Why AI Agents Are Challenging Identity Security

The wide adoption of AI agents is forcing organizations to rethink identity security as enterprises contend with an expanding population of non-human identities that increasingly outnumber employee accounts. While identity and access management programs have traditionally focused on managing people throughout their employment lifecycle, autonomous software identities are exposing governance gaps that many organizations are still struggling to address.

Unlike human users, machine identities, including AI agents, service accounts, workload identities, OAuth applications, and API credentials, are created to authenticate systems, automate processes, and enable communication between applications. As organizations embrace cloud computing, automation, and generative AI, these identities are being created at a pace that often exceeds traditional governance processes.

Human identities typically follow a predictable lifecycle. Employees are onboarded, assigned appropriate access, promoted or transferred to new roles, and eventually offboarded when they leave an organization. These lifecycle events form the foundation of identity governance, allowing security teams to periodically review permissions and revoke unnecessary access.

Machine identities operate differently. They may be generated automatically when new cloud workloads are deployed, inherit permissions from existing applications, communicate across multiple enterprise platforms, or exist only briefly before being replaced. Others remain active long after the application, automation workflow, or development project that created them has been retired. Without continuous oversight, organizations can lose visibility into who owns these identities, why they still exist, and what sensitive resources they are capable of accessing.

The scale of this challenge continues to grow. According to the Non-Human Identity Management Group, machine identities can outnumber human users by as much as 50 to one across many enterprise environments. While these identities are essential for modern business operations, security teams frequently struggle to maintain accurate inventories or establish clear ownership for every credential operating within their environments.

The security implications became evident during the UNC6395 campaign in 2025, when attackers reportedly obtained an OAuth token associated with Salesloft’s Drift chat integration and leveraged the trusted credential to move across Salesforce environments used by hundreds of organizations. Rather than exploiting a software vulnerability, the attackers abused an identity that had already been authorized within enterprise systems. Investigations found that the compromised access enabled attackers to obtain additional secrets, including AWS credentials and Snowflake tokens, demonstrating how a single trusted machine identity can provide a pathway to multiple connected environments.

AI agents are not creating an entirely new category of identity risk, but they are accelerating an existing challenge. Modern AI systems increasingly perform tasks autonomously, interact with multiple business applications, retrieve sensitive information, and execute workflows without continuous human involvement. As these agents operate across cloud services, they introduce additional trusted identities, inherit permissions from existing accounts, and expand the number of credentials that organizations must secure.

This rapid growth creates a governance challenge that extends beyond simple visibility. Security teams may know that identities exist, but effective identity security also requires understanding who owns each identity, what permissions it has been granted, what sensitive data it can reach, and when that identity should no longer exist. Without continuous lifecycle management, dormant or forgotten machine identities can quietly expand an organization’s attack surface.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article:

Why AI Agents Are Challenging Identity Security