AI agents reshape identity security

Associated Writers

Agentic AI Reshapes Identity Security Landscape

Agentic artificial intelligence is transforming the identity security landscape by introducing complexities in governing access. No longer limited to managing permissions for employees and traditional machine identities, AI agents are capable of operating on behalf of users, interfacing with applications, obtaining permissions, and executing tasks at unprecedented speeds. This evolution prompts a critical question: how can organizations accurately identify who or what is acting, and verify if the granted authority remains applicable?

Krista Case, principal analyst and practice lead for cyber resilience and security at theCUBE Research, stated that “agentic AI turns identity governance into an execution problem.” Organizations must understand not only the identity behind an action but also the authority it carries, what resources it can access, and whether that authority remains valid as tasks evolve. For this reason, she advises customers to assess identity platforms on their ability to maintain contextual awareness throughout an agent’s operational lifecycle.

This pivotal question will take center stage at SailPoint’s Navigate event, scheduled from October 5–8 in Austin, Texas. The event, under the theme “AI, secured,” will delve into how identity security is evolving in the context of AI agents amid an expanding array of both human and machine identities. SailPoint emphasizes that identity is becoming a crucial control point for enterprise security, with this year’s conference addressing the implications of incorporating agentic AI into identity governance.

During the event, theCUBE will provide exclusive interviews and insights as Case and co-host Rebecca Knight engage with industry leaders regarding topics such as adaptive identity, agent lifecycle governance, and the integration of human, machine, and AI agent identities in the broader enterprise security landscape.

AI Agents Create New Identity Governance Challenges

Historically, identity governance centered around people, defined roles, and predictable access patterns. The emergence of autonomous AI agents complicates this traditional framework since they are capable of executing tasks, interacting with diverse systems, and adapting their actions in real-time.

The magnitude of this complexity is underscored by recent research from SailPoint, which reveals that 97% of AI agents have access to sensitive data, yet only 21% of organizations express high confidence in their ability to effectively manage the associated security risks. Additionally, a proof of concept conducted by SailPoint at a Fortune 500 company uncovered over 10,000 previously unrecognized AI agents, highlighting significant visibility issues within the ecosystem. As Kerravala noted, “You can’t govern what you can’t see.”

Facing growing identity risks, SailPoint is taking steps beyond traditional periodic governance to establish a more immediate and dynamic security approach. Chandra Gnanasambandam, SailPoint’s chief technology officer, emphasized the need to transition from static compliance to a real-time, continuous security model aimed at discovering all identities and actively managing access lifecycle policies to preempt vulnerabilities before they are exploited.

Governance Models Must Evolve for AI Agent Management

Identifying AI agents is just the beginning; organizations must also ascertain ownership, requisite permissions, and the criteria for revoking access. The fluid nature of agent capabilities means they can amass privileges or interact with other agents, raising the stakes of insufficiently governed access controls.

According to Case, the significant organizational challenge lies in the speed at which agents can be created and deployed, often outpacing the ability of traditional access protocols to assign ownership and governance. To address this, companies require a robust operational model that aligns AI development with identity and security frameworks before AI agent populations expand to unmanageable levels.

The interplay between technology and organizational structure is critical, as identity systems can provide context that runtime security solutions typically lack. Although containment technologies can limit what an agent can access, they do not clarify the creator’s identity or accountability; hence, Kerravala states, “identity is the system of record everything else relies on.”

Expanding Identity Attack Surfaces and Security Control

SailPoint is positioning identity at the forefront of enterprise security as organizations integrate human, machine, and agent identities. The Navigate agenda reflects a broader industry trend toward centering identity governance within the security framework, particularly as the number of entities requiring access continues to grow.

The proliferation of AI agents represents a new dimension of identity attack surfaces, according to SailPoint. CEO Mark McClain articulated, “The emergence of AI agents creates a new class of non-human identities, each embodying a unique attack surface.” He affirmed that a secure foundation is crucial for AI to act as a genuine business accelerant, highlighting SailPoint’s collaboration with AWS to build a unified identity plane for enhanced visibility and control in an AI-driven environment.

However, organizations should exercise caution against claims that any single platform can serve as the definitive control plane for agentic AI. According to Case, effective governance must integrate identity management with runtime infrastructure, applications, data, and security telemetry to foster a successful operational architecture.

Addressing Complex Governance Issues for AI Agents

As enterprises grapple with the complexities of maintaining governance across diverse identity types, key questions arise. Organizations must determine how to efficiently discover and classify AI agents, link them to responsible human owners, and implement least-privilege access while ensuring that permissions are revoked once an agent’s task shifts.

Moreover, organizations face the challenge of developing a unified governance model without forcing disparate identity types, each with unique behaviors and risk profiles, into a singular operational framework. This distinction will be crucial as enterprises begin to experience autonomous systems at scale. The focus will shift from merely verifying log-ins to continuously assessing who or what possesses the authority to act.

Live Coverage of theCUBE Event

In-depth coverage of SailPoint’s Navigate event will be provided by theCUBE on October 6–7, featuring expert discussions that highlight developments pertinent to the evolving landscape of identity security. Exclusive content will also be made available on demand post-event.

Guest Insights on Governance Challenges

At the event, theCUBE will engage with executives and identity security leaders from prominent organizations, including SailPoint, Amazon, and HCLTech, to discuss governance strategies for AI agents and how enterprises can rethink access frameworks in light of increased autonomy in business operations.

Disclosure: theCUBE is a paid media partner for SailPoint’s Navigate event. Neither SailPoint, the event’s sponsor, nor other contributors have any editorial influence over the content produced by theCUBE or SiliconANGLE.

[gspeech type=full]

Share This Article
Leave a comment