3 Sources
[1]
AI agents are part of your team now. Here's how to secure all of them.
A practical framework for securing every identity in the modern workforce, human or not. Your organization already has a rigorous process for governing human identities. New employees go through onboarding. They get a role, a set of entitlements, and a named manager accountable for their access. When they leave, their credentials are revoked and access is terminated. It's a well known IT process: every workforce identity that can access your systems needs to be known, scoped, and accountable from the moment they enter your world, to the moment they are off-boarded. AI agents are now operating inside those same systems. They access Salesforce, create tickets in Jira, provision infrastructure, process financial transactions, and communicate on behalf of your teams. In every meaningful sense they are members of your workforce, except that in most organizations they were never onboarded, have no named owner, and have no offboarding process when their purpose expires. JumpCloud's Q3 2026 research found that non-human identities now outnumber human users in 83% of organizations, and only 21% have implemented governance controls specifically for them. The framework below is designed to close that gap. Stage 1: Discover every agent operating in your environment Governance starts with an accurate inventory, and most organizations are working with an incomplete one. AI agents are being deployed by product teams, operations leaders, and individual contributors who have both the tools and the motivation to move fast. IT inherits the governance responsibility after the fact, often without knowing the full scope of what has been deployed. Shadow AI is the practical consequence: agents operating across production environments with no formal record, no defined owner, and no systematic way to stop them if something goes wrong. Discovering your agent population is an ongoing practice, not a one-time audit. Build an inventory across every environment where agents could be running: cloud platforms, managed devices, SaaS integrations, and on-premise systems. For each agent, document what it can access, what workflows it influences, and what triggers its actions. That inventory is the foundation everything else in this framework depends on. Stage 2: Register every agent as a formal identity with a named owner Every agent that operates in your environment should exist as a formal identity in your directory, with the same basic attributes you assign to any employee: a defined purpose, a scope of authorized action, and a named human owner who is accountable for its behavior. This is the architectural decision that separates organizations that can govern their agents from those that cannot. Agents registered as proper identities can be assigned entitlements, subjected to conditional access policies, and included in access reviews. Agents that exist only as service account workarounds or API keys in environment variables are ungovernable by any systematic means. Registration is also the mechanism for addressing Zombie Agents: agents that outlived their original purpose but kept running, kept accessing systems, and kept accumulating permissions. When every agent has a named owner responsible for its renewal, agents without active ownership naturally lose their access when that ownership lapses. The offboarding happens as a consequence of process rather than as a reactive cleanup after something breaks. Stage 3: Manage agent access with least privilege and zero standing credentials Registered agents need access to do their jobs. The governing principle for that access is least privilege: each agent should have entitlements scoped precisely to what its defined purpose requires, with access that is time-bounded wherever possible and revocable immediately if the agent's behavior changes. Standing credentials in environment variables are a persistent liability. Static API keys that never rotate are a persistent liability. In practice, managing agent access securely means issuing just-in-time credentials for privileged operations, building approval workflows that require human sign-off before agents reach sensitive systems, and maintaining emergency shutdown mechanisms that work at the speed the situation requires. For agents that need access to privileged web applications, SSH servers, or databases, credential shielding is an additional requirement: the agent should be able to complete its task without the underlying credentials ever being exposed to the model running it. Every privileged session should be recorded and available for audit. Stage 4: Govern agent behavior continuously, not just at deployment The first three stages establish the controls. Governance is what keeps them current. It is the ongoing practice of verifying that what agents are actually doing matches what they are authorized to do, and course-correcting when those diverge. Every agent action should be logged. Access reviews should happen on a regular cadence, evaluating whether each agent's entitlements remain appropriate for its current purpose. When an agent's behavior deviates from its defined scope, the anomaly should be detectable before it becomes an incident. When an agent's purpose ends, access revocation should be a procedural step, not a reactive measure triggered by something going wrong. Governance also means maintaining the audit trail needed to answer accountability questions: what did this agent access, what actions did it take, who authorized it, and what was the outcome? Organizations that cannot reconstruct that chain for any given agent are not governing their agents in any meaningful sense. They have deployed them and hoped for the best. The foundation underneath all four stages Each stage of this framework becomes significantly harder to execute when the underlying IT environment is fragmented. Identity, access, device management, and security controls spread across disconnected systems create the gaps where agent governance falls through, and organizations end up applying different policies in different places rather than consistent governance everywhere. JumpCloud's research found that organizations operating in fully unified IT environments are five times more likely to deploy agents in business-critical workflows than those running fragmented stacks. Whether the control layer is coherent enough to apply consistent policies across humans, devices, and agents simultaneously is what determines whether governance scales with AI adoption or lags behind it. This is the core premise of Agentic IAM: that governing humans, devices, and agents through a single coherent control layer is what makes the framework above executable at scale rather than aspirational. Securing every identity, human or not, is the operational foundation that makes AI safe to scale. Organizations that build it now will not just reduce risk. They will expand AI into more workflows, move faster, and do it with the confidence that comes from knowing every identity in their environment is known, governed, and accountable. JumpCloud's Q3 2026 IT Trends Research report (n=800 IT leaders, US + UK) is available here. The Agentic IAM lifecycle framework referenced in this article was developed by JumpCloud and is available here. Greg Keller is CTO and Co-founder at JumpCloud. Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they're always clearly marked. For more information, contact [email protected].
