Agentic Identity

AI identity risk, in plain English

Most vendors are selling AI agents as a terrifying new species. The calmer truth: an AI agent is just software with a login, doing things through the same connections your other apps use. You already know how to secure most of that. There's one part that's genuinely new.

 

Here's the honest bit most of the market won't say: no single product secures all of it, not even the best identity platform. We're the people who'll show you exactly which pieces your existing stack already covers, get those working, and map out the rest without the fear-selling.

What's actually changed

An agent is code with credentials calling APIs, the same shape as software any good engineer writes. Most of securing it is familiar work: who is it, what's it allowed to do, can you see what it did.

A few things are different and worth your attention:

It decides for itself what to do next. You can't list every action in advance.

It can be tricked by the content it reads. A poisoned document or email can redirect it, a bit like a brilliant new hire who'll follow any note handed to them, even from a stranger.

Its permissions can be widened without a code review, so scope creeps quietly.

You can't "sign off" its behaviour the way you can a fixed piece of software.

Because of this, two things that used to be optional are now essential: checking what an agent is allowed to do at the moment it acts, not just when it was set up, and being able to prove which piece of software is really calling, not just that it's holding a valid password.

The two lanes

Every AI agent falls into one of two groups, depending on whose authority it acts under. Telling them apart in your actual estate is the skill that matters.

Agents acting for a person

A copilot reading your email, an assistant booking your meetings, an agent answering a customer using that customer's account.

The question here is whether it's actually acting for the person it claims, and only within what that person is allowed to do.

Well-established ground · largely available today

Agents acting on their own

A background automation, a data pipeline, a coding agent inside a build system. There's no human login to lean on here.

The question is harder: can you prove which piece of software this actually is? This needs a different kind of technology, deliberately handed off by the identity platforms, not because the product is weak, but because it's a genuinely different problem.

Where our advisory work sits

Most confusion in this space comes from trying to solve the second problem with tools built for the first. Sorting out which of your agents are which is where a real conversation starts.

Why this matters now

Numbers worth knowing

91%

of organisations run AI agents - only 10% have a well-developed strategy to manage them.

Okta, AI Agents at Work 2026
82%

discovered at least one AI agent or workflow in the past year that IT and security didn't know about.

Cloud Security Alliance, 2026
65%

reported an AI agent security incident in the past year, most commonly data exposure.

Cloud Security Alliance, 2026
50 : 1

non-human identities outnumber human identities in large organisations - the API keys, tokens and machine credentials behind these agents.

Silverfort research

The EU AI Act's high-risk obligations became enforceable from 2 August 2026. You can't demonstrate an agent acted within its authority if you never gave it an identity in the first place.

Questions we hear a lot

Does this cover every agent we have?

It covers the agents you deploy and own, with a person behind them, which is most of what enterprises run today. Fully autonomous, machine-to-machine agents are where the industry is heading next, and we're straight with customers about where that line currently sits.

What about tools people have connected themselves, outside IT's knowledge?

You get visibility into what those tools have already been granted. Controlling the rest is a question of the right architecture, and it's exactly where a good partner earns their place.

Does this stop an agent that's been hijacked or manipulated?

Identity limits what an agent can reach and gives you a way to cut it off. Stopping the manipulation itself happens at a different layer, one that's still maturing across the whole market, and we won't tell you otherwise.

Worth reading beyond us

We're not going to pretend this is only our territory. Some of the best thinking on this is coming from the vendors and platforms themselves, and from other specialists working the same problem from a different angle.

From our own team

From the platforms and specialists

We're not competing with any of these. If a conversation about your stack points toward one of them, we'd rather say so than pretend otherwise.

Where to start

Of the AI agents turning up in your organisation, roughly how many have a person clicking "go", versus running on their own? And who's securing the ones that don't?

Most organisations can't answer that yet, and that's a reasonable place to be. The Agentic Identity Readiness Assessment is a short, structured way to find out: what you're already running, which lane each agent sits in, what your existing identity setup already covers, and what still needs a plan.

No product pitch. Just an honest picture of where you stand, and what to do next.

Book your Readiness Assessment