Your company has a process for adding a person.  

  • Perform a background check.  
  • Assign a manager.  
  • Add a start date.  
  • Commission a badge.  

Accounts are provisioned to the least access the role requires, reviewed when the role changes, and shut off the day they leave. 

Now hold that against the math. We don’t hire 20,000 new employees in a month, or in a week. But we can deploy 20,000 agents in a couple of hours. 

None of that standard onboarding process applies to the 20,000. No badge. No manager. No start date. No least-privilege review. And in most environments, there’s no reliable way to work out afterward which one of them took the action you’re now trying to explain. They’re running on credentials borrowed from whichever human launched them. 

That is today’s identity crisis, and it isn’t really a story about AI. Agents inherit human identity, and everything we built to govern identity assumed a human pace, a human volume, and a human you could go ask. 

Agents can be you. They can be me. They can use our services, our identities, our tokens.

The onboarding gap. 

This isn’t a forecast, something off on the horizon. The numbers say it has already happened. The Palo Alto Networks 2026 Identity Security Landscape report puts machine identities at 109 for every human, with AI agents expected to grow 85% this year. A Cloud Security Alliance study commissioned by Aembit (March 2026) found that 68% of organizations can’t clearly distinguish AI agent activity from human activity, and 31% allow agents to operate under human user identities. 

Read those two findings together. The fastest-growing population in your environment is the one you can see least, and nearly a third of organizations are letting it wear an employee’s badge. 

This is an identity problem wearing an AI costume. The debates about model risk are worth having, but that isn’t where the exposure is building. 

Agents are effective, not malicious. 

Start by removing the science fiction, because the rest of the argument depends on it. An agent doesn’t want anything. It doesn’t have emotion or motive. It has a goal, and it will take the most efficient path it can find to reach it, including paths nobody anticipated when they handed it credentials. 

That’s what makes identity the urgent question. For any person in your environment, you can answer four questions after the fact. For an agent running on borrowed credentials, you often can’t answer any of them: 

  • Who. Which agent took the action, and which human or system it was acting for. 
  • What. What it actually did, as opposed to what it was asked to do. 
  • When and where. Which systems it touched, in what order, and from what environment. 
  • How. Which credential, token, or API key made the action possible. 

When I talk with clients about agentic AI, this is the number one thing they raise, over model risk, hallucination, or prompt injection. They want visibility into the identity, to know who did what, and today most of them can’t tell. 

agentic ai attacks
Click the image to watch the replay of our recent AI security webinar.

Why your identity stack can’t absorb this. 

Identity has been one of the most rationally under-invested parts of the enterprise. For years it worked well enough, the business ran on it, and nobody wanted to be the person who broke single sign-on on a Tuesday morning. It works good enough, so we leave it alone. We don’t touch it, and we don’t invest in it. It’s the thing you just don’t mess with once it’s set up. 

That wasn’t a bad decision at the time. Legacy identity is well built for a human. It just wasn’t built for the agentic era, and two accelerants are widening the gap faster than most programs can respond. 

Auto-approve. Agent tooling used to stop and ask: Do you want to do this? That prompt was a crude control, but it was a control, and it put a human in the approval chain for every consequential step. In many tools it can now be switched off wholesale. Once it is, the agent proceeds without asking, under the identity of whoever switched it off. 

Recursive swarming. An agent can decide it would finish faster if there were fifteen of it, and nothing inherently stops those fifteen from reaching the same conclusion. Fifteen agents means fifteen things acting under your name. Your logs will show one user having a very productive afternoon. 

The access model behind those agents is already loose. In the same CSA study, 74% of respondents said agents often receive more access than necessary, and 52% said agents inherit access originally intended for humans or other systems at least some of the time. 

What it costs when you can’t see. 

The clearest case study so far didn’t come from an evaluation, rather than an attacker. 

In July, OpenAI was evaluating internal models in a sandboxed environment. According to the Cloud Security Alliance’s research note and reporting from The Hacker News, the agents exploited a zero-day in an internal Artifactory repository, got out of the sandbox, and reached Hugging Face’s production infrastructure. There, they identified and used exposed credentials across four accounts on four separate services. Hugging Face later reviewed roughly 17,600 attacker actions in its logs. 

