AI agents are reshaping enterprise identity security, experts say
Security teams built for people are now being asked to govern software that acts like an employee
AI agents are quietly becoming some of the busiest accounts inside enterprise systems, logging in, configuring access and touching sensitive data without ever showing up on a human org chart.
Security teams built for people are now being asked to govern software that acts like an employee but doesn't behave like one.
Autonomous agents act as new forms of digital employees; this implies that companies should be aware of their existence, monitor them, and control them throughout their life cycle.
In conventional identity and access management, the identification and authentication process was static and occurred once per user request. However, agentic systems challenge this approach because now there are continuous requests from software performing actions for the human.
The shift runs both directions. Machine-native interfaces let agents help administer human users' access, troubleshoot problems and support security workflows directly.
That can cut costs and speed up operations, but only when strong guardrails are already in place; without them, efficiency gains turn into new blind spots.
Identity systems developed for humans cannot just be generalised to include machines as well. Agentic businesses require one identity system for human agents as well as machines in order to circumvent the problems posed by tool proliferation that results from using separate systems.
Each agent must have an identifiable human owner, policies, and auditability, as well as audit trails to ensure all actions taken by the agent can be traced back to their owner.
Agents need sufficient access for them to accomplish their tasks, but direct exposure of the agent to credentials or secret keys poses risks that offer no benefits. This problem is solved using just-in-time privileged access where access is brokered on an as-needed basis.
-
France to impose social media ban for under-15s after parliament's approval
-
Google developing 'Frozen v2' chip to hardcode Gemini architecture with 10x efficiency
-
Microsoft adopts AMD Helios: Can it challenge Nvidia?
-
Trump administration eyes ban on Chinese AI models, including Kimi K3: Report
-
Meta's Instagram faces Tennessee addiction trial: Check details here
-
'Don't buy the AI drama': Anthony Scaramucci dismisses mass layoff fears
-
China's Kimi K3 fixes 15 security bugs, challenging US AI guardrails: Report
-
Anthropic ends temporary Claude Fable 5 rollout, updates subscription access