AI Agents Force Enterprise Security Shift: Identity Management Becomes Critical Control Plane

6 Sources

Share

Enterprises face a new security challenge as autonomous AI agents multiply across their systems. With the average Fortune 500 company projected to run 150,000 AI agents by 2028, traditional security models built for predictable workflows are failing. Identity management has emerged as the only viable control plane for agentic AI.

News article

AI Agents Operate Through Improvisation, Not Prediction

AI agents function by reasoning probabilistically, choosing the next best action, observing results, and adapting in real-time

1

. This improvisation makes them powerful but unpredictable. Watch Claude work through a task and you'll see it spend four minutes trying to read a CSV that turned out to be a folder, then write a script to list its contents

1

. When paired with broad access, every wrong turn becomes a security risk. Traditional security models built around predictable workflows break down because you cannot secure a goal-driven system by profiling its past behavior.

The Scale of AI Agents Has Already Arrived

Palo Alto Networks reports the ratio of non-human identities to human identities stands at 109 to 1, including 79 AI agents

1

. Gartner projects the average Fortune 500 organization could be running more than 150,000 AI agents by 2028, compared with fewer than 15 only a year earlier

4

. Omdia research suggests 96% of organizations rely on governance models never designed for autonomous AI agents

4

. Anyone can spin up an agent in minutes, and most do so outside any security review.

Mastercard Rewrites Fraud Rules for Bot Buyers

Mastercard processes 175 billion transactions annually, scoring each in under 100 milliseconds for fraud likelihood

2

. Greg Ulrich, the company's chief AI and data officer, explained the fundamental shift: "We've built a bunch of risk rules over time that were intended to stop a bot from transacting. Now we need to enable the bot to transact, so that requires a change to our risk framework and our risk rules"

2

. Generative AI has enabled Mastercard to identify 300 to 400% more fraudulent transactions at high-risk bands

2

. About 40% of Mastercard's business now runs on services, with a third predicated on AI and growing faster than everything else

2

.

Identity Management Emerges as the Only Control Plane

Every action an AI agent takes runs through an identity—a service account, API key, OAuth grant, cloud role, or token

1

. Identity is the layer that spans every system an agent touches, making it the only place to enforce control consistently. Israeli cybersecurity startup Hush Security raised $30 million in Series A funding led by Battery Ventures and YL Ventures, with Akamai Technologies joining as a strategic investor

4

. CEO Micha Rave told VentureBeat: "Software now acts autonomously, on its own initiative, inside your most sensitive systems. AI agents need strict identity, not just API keys"

4

.

Traditional IAM Policies Fail for Autonomous Systems

Static IAM policies written for humans who log in during business hours and get reviewed once a quarter were never designed for agents that never sleep, don't use MFA, and are rarely retired

1

. The Cloud Security Alliance concluded that traditional identity and access management protocols designed for static applications and human users can't keep up

3

. Agent risk equals access multiplied by autonomy. Access sets the blast radius, while autonomy narrows the window for human intervention.

AI Agents Need First-Class Identities and Governance

Enterprise agents should have first-class identities like human colleagues, including unique identities, named owners, clearly defined purposes, and specific permissions

3

. Zendesk Chief Security Officer Vinay Patel emphasizes that agents should also have lifecycles akin to software, such as creation dates, review points, and expiry dates

3

. Without treating AI agents as users in their own right, companies risk accumulating abandoned agents, stored credentials, and data access paths whose original business purposes may have disappeared.

Verifiable Intent Solves the Context Problem

Mastercard built five layers to secure agentic commerce. Verifiable intent creates a tamper-proof cryptographic record of original instructions that travels with the transaction

2

. Ulrich explained: "If you've asked for Nike black Nikes in size 12, but you got them on a final sale and they're not returnable and that wasn't in your instruction, there's a way to look at that in an objective and clear way on the back end"

2

. Intent separates safe behavior from dangerous behavior, because an agent resolving a failed deployment and an agent exfiltrating data may perform nearly identical low-level actions

1

.

Zero Trust and Breach Containment Become Critical

Zscaler's 2026 threat report cited an 83% year-over-year rise in AI usage, creating a critical security gap between innovation and security

5

. CEO Jay Chaudhry explains that traditional network security treated data centers as castles with firewalls as moats, allowing lateral movement once inside

5

. This design enables malware exploitation and makes breach containment nearly impossible. Applying zero trust principles by treating agent compromise as credible, enforcing least privilege, isolating systems, and continuously verifying access can limit potential consequences

3

.

Audit Trails Must Preserve Both Human and Agent Identity

An audit trail should preserve both identities: the human who initiated or authorized the action and the agent that executed it

3

. For fully autonomous agents, logs tying them back to their owner, purpose, and approved policy remain critical. Companies need inventory and discovery across places where agents can be created or embedded, including SaaS platforms, internal automation tools, development environments, and third-party integrations

3

. Organizations must monitor not only which agents are deployed, but whether their permissions and behavior remain aligned with their original business purposes.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved