Vulnerabilities

AI Agents Expose Identity Security Gaps

July 11, 2026 00:11 · 12 min read
AI Agents Expose Identity Security Gaps

Introduction to AI Agents and Identity Security

Security was built for people, but with the rise of AI agents, service accounts, OAuth applications, workload identities, and machine identities, the traditional approach to identity security is being exposed as inadequate. According to the Non-Human Identity Management Group, machine identities now outnumber human users by as much as 50 to 1 in many environments.

The Problem with Machine Identities

Machine identities rarely follow the same lifecycle as human identities. They can exist for minutes or remain active years after the application or automation that created them has been forgotten. Most organizations struggle to answer basic questions about who owns them, why they still exist, or what they can access.

In 2025, a threat actor tracked as UNC6395 obtained an OAuth token associated with Salesloft's Drift chat integration and used it to move through Salesforce environments across hundreds of organizations. The token wasn't dangerous because it exploited a software vulnerability, but because it was already trusted.

AI Agents Accelerate the Problem

AI agents don't create this problem, but they accelerate it. Organizations are deploying AI agents that create identities, inherit permissions, interact across systems, and expand the number of trusted credentials operating inside the environment. If security teams don't know those identities exist or don't understand what they can access, the attack surface grows quietly in the background.

Identity Programs Were Built for People

Identity programs were built around human behavior, assuming someone owns an account, reviews access periodically, and eventually removes it. AI agents don't naturally fit that lifecycle. They can be created automatically, inherit permissions from other identities, interact with systems at machine speed, and even create additional identities as they work.

The result is an identity population growing faster than most governance processes were designed to handle. The Netwrix AI Maturity Assessment benchmarks an organization's identity, data, and AI governance practices, identifies strengths and blind spots, and provides practical recommendations to help reduce AI-related risk.

Visibility Isn't Enough

Organizations where AI significantly expanded the number of identities in their environment reported a 43% breach rate over the previous year, compared with 11% among organizations where AI hadn't significantly changed their identity footprint. The surprising part wasn't the breach rate, but who got breached. Organizations where AI rapidly expanded identity counts generally reported stronger governance practices than their peers.

The Accountability Question

When an AI agent contributes to a security incident, who owns that identity? Who approved its permissions? Who reviews its access? Who decides when it should be retired? For a service account, there's usually a trail, but for an agent operating at machine speed, creating downstream identities, and interacting across systems, that line back to a person can disappear quickly.

Knowing where sensitive data lives is only half the equation. Knowing every identity that can reach that data, maintaining a current inventory, and ensuring each identity has a clear owner is the other half. The trusted identities that matter most aren't always the ones security teams are watching. Increasingly, they're the ones nobody remembers creating.

To learn how organizations are adapting identity security for AI, read the 2026 Data and Identity Security Report.

  1. Recommendations:
    1. Implement a robust identity governance program.
    2. Use AI maturity assessments to identify gaps.
    3. Maintain continuous visibility into sensitive data and identities.
Security teams need continuous answers to four questions: What identities exist? Who owns them? What can they access? When should they no longer exist?

By addressing these questions and adapting identity security for AI, organizations can reduce the risk of breaches and ensure the trust and integrity of their systems.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free