9 Sources
[1]
The Replicant in Your Directory: AI Agents and the Identity Security Gap
By Grady Summers, CEO, Netwrix Security was built for people. AI agents are exposing the gap. Forty-four years after Blade Runner imagined replicants walking among us, security teams are managing their own version of a non-human workforce. These replicants already have accounts, permissions, and
[2]
Why AI coding agents keep stalling before production and the governance controls that fix it
Across 100 engineering organizations, 61% already run AI agents. Yet almost none trust them enough to bring them into production. There are a few reasons for this. Firstly, agents are prone to making mistakes that humans know to avoid through experience. They move at a much faster pace, and by
[3]
69% of enterprises share AI agent credentials | VentureBeat
Share one API key across five AI agents, and a single compromised agent inherits the reach of all five. The attacker immediately benefits from the accumulated permissions of every workflow that the key touches. The forensic trail goes cold at the credential level because five agents on one account
[4]
The AI security paradox: Why are organizations trusting what they can't fully see?
Businesses are racing to adopt and operationalize AI, but many are deploying the technology faster than they can govern it. This gap is quietly becoming one of the biggest security risks facing enterprises today. AI agents are being embedded into everyday workflows as teams chase efficiency gains,
[5]
AI has collapsed the cyber response window -- resilience now starts before the attack
Enterprise cybersecurity is facing a fundamental speed problem. Frontier AI models are now enabling autonomous attacks that can move from initial access to full system breakout in as little as 27 seconds. That's faster than any human-operated security workflow can detect, escalate, and respond. As
[6]
Anthropic's Mythos leak hands enterprises a timely warning
What governance actually needs to look like to keep pace with AI Anthropic's Mythos Preview had barely been announced before it was compromised - accessed by a private Discord group on the day of its public release through a third party vendor environment. For a model distributed across 40
[7]
Understanding cyber resilience in the age of internal threats, AI, and emerging data loss risks
Human error, insider threats, and AI reshape cyber resilience External cyberattacks, especially ransomware, are now viewed as a matter of when, not if. It's no wonder they dominate cybersecurity discussions and make frequent headlines. IBM's 2025 Cost of a Data Breach report found that the
[8]
AI Agents in Enterprise IT Need Operational Guardrails, Not Just Policy Controls
The moment an AI agent can restart a service, change a configuration or trigger a workflow, it stops being software that assists and becomes something enterprises have spent a decade learning to govern: a privileged identity operating inside production. Most organisations have not made that mental
[9]
The Agent Is Inside the Perimeter: Why Indian Enterprises Can't Afford to Ignore AI Agent Governance
In April 2026, Vercel disclosed that a breach of its internal systems began with an AI tool that an employee had connected to their work account months earlier. The attacker simply rode the agent's existing access permissions into the enterprise. No sophisticated exploit and no insider threat. Just
Share
Copy Link
A new wave of research reveals that 69% of enterprises share credentials across AI agents, creating massive security vulnerabilities. Organizations deploying AI agents report a 43% breach rate compared to 11% among those without significant AI-driven identity expansion. Major security firms including Palo Alto Networks, CrowdStrike, and Cisco have invested over $22 billion in acquisitions to address this emerging threat as machine identities now outnumber humans by 50 to one in many environments.
AI agents are quietly reshaping enterprise security landscapes, and the numbers paint a troubling picture. According to VentureBeat research surveying 107 enterprises, 69% share credentials across their AI agent deployments
3
. When one API key powers five AI agents, a single compromised agent inherits the accumulated permissions of every workflow that key touches. The forensic trail disappears at the credential level because multiple agents operating on one account leave no record of which agent performed what action.
Source: VentureBeat
The scale of this AI security challenge extends far beyond shared credentials. Machine identities now outnumber human users by as much as 50 to one in many enterprise environments, according to the Non-Human Identity Management Group
1
. Some exist for minutes while others remain active years after the application that created them has been forgotten. Most organizations struggle to answer basic questions about who owns these identities, why they still exist, or what they can access.Organizations where AI significantly expanded identity counts reported a 43% breach rate over the previous year, compared with just 11% among organizations where AI hadn't significantly changed their identity footprint, according to Netwrix's 2026 Data and Identity Security Report
1
. The surprising element wasn't the breach rate itself but who got breached. Organizations experiencing rapid AI-driven identity expansion generally reported stronger governance practices than their peers, including monitoring shadow AI and maintaining continuous visibility into sensitive data. They invested in the security playbook but still suffered breaches.More than half of survey respondents, 54%, have already experienced an AI agent security incident or near-incident
3
. Eighteen percent confirmed an actual incident while 36% caught a near-miss before a breach occurred. Security teams are stopping most events at the last control point in the chain, but the data shows how thin that margin has become.An AI security paradox has emerged across enterprises. Research shows that 87% of organizations believe their identity management posture is prepared to support AI-driven automation, yet 46% simultaneously admit their identity governance falls short
4
. This contradiction sits at the core of current deployment challenges. Organizations grant AI agents increasing levels of access and autonomy before establishing clear methods to monitor or verify how these systems behave.
