In the AI era, identity evolves into the control plane for trust
Every major security shift ultimately comes down to one question: Who or what is allowed to do this? For most of the past two decades, the answer was a person with a username and password. In the artificial intelligence era, the answer increasingly is an agent, and most organizations have no idea how many agents […] The post In the AI era, identity evolves into the control plane for trust…
The AI era has transformed the concept of identity, elevating it to the control plane for trust within cybersecurity frameworks. Historically, security relied on human users with usernames and passwords. However, with artificial intelligence, the focus now shifts towards agents, many of which remain unknown to organizations. This shift underscores the critical role of identity in AI security.
The identity thesis is bolstered by data, such as a 2026 Identity Security Landscape report by Palo Alto Networks, which reveals that organizations manage an average of 109 machine identities for every human identity. Furthermore, AI agent identities are anticipated to grow by 85% in the next year. Research from SailPoint uncovers that over half of organizations fail to enforce least-privilege access for service accounts consistently across various systems.
Additionally, a significant proportion of AI agents have unrestricted access to sensitive data, yet only 21% of organizations feel confident in managing AI agent security risks.
This proliferation of highly privileged identities poses a real risk today. A recent example from SailPoint's earnings call detailed a proof-of-concept at a Fortune 500 company that discovered more than 10,000 unknown AI agents, highlighting the urgency of managing AI agent security risks. The rise of shadow IT and shadow agents, which spread in months rather than years, underscores the need for better governance.
Containment measures like sandboxes and secure runtimes are essential but fall short in addressing fundamental governance questions. These measures can prevent agents from accessing the internet but cannot provide visibility into who created the agent, under whose authority it operates, or whether it should still exist. Identity systems are essential to ensure accountability and governance, answering questions about data access, accountability, and revocation of access when necessary.
SailPoint has been actively addressing this issue with its Agentic Fabric, which discovers AI agents and machine identities, maps them to human owners, and enforces real-time authorization. This solution is part of a broader Identity Security Cloud, enhancing visibility and control. The company emphasizes that visibility without accountability merely compounds problems, as it does not solve the core issue of knowing who and what operates within the environment.
The upcoming SailPoint Navigate conference in Austin, TX, will provide insights into how the industry and SailPoint are preparing for this shift. Companies that treat agents as first-class identities are better positioned to scale AI with confidence, while those that do not risk facing the consequences of unmanaged AI agents.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.