gshc2020.com

Council Post: The Agents Are Here: Why Your IAM Strategy Isn't Built For 2026

tags:
@ 18/08/2026

Israel Duanis is CEO of Linx Security, an identity governance platform for human, non-human, and agent identities across the enterprise.

getty

Between December 2025 and February 2026, attackers used compromised AI agents to extract 150 gigabytes of sensitive data from nine Mexican government agencies, including the federal tax authority and electoral institute. In June 2025, a zero-click prompt injection in Microsoft 365 Copilot allowed a single attacker to exfiltrate data from OneDrive and Teams.

These incidents point to a larger shift: AI agents are becoming a new identity class with privileged access, but most organizations are still governing them as if they were conventional users or service accounts.​

The EU AI Act's high-risk compliance obligations, while originally set to apply on August 2, 2026, will take effect in December 2027. ​The SEC is tightening rules around AI-driven decision-making. NIST is launching new standards for autonomous agents.

Still, most CISOs today are managing three overlapping identity problems simultaneously. You're handling human identity debt with dormant accounts, over-privileged users and legacy access from years ago. You're building governance for non-human service accounts and APIs numbering in the tens of thousands, and now you're deploying AI agents into production that need access to sensitive systems with no unified framework to control them.

To stay ahead of both attackers and regulators, organizations need to understand this isn't a sequential problem.

Three Identity Layers, One Broken System​

Every enterprise now operates across three distinct identity layers. Each one expands the attack surface, and weakness in any one of them can undermine the others.

Layer 1: Human identity

This includes dormant accounts, users with permissions from five jobs ago and excessive privileged access that nobody cleaned up because the business kept moving. This problem alone has historically been a nightmare to manage at scale.

Layer 2: Non-Human Identities

The second layer includes service accounts, API credentials and container identities. These likely number in the tens of thousands across your infrastructure. Most were never formally provisioned. Only 21% of organizations report having a matured program in place to govern agents.​

Layer 3: AI Agents

These are deployed now. They operate 24/7, spawn sub-agents dynamically, request permissions thousands of times per day and can chain together actions across dozens of systems in minutes. Unlike humans or service accounts, agents don't follow predictable workflows.

The problem is that your IAM system may be treating all three as separate challenges.

The Immediate Operational Crisis

Organizations are deploying agents to summarize documents, automate workflows and assist analysts without a clear framework for controlling their access. CISOs are asking questions their tools can't answer: Which AI agents have access to production data? What's the blast radius if an agent is compromised? Did that agent's access actually expire when the project ended? Can you revoke an agent's access instantly if it starts behaving strangely?

The standard approach—forcing agents into existing IAM systems—fails because agent access control operates on fundamentally different rules. Agents request permissions differently. They operate on sub-second cycles. They don't follow human workflows, and they can exploit access faster than humans can recognize the pattern.​

I've seen this firsthand. In one financial services organization, an AI agent deployed to research vendor risk accumulated access to procurement systems, vendor databases and internal communications within a matter of months. Much of that access wasn't formally provisioned; it emerged as the agent became embedded in day-to-day workflows. By the time leaders recognized how much access it had accumulated, revoking it without disrupting operations had become a significant challenge. This is where most enterprises are right now.

What Organizations Should Do​

I recommend building separate governance frameworks for agents instead of forcing them into human-centric workflows. Implement unified visibility across all three identity types so you can see which humans, service accounts and agents have access to critical systems in a single pane, not three separate reports.

Automate remediation. When you detect excessive access, policy violations or suspicious behavior, revoke access instantly across humans, service accounts and agents alike: no ticket, no approval cycle and no delay.

Most importantly, build continuous verification. When an agent requests permission to access a database, your system should check in real time: Is this agent supposed to exist? Does it have a valid deployment? Is the permission appropriate for its use case? Should this access be revoked?

If you're a CISO managing agents in production, here's what you should do—not sequentially, but in parallel:

• Audit your agent deployments and identify your agent access "blast radius." For your highest-risk agents, trace what systems they touch.

• Build separate governance for agents. Don't try to force agent access control into your existing IAM system. Design a parallel framework that treats agents as policy-driven, time-bound and continuously monitored.

• Implement detection and instant revocation. You need the ability to detect when an agent behaves outside expected parameters and revoke access immediately, mid-workflow if necessary. This is nonnegotiable for production agents.

• Fix human and non-human layers in parallel. Don't postpone cleaning up dormant accounts, and don't let that become an excuse to delay agent governance. Both need to happen simultaneously.

What's Coming Next

Agent sprawl is likely to become the default. By 2028, an average global Fortune 500 enterprise is projected to have over 150,000 agents in use, up from less than 15 in 2025​.​

The timeline to ensure compliance is getting shorter. Although the EU AI Act's high-risk requirements were extended to December 2027, organizations shouldn't treat that as a reason to postpone preparation. Building the governance, audit logging, documentation and oversight capabilities needed to support compliance takes time, and waiting until the deadline will leave many organizations scrambling.​​

AI-powered identity attacks are scaling, and attackers are weaponizing agents for autonomous cyber espionage. The blast radius of a compromised agent makes a compromised service account look tame.

The Decision Window

The enterprises that will be secure and compliant in the near future are building agent governance right now, in parallel with human and non-human identity work. Those that wait will face compressed timelines: agents already in production, exponential growth, regulatory pressure and an evolving threat landscape.​

The agents are already in production and the compliance requirements are coming. The question is whether you'll control them intentionally or discover you needed to at 2 a.m. on a Tuesday during an incident response.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?