[2]
Autonomous actors need new AI agent governance
Agentic AI forces a reckoning on governance as autonomous actors enter production As AI agents move from experimental chatbots into production systems, enterprises must rethink agent governance as autonomous actors gain access to sensitive data, tools and business processes that traditional identity and security controls were never designed to handle. Enterprise cyber resilience company Rubrik Inc., which this week unveiled Rubrik Agent Identity to govern agent access one tool call at a time, argues that agents demand an entirely new control layer. Unlike a service account or a person, an agent pairs a non-deterministic model with federated identity -- and that combination breaks conventional assumptions about how software should be secured, according to Dev Rishi (pictured), general manager of AI at Rubrik. "If you or I were accessing Salesforce [or] accessing email, we have some judgment on how we would use that, that the models don't," Rishi said. "So I feel like you need a new class of guardrails that are a lot more intelligent and semantically aware to be able to actually secure and govern what agents are doing." Rishi spoke with theCUBE's Krista Case at Black Hat USA 2026, during an exclusive broadcast on theCUBE, SiliconANGLE Media's livestreaming studio. They discussed how enterprises can deploy autonomous actors with visibility, control and recovery. (* Disclosure below.) A new class of AI agent governance for autonomous actors Traditional identity stacks fall short because agents inherit legitimate permissions but lack the judgment to use them wisely, Rishi explained. An agent can pull data from Salesforce, then paste sensitive fields into an outbound email -- each action authorized, the combination toxic. To avoid flooding humans with endless approvals, Rubrik built SAGE, a small language model trained to act as a cybersecurity professional that vets actions at machine speed. "The entire [business] case on agents is that they're doing 10 times as much work as a human in the same amount of time," Rishi said. "If I'm sitting there and I'm hitting approve, approve, approve, we feel like it's more security theater than anything else." Observability is the foundation of AI agent governance, but it cuts both ways, Rishi noted. Rubrik's internal deployment emits trillions of tokens, so raw telemetry needs an intelligence layer to surface risk and runaway spend. In one case, the company found that a small fraction of activity drove a disproportionate share of cost. "One percent of sessions were driving 40% of the cost, and there was a lot more that we could drive once we had the observability in place," he said. Stay tuned for the complete video interview, part of SiliconANGLE's and theCUBE's coverage of Black Hat USA 2026. (* Disclosure: Rubrik sponsored this segment of theCUBE. Neither Rubrik nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
[3]
As A.I. Agents Gain Authority, Governance Becomes the Primary Constraint
Every enterprise wants to deploy A.I. agents. Far fewer have built the governance infrastructure required to let those agents operate safely across financial systems, customer data and mission-critical workflows. Every enterprise is running the same experiment right now: handing more decisions to A.I. agents and watching to see what breaks. Some are further along than others, but few are proactively asking the question that ultimately determines whether agentic A.I. can move beyond pilots: what happens when an autonomous system takes an action no one can fully explain? That question rarely surfaces during a product demo. It arrives later through finance after an unexpected bill, through security during an audit or in the boardroom once A.I. begins touching customer data, financial transactions or core business processes. As enterprises hand more authority over to software, governance is becoming the operating system of trust. Sign Up For Our Daily Newsletter Sign Up Thank you for signing up! By clicking submit, you agree to our <a href="http://observermedia.com/terms">terms of service</a> and acknowledge we may use your information to send you emails, product samples, and promotions on this website and other properties. You can opt out anytime. See all of our newsletters In traditional applications, governance has often been treated as the last mile of deployment. You built the app, signed off on the compliance checklist and then deployed the product. That sequencing made sense when software applications followed the same deterministic path every time. It falls apart if that is an agentic application -- a piece of code, interacting with a model, that is then interacting with one or more systems -- using probabilistic judgment to take actions. It may approve refunds, move money between accounts or initiate vendor contracts. Each decision introduces new uncertainty. An A.I. agent therefore, needs the same basic infrastructure as any new employee on day one: a verified identity, a clearly defined scope of authority and a record of every action it takes. Companies that