Orchid Security gives enterprises a kill switch for rogue AI agents
Identity security startup Orchid Security Inc. today added identity drift detection and application-level kill switches for artificial intelligence agents to its Identity Control Plane. The controls are meant to let security teams strip an agent of its authority the moment its behavior moves outside what was approved. Agents rarely have to defeat a security control […] The post Orchid Security…
Identity security firm Orchid Security has introduced a kill switch to manage rogue artificial intelligence agents within enterprise applications. The new Identity Control Plane feature detects identity drift, enabling security teams to revoke an agent's authority immediately when its behavior deviates from approved parameters. Unlike AI agents that often exploit hard-coded credentials, dormant accounts, and unmanaged authentication paths, this proactive approach prevents unauthorized access escalation.
Orchid's report "The Identity Gap: 2026 Snapshot" revealed that 57% of identities in enterprises are invisible, outnumbering the visible ones by 2-to-1. Two-thirds of nonhuman accounts were provisioned within applications, outside the purview of identity and access management tools. The Identity Control Plane now includes five capabilities: tagging applications, identities, and access paths with an AI readiness status, identifying orphaned, dormant, over-permissioned, and suspicious accounts, running continuous drift detection, orchestrating responses through existing identity and security tools, and documenting audit trails.
The application-level kill switch extends this functionality by terminating an agent's operational authority. Orchid CEO Roy Katmor attributes the release to boardroom stress, noting that security professionals must now justify why AI transformation is not proceeding faster, rather than simply stating it is not possible. Two integrations were launched alongside the update: a connector for Palo Alto Networks' Idira identity security platform to incorporate privileged accounts not already managed by Idira, and an integration with Splunk Enterprise Security for correlation and incident response.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.