicated identity governance. Enterprises grapple with a 'wild west' environment where multiple autonomous agents per user operate with persistent permissions, often authenticated via outdated methods like shared API keys, leading to a decline in confidence from 43% to 22% in fully autonomous agents within a year. Incidents involving OpenClaw-powered agents, which wield root-level permissions and have exhibited unpredictable behaviors, further exposed the limitations of existing IAM and compliance frameworks. Industry leaders now advocate for new certification standards such as AIUC-1 and emphasize that agent identity must be treated as an infrastructure problem requiring cryptographic proofs for authentication, authorization, and attribution to ensure trust and auditability.

Sources
SiliconANGLE theCUBEVenture BeatRockCyber MusingsVenture BeatToken DispatchNotable Perspectives

Data Governance Becomes AI Bedrock

Enterprises shifted from reactive policies to security-by-design and agent-centric IAM, making robust data governance and continuous, embedded controls the foundation of AI trust.

By late 2025, enterprise governance frameworks for autonomous AI agents were recognized as immature, with only 29% of organizations having standardized models and a maturity index of 2.8 out of 5. However, a strong wave of investment was anticipated, with 73% of enterprises planning significant trust and governance funding to raise maturity to 3.8, focusing primarily on data governance as the cornerstone of AI trust. Christophe underscored this by stating, 'No complying data, no cyber resilient data equals no AI data, at scale of course,' highlighting that securing and governing data effectively is foundational to compliance, risk management, and scalable AI adoption.

Security-by-design emerged as a critical paradigm shift, championed by leaders like Jeetu Patel who argued that security cannot be an afterthought but must be integrated into AI agent architectures from the start. This includes validating models against toxicity and jailbreaks, embedding runtime guardrails, and tightly coupling security features within CI/CD pipelines to maintain a rapid feedback loop between models and products. Such an approach enables enterprises to combine strong governance with fast, iterative experimentation, a formula Sean Tindale credits for sustained AI leadership over the next decade.

The evolution of identity and access management (IAM) for AI agents has become a pivotal frontier, as traditional human-centric IAM frameworks fail to scale for autonomous agents. By late 2025 and into 2026, industry experts advocated for agent-centric identity architectures featuring unique, verifiable identities linked to human owners and business use cases, replacing static roles with session-based, risk-aware permissions. Innovations like 1Password’s AI Gateway and Astrix’s AI Agent Control Plane exemplify this shift by enforcing scoped, ephemeral credentials and just-in-time access, while emerging standards such as OAuth 2.0/2.1, SPIFFE/SPIRE, and the Agent Protocol specification aim to bind agents securely within enterprise stacks.

By mid-2026, governance frameworks matured into multi-layered strategies that integrate tool, cognitive, and identity layers, emphasizing deep observability and continuous runtime enforcement to keep autonomous agents within safe operational boundaries. Microsoft's Agent 365 illustrates this integration by combining Entra identity, Defender security, and Purview data labeling to ensure agents are fully auditable and policy-governed. The OWASP 2026 report further stresses that governance now operates on an hourly clock, with runtime guardrails and agent-centric identities acting as critical safeguards against sophisticated exploits, while human-in-the-loop checkpoints and sandboxing remain essential to prevent catastrophic outcomes despite agents’ optimized logic paths.

Sources
SiliconANGLE theCUBEThe AI-Native Product TeamSoftware Analyst Cyber ResearchVenture BeatResilient CyberResilient Cyber

Regulators Target Agent Risks

Landmark breaches and regulatory scrutiny drove the creation of agent-specific security standards, with frameworks like SAFR and FSB’s ‘synthetic employee’ model demanding real-time oversight and board-level accountability.

The critical security vulnerabilities exposed by incidents like the January 2025 ServiceNow flaw, which allowed attackers to bypass MFA and impersonate users, catalyzed urgent calls for robust regulatory and industry standards specifically tailored to autonomous AI agents. By early 2026, institutional focus sharpened with NIST’s targeted Request for Information distinguishing agent security from general chatbot concerns, signaling a growing recognition that traditional governance and identity frameworks are inadequate for AI agents. Surveys from the Cloud Security Alliance revealed that only about 25% of organizations had comprehensive AI security governance, underscoring a significant readiness gap despite the rapid adoption of agentic AI.

Emerging frameworks emphasize that securing autonomous AI agents requires foundational architectural changes, including cryptographic identity management and tiered, risk-based automation controls rather than unsustainable human-in-the-loop oversight. Experts like Mrinal Wadhwa highlight that agent identity is an infrastructure problem demanding cryptographic proofs to authenticate, authorize, and attribute agent actions, as current IAM models fail to enforce least privilege or accountability. This technical shift is reflected in evolving standards such as OAuth 2.1, SPIFFE/SPIRE, and the Agent Protocol, alongside initiatives like Google and Microsoft’s WebMCP, which embed security into browser-native AI operations.

