AI & TechnologyAgentic

Your AI Agent Problem is an Identity Problem

By Craig Ramsay, senior field strategist, Omada

Enterprises are rapidly embracing AI agents, copilots, and autonomous workflows in pursuit of productivity and the competitive advantages these can bring. Business teams are increasingly deploying AI capabilities outside traditional governance processes, meaning there is no centralized authoritative source for AI agents. Innovation is being prioritized over governance and compliance — and in most organizations, that is a trade nobody consciously made. 

The problem is that most governance frameworks were designed for a fundamentally different technology era. Traditional controls assume human identities with predictable systems and stable permissions. Governance programs rely heavily on periodic reviews, manual approvals, and human oversight. 

Agentic AI introduces a new reality. AI systems can act independently, interact with other systems, and modify how they operate. Organizations are discovering that innovation is moving faster than governance can adapt. 

The challenge is no longer whether organizations will adopt AI agents but whether they can establish governance models capable of operating at the same speed, scale, and level of autonomy. 

Agentic AI breaks traditional governance assumptions 

The explosion of non-human identities (NHIs) is overwhelming legacy governance models. AI agents aren’t single entities like traditional NHIs such as service accounts or shared mailboxes. They are an identity graph, creating artifacts in your environments like service principals, app registrations, and more. A single agent deployment can produce all three, each a distinct governable object in its own right, and none of them likely to appear in a quarterly access review. Organizations now manage significantly more non-human identities than human users, with some estimates putting the ratio beyond 100:1. 

Scale is only part of the problem. AI agents operate continuously and often require real-time decision-making. Human approval processes cannot keep pace with this autonomous activity. 

Consequently, autonomy changes the risk equation. Traditional service accounts execute predefined tasks; AI agents can adapt, optimize, and interact with other agents in unexpected ways. Governance models built around predictability begin to break down. The result is a widening disconnect between how organizations govern technology and how AI actually behaves. 

You can’t govern what you can’t see 

Visibility has emerged as the foundational challenge. Most organizations can identify their workforce identities; far fewer can confidently identify every non-human identity operating within their environment. 

Adding to the lack of clarity, AI adoption is becoming increasingly decentralized. Agents are often created by developers and business teams rather than centralized IT groups. Many are deployed without standardized onboarding, ownership, or retirement processes. 

Even where agents are known, what they can actually reach is frequently invisible. An agent’s own entitlements rarely tell the full story, because much of its access is indirect: delegated permissions, the identity it acts on behalf of, and the artifacts created alongside it. Reviewed in isolation, an agent can look appropriately scoped against its stated intent, while its effective access extends well beyond what the reviewer sees. 

Organizations cannot enforce least privilege if they do not know what exists, while orphaned agents and ghost permissions continue to expand the attack surface. Accountability becomes difficult when autonomous actions cannot be traced to a responsible owner. 

Effective governance begins with discovery. Organizations must establish clear classifications for AI-related identities. Continuous inventory and compliance monitoring must replace periodic audits. 

The new attack surface created by autonomous systems 

AI agents dramatically increase the potential blast radius. Overprivileged agents create disproportionate risk compared to traditional user accounts. A single compromised credential can expose multiple systems and downstream resources. 

Agent-to-agent interactions introduce new trust challenges. Autonomous systems increasingly rely on delegated access and transitive trust. Attackers can exploit these relationships to move laterally through environments. 

The threat landscape is evolving beyond traditional identity security. Attackers are targeting orchestration layers, AI workflows, and machine identities. Security leaders must think beyond protecting models and focus on governing the systems surrounding them. Organizations are confronting a new reality: AI risk is an identity security problem. 

Governance that moves at machine speed 

Organizations cannot solve the problem by restricting AI adoption. Excessive controls risk slowing innovation and reducing competitiveness. Yet completely open adoption creates unacceptable security exposure. 

Governance must become continuous rather than periodic. Monitoring should focus on behavioral signals rather than static compliance checkpoints. Key indicators include ownership gaps, anomalous behavior, permission growth and intent drift. As an agent’s access quietly diverges from the job it was created to do, the risk it presents only grows. 

Accountability must remain non-negotiable. Every non-human identity should have a clearly defined human owner. Autonomous activity must remain transparent and auditable. 

That’s why identity must be the control plane for AI governance. Policies should be enforced dynamically and at runtime. Zero Trust principles must extend to autonomous systems. Governance controls must operate with the same speed and automation as the agents they oversee. 

Governance must evolve before the gap widens further 

Organizations that succeed will shift their focus from static compliance to continuous visibility, accountability, and adaptive control. The future of enterprise AI will not be determined solely by how quickly organizations deploy agents, but by how effectively they govern them. 

Three questions worth putting to your team this week: 

  • How many AI agents are running in your environment right now? Not “roughly” — a number you’d put in front of an auditor.
  • Can you name their business and technical owner? Two names, not a team, not a distribution list.
  • What is each agent’s intent, and does its access match that intent — including the access it holds indirectly?

If those questions are hard to answer, that gap is the problem. And if you can’t answer them for the agents running today, you are unlikely to be able to answer them for the one created tomorrow. This isn’t an AI problem; it’s an identity security problem that hasn’t been inventoried yet. 

Related Articles

Back to top button