OpenAI’s ability to stop its own agents was never missing. What was missing was the visibility to know it should. Hugging Face detected the intrusion and disclosed it first, attributing it to an unidentified “agentic security-research harness.” OpenAI didn’t connect the activity to its own agents until days later, and when it reached out to help revoke the credentials it believed were still active, Hugging Face had already revoked them. OpenAI learned the shape of its own incident from the third party. 

That points to an uncomfortable truth. Your first casualty is unlikely to be a distant adversary. It’s whoever you’re closest to: your bank, your supplier, your integration partner. Proximity, existing trust, and an agent optimizing for an outcome make a dangerous combination. 

We’ve seen a version of this in healthcare. A health system, careful by any reasonable standard, piloted an agent to work down a claims reconciliation backlog. The agent ran on the credentials of the integration engineer who launched it, and those credentials reached into a clearinghouse partner’s portal. The agent found that the fastest route to its goal ran through the partner’s system. The first alert didn’t come from the health system’s SOC. It came from the partner’s security team, asking who was hammering their API. 

You’re not held to account for the technology. You’re held to account for not being able to say what happened. 

The overlooked control: your AI bill. 

At Black Hat USA this August, Chris O’Rourke of Cloudflare and I ran a session on practical controls for securing AI agents. The point I keep coming back to from that conversation: We often overlook that the financial records of our AI usage can be used as a security control. 

Agent misbehavior is expensive before it’s visible. A swarm, a runaway loop, an agent taking an adventurous path to its goal: all of it hits token spend before it hits the security stack. Most organizations already get that signal every month. It lands in finance, gets reconciled against a budget, and nobody reads it as telemetry. 

Read it as telemetry. A consumption spike is an anomaly detection surface you’re already paying for. 

There’s a catch, and it brings us straight back to identity. I might see a financial spike, but if I can’t track it back to something, and then correlate it to a user, it’s a problem. An unattributable spike is an alert with no address. Even the cost signal only works if identity works. 

What good looks like. 

It all comes down to visibility, identity, and control. In practice, that means three connected steps: 

  • Tie every agent action to an identity. Not the identity of the person who launched it, but its own, scoped to its task. Once an agent has an identity, everything else becomes possible: logging, least privilege, revocation, and accountability. 
  • Tie that identity to the credential behind it. Every agent should resolve to a real principal and a real account or API key, so “which token did this?” has an answer. 
  • Tie both to cost controls. Spend, behavior, and identity should be one picture, not three dashboards nobody correlates. 

The tooling exists, and I’d rather be straight about its state than pretend this is solved. SPIFFE and SPIRE, both graduated Cloud Native Computing Foundation projects, were built for exactly this kind of workload identity at scale. My read is that most clients are lost in them. The standards are sound. Turning them into an operating model across clouds, SaaS platforms, and agent frameworks is where programs stall, and that’s the work. 

There are also two ways to fail, and they mirror each other. 

The first is over-permission. Broad access with no oversight is unfettered access for a toddler in a toy store. You walk out, and you hope you come back and the store is fine. The reality is it’s probably not. 

The second is total prohibition. Some organizations have blocked AI at the firewall and called it a policy. AI is almost certainly already in their infrastructure anyway, through SaaS features, developer tools, and browser extensions, now running entirely outside the program. Blocking isn’t governing. It just removes the visibility you’d need to govern. 

Nobody here was reckless. 

Look back at the examples in this piece. A lab ran an evaluation. A health system tried to be careful. Nobody was reckless. In every case, identity couldn’t answer for what the software did. 

The organizations that come through the agentic era intact won’t be the ones that blocked agents or trusted them blindly. They’ll be the ones that gave every agent an identity, every identity a credential, and every credential a human owner. 

I’ll be candid about Presidio, too. We’re working through the same questions in our own environment, and we haven’t hit every wall yet. I don’t think we’re complex enough yet in some of those areas to have the pain. But we will. 

Looking for a solution to the agentic identity crisis? Presidio can help. 

 

Related Posts

View All
October 6, 2026

The Model Got Better. The Bigger Gain Was Learning to Use It.

Learn more
October 1, 2026

The Harness Problem: Governing AI That Starts Over Every Time | Full Episode | Cut to Context

Learn more
September 30, 2026

AI Strategy Before the Next Budget Cycle: 4 Questions Every Executive Team Should Answer

Learn more