In the AI era, identity evolves into the control plane for trust
Every major security shift ultimately comes down to one question: Who or what is allowed to do this?
For most of the past two decades, the answer was a person with a username and password. In the artificial intelligence era, the answer increasingly is an agent, and most organizations have no idea how many agents they have, what they can reach, or who is responsible for them.
This is the primary reason identity has become a critical, and some would argue the most important, layer in the AI security stack. Reflecting this, the theme of this year’s SailPoint Technologies Inc.’s Navigate conference is “AI, secured,” which I will be attending on October 5-8 in Austin, TX.
The identity math has changed
A tremendous amount of data supports the identity thesis. As an example, Palo Alto Networks Inc.’s 2026 Identity Security Landscape report found that organizations now manage an average of 109 machine identities for every human identity, and companies expect AI agent identities to grow 85% over the next 12 months. The same research found that more than half of organizations can’t consistently enforce least-privilege access for service accounts across cloud, software-as-a-service and on-premises systems.
SailPoint’s own research is equally telling: Some 97% of AI agents have access to sensitive data, yet only 21% of organizations are highly confident they can manage AI agent security risks. Put those together, and you have an exploding population of highly privileged identities that almost nobody is governing well.
It’s important to note that the risk is real today. On SailPoint’s most recent earnings call, management described a proof-of-concept at a Fortune 500 company that uncovered more than 10,000 previously unknown AI agents and thousands of related risks. Shadow IT took years to spread, while shadow agents are spreading in months. A recent ZK Research data point found that almost half of AI use is on mobile devices, most of which information technology can’t see. As has been the case with every tech transition, if users do not get the experience they want from work tools, they will turn to consumer applications, and that’s happening today with AI.
Why identity, and why now
Much of the industry’s work on agent security has focused on containment: sandboxes, secure runtimes, guardrails, and, increasingly, hardware enforcement. That work is essential, but it doesn’t answer the most basic governance questions. A sandbox can prevent an agent from reaching the internet, but it can’t tell you who created that agent, whose authority it’s acting under, or whether it should still exist. For that, even the most sophisticated runtime must rely on an identity system.
In other words, every layer of agent security depends on the enterprise getting identity right. Containment tells you what an agent can’t do. Identity tells you who the agent is, who owns it, what it’s entitled to, and when that entitlement should end. You need both, but identity is the system of record everything else relies on.
Identity matters more for agents than it ever did for people for three reasons.
First, agents operate at machine speed. A human with excessive privileges might misuse them occasionally. An agent with excessive privileges can exercise them thousands of times an hour, and as the Hugging Face incident this summer showed, it can find paths no one anticipated.
Second, agents accumulate access. People change roles but retain permissions they no longer need; that’s a longstanding identity problem. Agents do the same thing faster, spawning sub-agents, borrowing credentials and combining permissions in ways no single policy anticipated.
Third, agents undermine accountability. When something goes wrong with a human account, there’s a person to call. With agents, the owner is often unclear, credentials are shared, and the logs point to a service account nobody remembers creating. SailPoint Chief Executive Mark McClain explained on the earnings call that enterprises need to know what data each agent can access, which human is accountable for that access, and how to revoke it when necessary. Those are the right three questions, and most companies can’t answer any of them today.
SailPoint’s bet on unified identity
SailPoint has leaned hard into this problem. In May, it launched Agentic Fabric, which discovers AI agents and machine identities, maps each to a human owner, and enforces real-time authorization. It became GA in August as part of a broader SailPoint Identity Security solution that pairs it with Human Fabric, the evolution of its Identity Security Cloud, on the Atlas platform. Capabilities include endpoint and browser sensors that expose hidden agents, Model Context Protocol servers, inline redaction of personal data before it reaches large language models, and a centralized kill switch for rogue agents.
I met with SailPoint President Matt Mills at BlackHat, and we discussed the product’s importance. He explained, “You cannot secure what you cannot see, or what you cannot tie back to accountability.” It’s the latter part of his statement that’s most important, because visibility without ownership just creates a longer list of problems.
What to watch at SailPoint Navigate
SailPoint Navigate is coming up next week, and here’s what I’ll be looking for:
- Proof in production. Agentic Fabric has been generally available for about two months. I want to hear from customers about how many agents they found, how they assigned ownership and what they shut down.
- Interoperability with the agent stack. Identity has to integrate with runtimes such as OpenShell, cloud agent platforms and developer tools. SailPoint’s recent Cursor connector is a good start, but the ecosystem should expand.
- Just-in-time access for agents. Standing privilege is the enemy. I’ll be watching how far SailPoint pushes toward zero standing privilege for nonhuman identities.
- Speed of governance. Quarterly access reviews don’t work for identities created and destroyed in minutes. Governance has to become continuous and largely automated.
Recommendations for IT pros
Regardless of which vendor an organization chooses to use, this is where the focus for identity should be:
- Inventory every agent. You can’t govern what you can’t see. Run discovery across cloud, software-as-a-service, endpoints and browsers, and expect the number to be much higher than you think.
- Assign a human owner to every agent. No agent should exist without a named person accountable for it. Disable unowned agents by default.
- Eliminate standing privileges. Move agents to just-in-time, scoped access that expires when the task is complete. Never embed long-lived keys or tokens in agent code.
- Govern humans and machines together. Agents often act on people’s behalf. Managing them in separate tools creates blind spots, so bring human, machine and agent identities into a single governance model.
- Build and test a kill switch. Know exactly how you would revoke an agent’s access and credentials in seconds and practice it before you need to.
- Connect identity to enforcement. Ensure your identity platform feeds your agent runtimes, network controls and security operations tools so policy is enforced wherever the agent goes.
Final thoughts
The industry has spent the past few years debating whether AI is safe, and that discussion has reached a crescendo over the past couple of months. The more practical question for IT leaders is whether they know who and what is operating within their environment. Identity has always been foundational to security, but in the AI era it becomes the control plane for trust.
Companies that treat agents as first-class identities can scale AI with confidence. Those that don’t will eventually learn the hard way what their agents have been doing. Navigate should give us a good read on how ready the industry and SailPoint are for that shift.
Zeus Kerravala is a principal analyst at ZK Research, a division of Kerravala Consulting. He wrote this article for SiliconANGLE.
Photo: SailPoint
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.