build those controls into the foundation are scaling agents with confidence. Those that postpone governance until after deployment are discovering how difficult -- and expensive -- it is to bolt accountability onto systems already embedded across the business. One of the most common problems begins with access. A business unit launches an agent to resolve customer support tickets or reconcile invoices. The pilot succeeds, so the agent gains access to additional systems and takes on more responsibilities. Only later does someone ask what the agent can actually access, whether those permissions were ever narrowed after the pilot or who approved them in the first place. Retrofitting access controls onto a live agent that's already woven into a dozen enterprise systems is significantly harder than designing those controls from the outset. Enterprise security leaders increasingly describe excessive permissions and weak access governance as recurring findings in their A.I. audits. The same lack of visibility shows up in cost. Agentic systems that can't be observed at the task level often retry failed actions, call expensive models or tools unnecessarily or become trapped in inefficient execution loops. Finance teams frequently discover the problem only after A.I. spending has climbed well beyond expectations because they're looking at a single budget line instead of thousands of individual decisions that could have been measured, optimized and governed. The bigger issue, however, is trust. Many organizations have built technically capable agents only to discover that their own teams are reluctant to let those agents touch any consequential business processes. The hesitation usually comes down to a simple question nobody can answer with confidence: if this agent makes a mistake, how will anyone know what happened? Capability without accountability doesn't scale. It stays confined to pilots and innovation labs while critical business functions continue relying on manual processes. The organizations handling this well haven't necessarily moved more slowly. They've treated visibility, auditability and access control as part of the system they're building instead of a compliance exercise added after deployment. One large insurer, for example, adopted a simple rule: no agent enters production without a clearly defined scope of authority and an activity log that a business leader -- not only an engineer -- can understand. That single requirement changed how teams designed agents from the outset, and ultimately allowed the company to expand the use of A.I. across claims processing because governance questions had already been answered before launch. A regional bank arrived at a similar conclusion for a different reason. Regulators were always going to ask for an accounting of automated decisions, regardless of how those decisions were made. Rather than reconstruct and assemble events after the fact, the bank built the audit trail directly into the system. The result wasn't just smoother regulatory reviews. It also gave the organization's leaders a much clearer picture of what every agent was doing, making it easier to identify a misconfigured workflow before it turned into a customer or operational incident. In many ways, this mirrors a transformation taking place across the digital economy. As software begins acting independently on behalf of people and organizations, the scarce resource is trusted delegation. Enterprises need confidence that an agent can access only the systems it should, perform only the actions it's authorized to take and leave behind an auditable record of every decision. That combination of identity, permissions and accountability is becoming part of the trust infrastructure that underpins the emerging agent economy. None of this requires exotic technology. It requires treating A.I. agents the same way organizations would treat any other actor with access to critical systems: register their identity, define what they're allowed to do, record what they did and make those records understandable to the people responsible for the outcome. A small investment in an A.I. platform engineering to put these controls in place is what unlocks the agentic model at scale. So much attention has been given to what A.I. agents are capable of and the work they can take on, but the companies pulling ahead aren't distinguished solely by the sophistication of their models. They're distinguished by the confidence to put those models into production because they know exactly what their agents are doing, why they're doing it and how they'll respond when something goes wrong. Governance is no longer the paperwork that follows A.I. adoption. Increasingly, it's the prerequisite that makes large-scale agentic A.I. adoption possible at all.
Share
Copy Link
Non-human identities now outnumber human users in 83% of organizations, yet only 21% have implemented governance controls for AI agents. As autonomous actors access sensitive systems and make consequential decisions, enterprises face a critical gap between deployment speed and accountability infrastructure.
