Introduction to AI Agents as Identities
For years, security teams have built their programs around controlling identities to control risk. However, with the introduction of AI agents, this premise is breaking. AI agents have entered the enterprise quietly, summarizing meetings, drafting emails, and helping employees find information. But as they become more connected to critical business services, they are creating new security risks.
Most security teams didn't think hard about AI agents at first, viewing them as productivity tools. But now, they are retrieving information, triggering workflows, updating records, writing and deploying code, and taking actions across multiple systems. This makes AI agents more than just tools - they are identities that require security and governance models.
The Pattern of Uncontrolled AI Agents
The pattern is consistent across organizations. A new identity layer gets built on top of existing infrastructure with almost none of the controls that identity teams spent the last decade putting in place. An agent might be created by one team, used by another, connected to five different applications, and running on credentials that were provisioned for a completely different purpose.
The result is a sprawl of high-privilege, low-visibility actors that most security teams can't inventory, let alone govern. According to a 2026 CSA survey commissioned by Token Security, 82% of organizations discovered at least one AI agent created without the knowledge of security, IT, or governance teams in the past year, and 41% found this happening multiple times.
Security Risks Associated with AI Agents
The most important piece that security teams need to answer is what can the agent actually access? An agent that summarizes public documentation has limited blast radius. An agent connected to customer records, source code, financial systems, and admin-level cloud credentials is a different problem entirely. A bad prompt, a compromised session, a malicious plugin, or a misconfigured integration can turn an overprivileged agent into a path for data exfiltration, destructive action, or lateral movement through systems that were never meant to be connected.
This is no longer theoretical, with 65% of organizations experiencing a security incident involving an AI agent in the past year, and 61% reporting exposure or mishandling of sensitive data as a result.
Getting Control of AI Agents
Getting control starts with visibility. Security teams need AI agent discovery and inventory that extends beyond just names and platforms to answer questions that actually matter. Who owns this agent? Who can invoke it? What systems is it connected to? What credentials does it use? What can it read, write, delete, or execute in each target application?
The second piece is purpose. Security and governance can't be purely permission-based with AI agents. It has to account for the agent’s intent. A sales prep agent only needs read access to CRM records. It doesn't need to delete database tables. A finance workflow agent should only read invoices. It shouldn't be able to create new privileged users.
Continuous Governance of AI Agents
Once intent is understood, enforcement becomes possible. Permissions can be trimmed to match the agent’s actual purpose, overprivileged service accounts remediated, unused credentials rotated or removed, and risky connections caught before they turn into incidents. However, this is not a one-time exercise. Agents change, instructions update, user bases shift, and integrations expand. An agent that started as a narrow internal tool can quietly end up connected to systems it was never designed to touch, not because anyone made a bad decision, but because nobody was watching when the scope crept.
That's why governance needs to be continuous to catch agents that start accessing applications outside their normal pattern, use unexpected credentials, or take actions that don't fit their stated purpose. The enterprises that succeed with AI will not be the ones that block agents entirely. They will be the ones that make agents governable and promote secure AI innovation.
This means treating them as first-class identities with owners, access, behavior, risk, and lifecycle controls. AI agents are becoming privileged insiders. Security and identity programs must now catch up before those insiders become invisible attack paths.
Source: BleepingComputer