Every AI agent you put into production is, in security terms, a new hire you never background-checked, handed a master key, and never assigned a manager. It works around the clock, at machine speed, with credentials you issued it — and in most organizations, no one can say how many there are or what they can reach.
An AI agent is not a chatbot answering questions. It is software that takes actions: it queries databases, calls APIs, writes to systems, triggers workflows, sometimes moves money. To do that it authenticates as a non-human identity — keys, tokens, and service credentials living inside your trust boundary. And here is the line I keep coming back to in The Defensible AI Program: nobody is the manager of an AI agent. The identity program you spent years building assumes there always is one.
Traditional identity management rests on five assumptions: every identity belongs to a person, access maps to a human job role, sessions start with a login and end with a logout, a manager reviews privilege periodically, and “normal” behavior is a human pattern. An autonomous agent violates all five — and each violation is a specific failure mode:
Machine identities now outnumber humans by more than 80 to 1 — and your IAM program was built to watch the other one.
That ratio comes from CyberArk’s 2025 research, and AI agents are accelerating it, because a single agent can spawn downstream identities to do its work.
Governance has to be proportionate, so the book sorts non-human identities into four classes. Class 1 is the static service account — lowest risk, where the gap is usually inventory rather than control. Class 2 is the automated pipeline identity. Class 3 is the AI model inference identity. Class 4 is the autonomous AI agent — the highest-risk class and the one your IAM program is least equipped for, because it takes actions, its access needs shift from one run to the next, and in multi-agent designs it can spawn sub-agents that are themselves identities needing credentials and oversight.
The fix is to extend your identity program to non-human actors, not replace it. For Class 4 agents, that means four capabilities:
The goal is never to slow AI adoption. It is to make sure the identities your AI runs on are governed as carefully as the people you hire — starting with the uncomfortable step most programs skip: running the inventory, so the agents stop being keys to the kingdom you can’t see.
A 30-minute conversation on where you are and what governing your AI actually takes.
Book a Consultation