6 Sources
[1]
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
Watch an agent work through a task, and you'll see the future of enterprise security. Watch Claude work through a long task some time. It can spend 4 minutes trying to read a CSV that turned out to be a folder, give up, write a script to list its contents, and then get there. It works. Just never
[2]
Mastercard rewrites fraud rules for AI agents | VentureBeat
Every time a Mastercard gets tapped, the network has less than a tenth of a second to judge how likely the purchase is to be fraudulent. It made that call across 175 billion transactions last year. Now the buyer on the other side of that judgment is starting to change, and Greg Ulrich, the
[3]
Agentic security doesn't need a whole new definition - you just need to reframe what you already know
AI agents need their own identities, controls and accountability Though attack vectors and threat environments have changed since the advent of the internet, one thing has remained a constant - humans use software, and software has predefined parameters. That distinction is exactly why social
[4]
Hush Security says the AI security problem has shifted from protecting models to governing identities as autonomous agents spread
Less than a year after emerging from stealth to tackle non-human identity security, Israeli cybersecurity startup Hush Security believes the enterprise AI security conversation has fundamentally changed. The company, which earlier this week announced a $30 million Series A round led by returning
[5]
Zero trust and breach containment in an agentic world - Zscaler CEO Jay Chaudhry on the new stakes of threat defense
As AI security drama hijacks enterprise news cycles with unsettling regularity, I keep coming back to my conversation with Zscaler. Billed as an "AI security platform built on zero trust," Zscaler is the perfect foil for everything that is preoccupies me with AI security: * Will AI ultimately
[6]
NTT DATA AIVista and Snowflake: Identity alone won't secure enterprise AI agents
Presented by NTT DATA AIVista VentureBeat's June research found that 69% of enterprises are still running AI agents that share credentials, a practice associated with higher rates of security incidents and near-incidents. But at VB Transform 2026, Mukesh Karki, CTO of NTT DATA AIVista, and Mayank
Share
Copy Link
Enterprises face a new security challenge as autonomous AI agents multiply across their systems. With the average Fortune 500 company projected to run 150,000 AI agents by 2028, traditional security models built for predictable workflows are failing. Identity management has emerged as the only viable control plane for agentic AI.

AI agents function by reasoning probabilistically, choosing the next best action, observing results, and adapting in real-time
1
. This improvisation makes them powerful but unpredictable. Watch Claude work through a task and you'll see it spend four minutes trying to read a CSV that turned out to be a folder, then write a script to list its contents1
. When paired with broad access, every wrong turn becomes a security risk. Traditional security models built around predictable workflows break down because you cannot secure a goal-driven system by profiling its past behavior.Palo Alto Networks reports the ratio of non-human identities to human identities stands at 109 to 1, including 79 AI agents
1
. Gartner projects the average Fortune 500 organization could be running more than 150,000 AI agents by 2028, compared with fewer than 15 only a year earlier4
. Omdia research suggests 96% of organizations rely on governance models never designed for autonomous AI agents4
. Anyone can spin up an agent in minutes, and most do so outside any security review.Mastercard processes 175 billion transactions annually, scoring each in under 100 milliseconds for fraud likelihood
2
. Greg Ulrich, the company's chief AI and data officer, explained the fundamental shift: "We've built a bunch of risk rules over time that were intended to stop a bot from transacting. Now we need to enable the bot to transact, so that requires a change to our risk framework and our risk rules"2
. Generative AI has enabled Mastercard to identify 300 to 400% more fraudulent transactions at high-risk bands2
. About 40% of Mastercard's business now runs on services, with a third predicated on AI and growing faster than everything else2
.Every action an AI agent takes runs through an identity—a service account, API key, OAuth grant, cloud role, or token
1
. Identity is the layer that spans every system an agent touches, making it the only place to enforce control consistently. Israeli cybersecurity startup Hush Security raised $30 million in Series A funding led by Battery Ventures and YL Ventures, with Akamai Technologies joining as a strategic investor4
. CEO Micha Rave told VentureBeat: "Software now acts autonomously, on its own initiative, inside your most sensitive systems. AI agents need strict identity, not just API keys"4
.Static IAM policies written for humans who log in during business hours and get reviewed once a quarter were never designed for agents that never sleep, don't use MFA, and are rarely retired
1
. The Cloud Security Alliance concluded that traditional identity and access management protocols designed for static applications and human users can't keep up3
. Agent risk equals access multiplied by autonomy. Access sets the blast radius, while autonomy narrows the window for human intervention.Enterprise agents should have first-class identities like human colleagues, including unique identities, named owners, clearly defined purposes, and specific permissions
3
. Zendesk Chief Security Officer Vinay Patel emphasizes that agents should also have lifecycles akin to software, such as creation dates, review points, and expiry dates3
. Without treating AI agents as users in their own right, companies risk accumulating abandoned agents, stored credentials, and data access paths whose original business purposes may have disappeared.Related Stories
Mastercard built five layers to secure agentic commerce. Verifiable intent creates a tamper-proof cryptographic record of original instructions that travels with the transaction
2
. Ulrich explained: "If you've asked for Nike black Nikes in size 12, but you got them on a final sale and they're not returnable and that wasn't in your instruction, there's a way to look at that in an objective and clear way on the back end"2
. Intent separates safe behavior from dangerous behavior, because an agent resolving a failed deployment and an agent exfiltrating data may perform nearly identical low-level actions1
.Zscaler's 2026 threat report cited an 83% year-over-year rise in AI usage, creating a critical security gap between innovation and security
5
. CEO Jay Chaudhry explains that traditional network security treated data centers as castles with firewalls as moats, allowing lateral movement once inside5
. This design enables malware exploitation and makes breach containment nearly impossible. Applying zero trust principles by treating agent compromise as credible, enforcing least privilege, isolating systems, and continuously verifying access can limit potential consequences3
.An audit trail should preserve both identities: the human who initiated or authorized the action and the agent that executed it
3
. For fully autonomous agents, logs tying them back to their owner, purpose, and approved policy remain critical. Companies need inventory and discovery across places where agents can be created or embedded, including SaaS platforms, internal automation tools, development environments, and third-party integrations3
. Organizations must monitor not only which agents are deployed, but whether their permissions and behavior remain aligned with their original business purposes.Summarized by
Navi
[1]
[2]
[3]
[4]
15 Oct 2025•Technology

12 Feb 2026•Technology

02 May 2026•Technology

1
Science and Research

2
Policy and Regulation

3
Technology