Intragen News

AI agents are creating a new identity security challenge

Written by Intragen Newsroom | Sep 9, 2026, 2:13:56 PM

Samu Harrinvirta, Head of Sales Finland at Intragen, recently joined Jas Sagoo from Okta in a Tivi article discussing the identity and access risks created by AI agents.

AI agents are moving rapidly from experimentation into everyday business processes. As they gain access to more applications, systems and data, organisations need to think carefully about how that access is governed.

Intragen’s Samu Harrinvirta, Head of Client Engagement Nordics, recently discussed the issue with Jas Sagoo from Okta in an article published by Finnish technology publication Tivi.

The discussion explored why AI agents introduce a different kind of identity and access risk and why organisations need to make sure their security controls evolve alongside AI adoption.

AI agents can access more than organisations realise

Traditional employees usually access systems through interfaces designed for human users, with authentication and monitoring built around those interactions. AI agents can operate differently. They may interact directly with applications and data, use persistent credentials and work across multiple systems in order to complete a single task.

For example, an AI agent managing business travel could potentially need access to:

  • Travel and expense platforms
  • Payment systems
  • Employee calendars
  • Airline or booking systems
  • Internal employee information

That can make an agent highly effective, but it also increases the importance of controlling exactly what it is allowed to access. If permissions are too broad, an agent could potentially retrieve or expose information outside its intended scope.


One AI agent can create multiple identities

The growth of AI agents is also contributing to the wider rise in non-human and machine identities. A single agent may require different credentials or identities across several systems. As organisations scale their use of AI, this can quickly make the identity environment more complex.

Security teams therefore need visibility not only of which AI agents exist, but also:

  • which identities they use
  • which systems they can access
  • which permissions they hold
  • who is responsible for those identities
  • whether that access is still appropriate

Without that visibility, excessive access can become difficult to identify and manage.

AI agents can also become an attack surface

The risk is not limited to accidental behaviour. AI agents themselves can potentially be manipulated into performing actions that were never intended. That makes identity security particularly important. Organisations need to consider how an agent is authenticated, what permissions it receives and how its behaviour is governed throughout its lifecycle.

Principles such as least privilege, access governance and regular entitlement reviews remain just as important for AI agents as they are for human users.

AI adoption should not mean losing control

AI agents offer significant potential to automate work and improve productivity. The challenge is making sure organisations can adopt them without creating blind spots around identity and access. As AI becomes embedded into more business processes, identity teams will increasingly need to answer a simple question:

Do you know what your AI agents can access, and whether they should still have that access? Organisations that establish visibility and governance early will be better positioned to scale AI adoption safely.

Assess your readiness for AI agents

Intragen’s AI Readiness Assessment helps organisations understand how prepared their identity and access environment is for AI adoption, identifying potential gaps across visibility, access and governance.

Samu Harrinvirta and Jas Sagoo originally discussed these issues with Tivi.

Read the original Tivi article in Finnish here.