The article usefully highlights a new class of identity risk: AI agents that inherit human or shared-service permissions, then persist beyond the project, owner or business need that created them. For IT leaders, the bigger issue is that this is not just another security control gap; it is an operating-model gap. Most IAM programs were designed around employees, contractors and application service accounts, not semi-autonomous software entities that can create, delegate and chain actions across systems.
That changes resilience planning. Recovery is no longer only about restoring systems after an incident; it also requires provable visibility into which agents exist, who sponsors them, what data they can touch, and how quickly their access can be revoked. If that inventory does not exist, incident response, audit and offboarding processes will all lag the speed at which agents proliferate.
A practical response is to treat agent creation as a governed lifecycle rather than an experimental convenience. That means requiring named business ownership, registration in a central repository, least-privilege access by default, expiration or re-attestation dates, and a clear kill-switch process when employees leave or projects end. Enterprises should also review where agents are using team identities or shared service accounts, because those shortcuts can erase accountability exactly where regulators and auditors will expect it.
The strategic takeaway for CIOs and CISOs is straightforward: if AI adoption is scaling faster than identity governance, resilience is already degrading. The first control to industrialize is not smarter agent capability, but reliable agent accountability.
While it might seem like AI is throwing a wrench into cybersecurity strategies by speeding up the threat of system vulnerabilities, CISOs are also using AI to strengthen their own security posture. But without guardrails in place, the proliferation of AI agents within organizations can create headaches around identity management and leave "orphaned" AI agents with unfettered access to private data.
CISOs face a complex identity management challenge involving not just human users, but also the AI agents they create and, at times, leave when they move on to other organizations.
"The risk is people start proliferating a lot of [AI agents] around the enterprise, and then they get orphaned, and then they become an attack vector," said Atticus Tysen, CIO and CISO at Intuit.
Tysen reviewed the four areas where AI is affecting enterprise security. The first three are familiar territory: AI can be used to enhance attacks against companies; it creates new attack surfaces as companies deploy it, and it gives defenders new tools to counter those threats. The fourth, AI governance, is where the proliferation of AI agents creates different problems.
Related:AI is changing network management. How smart can networks get?
"This is less about controlling the use of [AI], but more about ‘how do you enable proper MCP usage and enable people to produce agents that they share with others?’" Tysen said.
Atticus Tysen, CIO and CISO, Intuit
The rise of AI agents challenges identity management
One aspect of strong AI governance is identity management for AI agents within the enterprise.
While an employee might have good intentions in launching a new AI agent, loose access controls can quickly become a problem, Tysen said. If "they themselves have overbroad permissions, that then give the agent overbroad permissions, then the agent can then do things unexpected with those permissions. That’s not a bad actor. That’s a good actor just not knowing how to control what they’re building," he said.
Wally Dalyrymple, CISO at academic testing companies ETS and PSI, said one of the biggest risks from AI is identity management.
"How are you going to manage machine-to-machine identities when you were never built to manage machine-to-machine identities? We weren’t structured that way. Identity is the new perimeter," he said.
Dalyrymple explained that AI agents are now using organizational identities to access service accounts that aren’t always assigned to a person. An identity might be assigned to a team within the IT or security department and " now these service accounts are interacting with agents, and it’s happening so fast behind the scenes, and at such large volume and scale," he said. An AI agent might use a group’s identity to complete a task or share identities with other agents, for example.
Related:InformationWeek Podcast: Is quantum readiness worth a CIO’s effort?
"Identities get access to data – it could be PII, healthcare or HR data. What access does an agent have, and more importantly, who owns that agent?" he said.
Further complicating the matter, an employee might leave an organization after creating a dozen agents, leaving the organization to disable both the former employee’s account along with the accounts of every agent that person created, Dalyrymple explained. , Traditional identity and access management tools don’t know how to manage AI agents, he said.
Wally Dalyrymple, CISO, ETS and PSI
Managing agent sprawl
When Dalyrymple and his team run risk assessments for new enterprise projects, part of that process includes creating a plan for the management of agent sprawl.
"We have to treat each agent as its own identity," Dalyrymple said. This isn’t a one and done process – his team continually checks in with project teams to see if the project scope has changed and assess how that will impact the management of new agents.
One way Dalyrymple’s team manages AI agent identities is with AI agent attestation, a cryptographic method of proving an agent’s identity, combating drift, controlling autonomy, and securing collaboration between agents.
Related:Avoiding network logjams in the age of AI
According to Raghavaiah Avula, engineering leader and architect at security company Palo Alto Networks, AI attestation is an important process for validating that AI agents can be trusted in their current state since they evolve over time. Attestation makes assessments of "agent identity and role, model and configuration version, integrity of memory and context, trust score and behavior signals, and environment and dependency health," he said.
"Resilience now has to answer a second question, which is not just can we recover but do we even know what’s leaving or actually happening inside our environment right now, under what permissions and why?" Soin said.
Smartsheet’s approach to the AI agent challenge is Smart Hub, a central control panel for managing AI tools, where "every AI agent in the environment gets configured, owned, and monitored … with visibility into every agent in one place," he said.
"We’re doing agent identity as a repository within the corporate warehouse where you have a list of every agent that exists, every MCP that runs within the company is identified and we have that topology," Soin said.
Organizations need to be able to answer three main questions aboutAI agents: what actions are they taking within an organization, across which systems, and under what conditions. "If you can’t answer that, you’re not resilient," he said.
How is your organization handling identity management of AI agents? Let us know at [email protected].
Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