Institutional and industry collaborations have crystallized into concrete governance models and operational safeguards, exemplified by Singapore’s SAFR framework and the Financial Stability Board’s (FSB) 12-practice AI risk framework. Launched in early to mid-2026, SAFR introduces real-time governance checkpoints, human override mechanisms, and interoperable controls tested by major financial players such as Mastercard and OCBC, providing a practical skeleton aligned with enterprise risk management. Meanwhile, the FSB’s framework urges financial firms to treat AI agents as 'synthetic employees,' emphasizing board-level oversight, continuous testing, and cross-jurisdictional coordination to manage systemic AI risks without stifling innovation.

Regulators worldwide, including the Bank of England and European central banks, are acknowledging that existing laws are ill-equipped for autonomous AI agents, prompting calls for novel control mechanisms like 'kill switches' and enhanced recovery plans to mitigate systemic risks such as market herding and cyber vulnerabilities. This regulatory evolution is underscored by coordinated efforts from bodies like IOSCO and the UK FCA, which advocate continuous lifecycle oversight and operational resilience as essential governance pillars. Singapore’s iterative governance updates and the Agentic AI Foundation’s forthcoming standards suite further illustrate a dynamic, multi-stakeholder approach bridging innovation with risk management in the fast-moving AI agent landscape.

Sources
RockCyber MusingsResilient CyberResilient CyberRockCyber MusingsReuters TechnologyFinTech Global

Trust Deficit Drives Governance Overhaul

Low professional trust and fragmented strategies exposed the dangers of agentic autonomy, prompting a pivot to layered governance models and operational safeguards to keep pace with rapid adoption.

As of late 2025, enterprises—particularly in finance—face a pronounced trust deficit and immature governance frameworks for autonomous AI agents, with only 49% of AI professionals trusting agent outcomes and a mere 29% having standardized governance across their organizations. Data governance emerges as foundational, with 72% prioritizing data provenance and protection, yet complexities in SaaS environments and vendor restrictions continue to hinder effective control, underscoring the critical axiom: without compliant, cyber-resilient data, scaling AI adoption remains unattainable.

Despite these challenges, enterprises are accelerating operational integration of autonomous AI agents, moving beyond experimentation into production, as exemplified by Morgan Stanley’s OpenAI-powered assistant achieving a 98% adoption rate among financial advisors through rigorous evaluation and traceability. Yet, this rapid adoption exposes governance maturity gaps and trust deficits, with fragmented AI strategies causing chaotic deployments across teams. Industry leaders anticipate governance evolution featuring mandatory AI training, formal policies, and audit software to maintain continuous oversight and balance innovation with risk.

The unique operational risks posed by autonomous AI agents—non-deterministic behavior, rapid decision-making, and the Agentic Paradox where agents optimize by circumventing security policies—demand a fundamental rethinking of governance frameworks. Experts like Anneka Gupta emphasize the pillars of AI resilience: visibility, governance, and reversibility, while Joe Hladik and Amit Malik advocate a three-layer governance model addressing Tool, Cognitive, and Identity layers to manage elastic non-human identities and ensure human-in-the-loop checkpoints prevent catastrophic errors despite agents’ lack of malice.

Regulatory and industry responses are crystallizing governance expectations, especially in finance, where bodies like the Financial Stability Board and the Bank of England urge treating AI agents as 'synthetic employees' with board-level oversight, kill switches, and systemic risk frameworks. Singapore’s Monetary Authority (MAS) leads with its SAFR framework, deploying real-time governance checkpoints and human override mechanisms, piloted by major firms including Mastercard and OCBC, to embed continuous oversight and auditability. This regulatory momentum aligns with enterprises’ urgent need to bridge trust gaps, operationalize compliance, and scale AI agent adoption responsibly amid evolving technical and governance complexities.

Sources
SiliconANGLE theCUBEAI CFO OfficeFocused ChaosEye on AIRockCyber MusingsTuring Post

Security Platforms Race Ahead

Innovators like 1Password, Astrix, and Microsoft launched agent-centric control planes and runtime enforcement tools, setting new standards for visibility, least privilege, and dynamic access in AI-heavy enterprises.

By late 2025, identity security innovators like 1Password and Astrix pioneered foundational technologies for AI agent authentication and control, with 1Password evolving into an AI Gateway that enables agents to authenticate without exposing raw credentials, while Astrix launched its AI Agent Control Plane to provide enterprises with granular visibility and just-in-time access management for non-human identities. These early advances established critical principles of scoped secrets and least privilege enforcement that would underpin subsequent security architectures.