AI agents are now operating inside enterprise systems with the same access privileges as human employees, yet most organizations never formally onboarded them. These autonomous actors access Salesforce, create tickets in Jira, provision infrastructure, process financial transactions, and communicate on behalf of teams
1
. The scale of this shift is staggering: JumpCloud's Q3 2026 research found that non-human identities now outnumber human users in 83% of organizations, but only 21% have implemented governance controls specifically for them1
. Unlike human employees who go through rigorous onboarding processes with defined roles, entitlements, and named managers, AI agents typically have no named owner, no defined scope of authority, and no offboarding process when their purpose expires.Product teams, operations leaders, and individual contributors are deploying AI agents rapidly, leaving IT to inherit governance responsibility after the fact. This creates shadow AI: agents operating across production environments with no formal record, no defined owner, and no systematic way to stop them if something goes wrong
1
. The problem compounds when agents outlive their original purpose but keep running and accumulating permissions—what industry experts call "Zombie Agents." Retrofitting access controls onto live agents already woven into dozens of enterprise systems proves significantly harder than designing those controls from the outset3
. One large insurer addressed this by adopting a simple rule: no agent enters production without a clearly defined scope of authority and an activity log that business leaders can understand3
.At Black Hat USA 2026, Rubrik Inc. unveiled Rubrik Agent Identity to govern agent access, arguing that AI agents demand an entirely new control layer. Dev Rishi, general manager of AI at Rubrik, explained that unlike service accounts or human users, agents pair non-deterministic models with federated identity—a combination that breaks conventional security assumptions
2
. "If you or I were accessing Salesforce [or] accessing email, we have some judgment on how we would use that, that the models don't," Rishi said. "So I feel like you need a new class of guardrails that are a lot more intelligent and semantically aware to be able to actually secure and govern what agents are doing"2
. An agent can pull data from Salesforce, then paste sensitive fields into an outbound email—each action authorized individually, but the combination toxic. To address this without flooding humans with endless approvals, Rubrik built SAGE, a small language model trained to act as a cybersecurity professional that vets actions at machine speed2
.Securing AI agents requires treating them as formal workforce identities. The first stage involves discovering every agent operating in your environment through ongoing inventory across cloud platforms, managed devices, SaaS integrations, and on-premise systems
1
. Second, register every agent as a formal identity in your directory with the same basic attributes assigned to employees: a defined purpose, scope of authorized action, and a named human owner accountable for its behavior. This architectural decision separates organizations that can govern their agents from those that cannot1
. Third, manage agent access using least-privilege access principles with zero standing credentials. This means issuing just-in-time credentials for privileged operations, building approval workflows for sensitive systems, and maintaining emergency shutdown mechanisms1
. Finally, govern agent behavior continuously through logging every agent action and conducting regular access reviews to verify that what agents actually do matches what they're authorized to do.Related Stories
Observability forms the foundation of accountable AI operation, but raw telemetry needs an intelligence layer to surface risk and runaway spend. Rubrik's internal deployment emits trillions of tokens, and the company discovered that 1% of sessions were driving 40% of the cost
2
. Without observability at the task level, agentic systems often retry failed actions, call expensive models unnecessarily, or become trapped in inefficient execution loops. Finance teams frequently discover these problems only after AI spending climbs well beyond expectations because they're looking at a single budget line instead of thousands of individual decisions that could have been measured and optimized3
. A regional bank adopted governance controls proactively because regulators would inevitably ask for an accounting of automated decisions, regardless of how those decisions were made3
.Many organizations have built technically capable agents only to discover that their own teams are reluctant to let those agents touch consequential business processes involving mission-critical workflows, customer data, or financial systems. The hesitation comes down to a simple question: if this agent makes a mistake, how will anyone know what happened? Capability without accountability doesn't scale—it stays confined to pilots and innovation labs while critical business functions continue relying on manual processes
3
. Organizations handling this well have treated visibility, auditability, and access control as part of the system they're building instead of a compliance exercise added after deployment. As enterprises hand more authority to software, AI governance is becoming the operating system of trust, determining whether agentic AI can move beyond pilots into production systems that approve refunds, move money between accounts, or initiate vendor contracts3
.Summarized by
Navi
[2]
08 Jul 2026•Technology

10 Mar 2026•Policy and Regulation

16 Jun 2026•Technology

1
Technology

2
Technology

3
Science and Research
