Do you know who — and what — is on your network? If yes, do you know what “they” are actually doing?
In this case, the “what” and “they” mentioned could be an AI agent or two — or even hundreds.
Identity and access management (IAM) has been a core component of cybersecurity for decades, even as technology has changed. But one major new aspect of this challenge includes predictions that AI agents that will soon outnumber humans in certain areas.
THE AGENTIC IAM CHALLENGE
Diving deeper into this huge challenge, VentureBeat recently declared that “AI agents need more than access control — they need identity at runtime”:
“Enterprises are adding AI agents, applications, workloads, and machine identities far faster than they add employees. Many now plan for a non-human population several times larger than their human one, and identity architecture is what decides how far that growth goes.
“Every AI agent needs a verifiable identity, a credential it cannot leak, and a narrow set of permissions before it touches a production system, and the identity and access management (IAM) platforms most enterprises run today weren’t built to issue any of those things to software.
“What’s missing is an agentic equivalent to a human onboarding process, which is what gives an employer confidence in a new hire, says Matt Caulfield, VP of product, identity, at Cisco.
“’People build trust through a process,’ he says. ‘We know the same person, or the same company hired us, and that company ran a background check, ran an interview, verified our identity at onboarding. None of that exists for agents. We hire people over weeks or months. We hire agents in minutes.’”
GOVERNING AGENTIC IDENTITIES
According to an excellent article on siliconangle.com: “Discovering agents is only the first step. Enterprises also need to establish who owns them, what permissions they require and when those permissions should disappear. Agents can accumulate privileges, create or interact with other agents and use credentials across applications and infrastructure, increasing the potential impact of poorly governed access.
“That makes agent governance as much an operating model problem as a technology problem.
“’The hardest part of agent governance is organizational,’ Case said. ‘Agents can be created and deployed faster than traditional access processes can discover, assign ownership and govern them. Customers need an operating model that connects AI development, identity, security and the business before agent populations reach a scale where governance becomes a cleanup exercise.’”
So what steps are needed to holistically address this agentic AI identity issue?
CISO Series offers these “14 Tips for Human and AI Identity Management from Ping Identity.” Note there is a detailed description for each of these items at the link, so I urge you to visit the full article.
1. Healthy paranoia is the new best practice.
2. You can secure what you can identify. The opposite is also true.
3. Your next action is the new gate, then the next action, and …
4. Even a single session can spin out of control.
5. Think of every AI agent as a known adversary you hired on purpose.
6. Access the specific asset in the timeframe needed, and then you’re done.
7. Your agentic speed is not necessarily the same as your neighbor’s.
8. The FBI’s tips for spotting a deepfake were also seen by the attackers.
9. Humans should be re-verified as well.
10. Let “failure to verify” be a normal part of the process.
11. Don’t wait for a breach to start re-verifying your workforce.
12. Don’t let your help desk be your verification Achilles’ Heel.
13. Humans cannot monitor AI agents at machine speed.
14. Continuous authorization is a business lifestyle choice.
Conclusion: The goal isn’t to slow AI down. It’s to trust it at a speed you can manage.
I also like this article from theCUBE Research. Here’s an excerpt:
“AI is changing who, and what, interacts with enterprise applications. Websites, APIs, commerce platforms, and financial services environments continue to serve a mix of humans, traditional bots, AI assistants, autonomous agents, and automated workflows. That shift makes the traditional human-versus-bot model no longer sufficient in detecting and preventing fraud. Enterprises must now understand what type of automated actor is present, whether its claimed identity can be trusted, what level of access it should receive, and which policies should govern its behavior.
“Fingerprint has been building out its products around that problem, offering AI Assistant Detection, powered by its Automation Intelligence API, and AI Agent Detection. Taken together, the products point to a change in how enterprises will have to think about automated traffic. Knowing that a request came from a machine is only the starting point. Teams also have to determine whether they recognize and trust the system behind it, then decide what that system should be allowed to do.”
AGENTIC IDENTITY GUIDANCE
No doubt, some of you are looking for federal government and standards guidance from the National Institute of Standards and Technology (NIST). Earlier this year, this draft document was released for comment: Accelerating the Adoption of Software and AI Agent Identity and Authorization. The intention is to establish security frameworks for autonomous software and AI agents. Fully finalized federal standards are not expected until 2027 at the earliest. However, more details and notes are available here from NIST.
Hacker News offers this “IAM for AI agents: A Practical Enterprise Framework.” I encourage you to review the entire framework, but I want to highlight their good questions to consider in their “Decision criteria for AI-agent identity architectures”:
- “Ownership model: Can every agent identity be traced to a named human accountable for its purpose and expiration?
- Credential architecture: Does the pattern support federated workload identity and short-lived credentials, or does it depend on stored secrets?
- Delegated authorization: Is the agent’s own identity preserved separately from the user authority it exercises, with scoped and revocable delegation?
- Discovery coverage: Are agent identities discovered from applications and infrastructure, or only from what the IdP and IAM platform already know?
- Runtime telemetry: Does the architecture capture application-layer actions such as tool invocation, data access, and privilege use, not just authentication events?
- Enforcement reach: Can authority be constrained or revoked at the point of action, within the timeframe an autonomous task chain executes?
- Audit evidence: Does the system produce telemetry-backed proof of agent behavior, or attestations that a control was configured?”
RSA also offers their solution for regulated industries:
“RSA Agent ID Discover finds agents and MCP servers, known and unknown, sanctioned and shadow, across your identity, cloud, endpoint, and gateway sources, and registers each as a first-class identity with a named owner, risk tier, and lifecycle state, linked to the identity provider you already use.
“RSA Agent ID Secure enforces your policy on each call at an AI/MCP Gateway that runs either RSA-hosted or in your own environment, chosen per gateway. The solution provides approval with real assurance, demanding a named, authenticated operator approve high-risk actions out of band with a phishing-resistant credential. Access is revoked when an agent is decommissioned.
“RSA Agent ID Govern certifies and reviews agents the same way organizations govern people, with continuous certification, risk-based access reviews, and lifecycle automation for agents.”
FINAL THOUGHTS
I have written several blogs this year on related topics around identity and cybersecurity, but none focused on this AI identity governance issue. Here are a couple of those pieces:
Finally, I really like this related PwC report called 2027 Global Digital Trust Insights: C‑suite playbook and findings covering: Moving targets: Cybersecurity in a dynamic digital world.
I’ll close with one of their key takeaways: “The trust gap in autonomous agents: Organizations are eager to put AI agents to work for cyber defense, but far less willing to put them in charge. Only 22% would authorize fully autonomous AI actions, with reliability and maturity concerns being the biggest barriers.”
