Cyber SecurityAI & Technology

The AI Agent Security Problem Isn’t AI. It’s Identity

By Oded Hareven, CEO and Co-Founder of Akeyless

The AI industry has spent the past three years focused on capability.

How powerful are the models? How autonomous can agents become? How many workflows can organizations automate?

As AI agents move from pilots into production environments, a more practical question is emerging: how do organizations govern what AI agents actually do once they have been granted access? Recent research commissioned by Akeyless and conducted by MRA Research among 400 IT and security leaders globally suggests many organizations are struggling to answer that question.

Organizations estimate they spent more than $1 million on average over the past year responding to AI agent identity and security issues. At the same time, 67% suspect AI agents have already accessed data beyond their intended scope and 61% have revoked or rotated credentials due to suspected exposure. These findings point to a growing gap between AI adoption and AI governance. The problem is not that AI agents are inherently insecure, but rather that security teams are increasingly finding that existing identity controls are both inefficient and insufficient when it comes to governing autonomous systems.

For decades, enterprise identity systems were built around a relatively straightforward assumption: a user requests access, performs a task, and logs out. Access is granted at the beginning of a session and periodically reviewed over time.

AI agents do not operate that way. They can access multiple systems simultaneously, invoke tools dynamically, make decisions independently, and operate continuously across an environment. Yet many organizations still manage them using long-lived credentials, static permissions, and controls designed for people rather than autonomous software.

 The result is that organizations can verify an agent’s identity at the moment access is granted, but often lack runtime controls over what that agent actually does afterward.

An AI agent may be granted legitimate access to a system, but organizations often have limited control over how that access is used once the agent begins acting. As agents become more capable and more deeply embedded within enterprise workflows, the challenge is no longer simply preventing unauthorized access but governing authorized access at runtime.

That distinction matters because many of the risks emerging around AI agents occur after authentication and authorization has already taken place.

An agent may retrieve information it was not expected to access. It may interact with systems in ways developers did not anticipate. It may combine permissions across environments to produce outcomes that were never intended. Because it is operating with valid credentials, traditional security controls often struggle to distinguish expected behavior from problematic behavior.

This is why the AI agent security conversation increasingly comes back to identity.

Identity determines what an agent can access, what actions it can perform, and how quickly those permissions can be modified or revoked when something goes wrong.

The research reflects this. Fewer than half of organizations know where all the credentials used by their AI agents are stored. Half admit developers regularly bypass identity controls to keep systems running. More than four out of five say a single compromised credential could affect multiple major systems.

Addressing these challenges requires a shift in how organizations think about access. Instead of relying on long-lived credentials and standing privileges, enterprises need identity controls that operate in real time. Access should be dynamically granted, continuously evaluated, and limited to the specific task being performed. Organizations also need visibility into what AI agents are actually doing, not simply what they have been permitted to do.

Encouragingly, most organizations appear to recognize the challenge. Nearly three-quarters of respondents said AI adoption would move faster if security risks were better controlled, and 97% reported plans to strengthen AI agent security over the next year.

That should be a signal to the industry. Organizations are not struggling to see the value of AI agents. They are struggling to govern them.

The question is no longer whether AI agents can be trusted with access, but whether organizations have the controls needed to govern that access once it has been granted.

Author

Related Articles

Back to top button