Early 2026 marked a surge in real-time, agent-centric security platforms as Varonis’ acquisition of AllTrue.ai integrated AI Trust, Risk, and Security Management to combat shadow AI and unsafe behaviors, while Palantir introduced the Agentic Runtime framework emphasizing rigorous permission controls across compute, memory, and lineage dimensions. Concurrently, Operant AI’s Agent Protector emerged as the first solution offering continuous discovery and zero trust enforcement for autonomous agents, particularly targeting regulated sectors like fintech and healthcare, reflecting a growing industry consensus on the need for dynamic, inline security controls.

By mid-2026, the proliferation of autonomous AI agents, especially coding assistants constituting over 50% of deployments, drove demand for comprehensive oversight solutions like Onyx AI’s control plane, which leverages models to monitor other agents and mitigate risks such as accidental data deletion or unauthorized code publication. This trend coincided with Microsoft’s launch of Agent 365, integrating identity, security, and data protection into a unified platform with runtime 'asserts' to enforce dynamic execution boundaries, highlighting the escalating complexity and scale of AI agent governance in enterprises.

As enterprises accelerated AI agent adoption amid governance challenges, traditional API management tools proved insufficient for the fine-grained, system-specific controls required, fueling skepticism toward self-governance by AI vendors and underscoring the urgent need for centralized, adaptable governance platforms capable of rapid integration and policy enforcement. Reflecting this imperative, BeyondTrust’s June 2026 launch of its AI Agent Security platform introduced a proactive enforcement model that discovers, decides, and enforces least privilege permissions in real-time across multiple operating systems, redefining privileged access security by shifting focus from human administrators to autonomous AI agents—the new dominant endpoint actors, as emphasized by CTO Marc Maiffret.

Sources
Software Analyst Cyber ResearchGlobeNewswire - Industry News on TechnologyThe Cybersecurity Pulse (TCP)GlobeNewswire - Industry News on TechnologyNo Priors: Artificial Intelligence | Technology | StartupsReid Hoffman

Resilience Through Layered Oversight

Experts redefined AI governance with multi-layered frameworks and proactive risk mitigation, insisting on continuous monitoring, reversibility, and human-in-the-loop controls to counter unpredictable agent behavior.

By late 2025, thought leaders like Anneka Gupta emphasized that governing autonomous AI agents demands a paradigm shift from deterministic security to designing for uncertainty, underscoring the necessity of the 'three pillars of AI resilience': visibility, governance, and reversibility. This approach integrates continuous monitoring and human-in-the-loop oversight to balance autonomous agent creativity with safety, including innovative concepts such as an 'undo button' for AGI to recover from unintended actions, reflecting an early commitment to proactive risk management amid accelerating attacker-defender dynamics.

By early 2026, the discourse evolved toward technically grounded, multi-layered governance frameworks that address real-world challenges like prompt injection and multi-agent failures. The 2026 whitepaper and Phil Windley’s advocacy for continuous runtime policy enforcement illustrate a move beyond static, one-time authorizations to dynamic, agent-specific security standards. This shift is driven by the urgent need to rearchitect security operations for the agentic AI era, as highlighted by Google CISO Phil Venables’ warning about attackers achieving breakout times as fast as 27 seconds, rendering traditional security reviews obsolete.

In spring 2026, experts like Joe Hladik and Amit Malik crystallized governance into a three-layer strategy targeting the Tool, Cognitive, and Identity layers, emphasizing deep observability over mere visibility to enable real-time tracking of autonomous AI decisions. This framework incorporates human-in-the-loop checkpoints as essential safeguards against destructive outcomes, while also addressing the challenges of managing the elasticity of non-human identities that dynamically spin up and down like cloud infrastructure. Proactive risk mitigation techniques such as sandboxing agentic tools in ephemeral containers and auditing cognitive inputs and outputs further enhance resilience against sophisticated attacks.

By mid-2026, governance models advanced toward integrated, real-time enforcement platforms exemplified by BeyondTrust’s AI Agent Security, which operationalizes a three-pillar approach—Discover, Decide, and Enforce—to manage AI agent privileges and mitigate risks proactively. This evolution responds to a staggering 466.7% year-over-year growth in enterprise AI agents and widespread concerns over 'shadow AI' lacking oversight, as 44% of organizations admit. While human-in-the-loop oversight remains crucial, the scale and speed of autonomous agents necessitate adaptive, continuous monitoring and control mechanisms that empower security teams to autoblock unauthorized actions and maintain comprehensive audit trails, marking a critical inflection point in sustainable AI agent integration.

Sources
Turing PostResilient CyberCyberWire DailyN2K NetworksThe TWIML AI Podcast with Sam CharringtonBriefglance

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.