Source: TechRadar
Across 100 engineering organizations, 61% already run AI agents, yet almost none trust them enough to bring them into production
2
. AI agents are prone to making mistakes that humans know to avoid through experience. They move at a faster pace and operate autonomously by nature. When something goes wrong, there's often no audit trail or visibility into what they're doing across the organization.Only 32% of enterprises give every AI agent its own scoped, managed identity
3
. Nearly half, 48%, report that some agents have scoped identities while many still share AI agent credentials. Another 32% say agents mostly run on shared API keys or borrowed human and service accounts. The incident rate reaches 49% for companies with 101 to 1,000 employees but jumps to 63% for companies with more than 1,000 employees. Sandbox isolation moves in the opposite direction, falling from 35% to 20% at larger companies.Palo Alto Networks, CrowdStrike, and Cisco have collectively invested more than $22 billion targeting the identity security layer in the past year
3
. Palo Alto Networks completed its acquisition of CyberArk on February 11 for $21.1 billion in total consideration at close. CrowdStrike closed its $740 million acquisition of runtime authorization platform SGNL and by June 15 shipped Continuous Identity for AI Agents, a product that validates every agent action in real time. Cisco announced its intent to acquire non-human identity specialist Astrix Security on May 4 for a reported $400 million.The real problem isn't the AI agents themselves but the absence of governance controls around using them
2
. Three governance controls for AI agents can address deployment challenges: isolate, scope, and approve. Start with isolated, ephemeral workspaces where every task spins up from a clean template and gets erased when completed. All agents should have zero outbound access by default, with an explicit allowlist defining exactly which domains, methods, and paths an agent can touch.Forty-nine percent of enterprises enforce scoped permissions at runtime and 47% monitor and log agent activity
3
. Only 30% sandbox their highest-risk agents, the one control that limits blast radius when other measures fail. Isolation prevents a single compromised agent from becoming a deployment-wide event. Access controls should ensure agents never inherit a user's full credentials, with API keys carrying only permissions required for specific tasks.
Source: VentureBeat
Related Stories
Frontier AI models now enable autonomous cyberattacks that can move from initial access to full system breakout in as little as 27 seconds. That's faster than any human-operated security workflow can detect, escalate, and respond. Security operations can no longer assume there's time for humans to respond between breach and damage. Traditional detection and prevention built on rules-based logic, static access controls, and known signature detection was engineered for deterministic software. AI agents behave differently as non-deterministic systems capable of pursuing the same objective through many different paths.
In 2025, a threat actor tracked as UNC6395 obtained an OAuth token associated with Salesloft's Drift chat integration and used it to move through Salesforce environments across hundreds of organizations
1
. The token wasn't dangerous because it exploited a software vulnerability but because it was already trusted. From there, attackers reached AWS credentials, Snowflake tokens, and additional secrets stored where they shouldn't have been.Fifty-three percent of organizations regularly encounter unsanctioned AI tools or agents accessing company systems or data, but only 28% can detect shadow AI in real time
4
. Businesses are effectively allowing unknown contractors to roam freely through their systems with limited insight into where they're going, what they're doing, and what they have access to. Eighty percent of organizations said they cannot always determine why an AI agent took a privileged action, suggesting a fundamental accountability gap.AI agents should generate output but not decide what ships
2
. Human approval gates backed by existing role-based access controls create accountability. Every prompt, every tool call, every model interaction should be mapped to an authenticated identity and exportable to observability systems. Organizations need continuous answers to four questions: What identities exist? Who owns them? What can they access? When should they no longer exist? Without those answers, every new AI deployment quietly expands the number of trusted identities operating inside the environment.The shift toward cyber resilience frames recovery from a post-incident activity into a capability that is deliberately designed, tested, and continuously validated. Organizations that will gain the greatest advantage from AI will be those that bring identity security to the forefront of their governance strategies, improving visibility before adding more controls.
Summarized by
Navi
[1]
[2]
[3]
16 Jun 2026•Technology

02 May 2026•Technology

16 Jul 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
