Agentic AI shifts identity from a back-office control function to a frontline operating discipline. For IT leaders, the management issue is not simply whether agents can perform tasks, but under what authority, with which limits, and how those actions are traced back to accountable business owners. If AI agents act across procurement, customer operations, and data systems, identity design becomes inseparable from governance design.
The article points to a practical gap: most IAM models were built for persistent human users and relatively stable entitlements. That creates a mismatch when agents are temporary, autonomous, and able to act at machine speed. CIOs and CISOs should treat this as a modernization decision, not a tool add-on. Context-aware access means linking the human requester, the agent’s delegated purpose, the target resource, and the transaction risk into a single policy model.
The trade-off is clear: tighter contextual controls can slow early deployment, while weak controls create outsized operational, compliance, and fraud exposure. Leaders should resist scaling agentic AI through exception-based workarounds or shared service accounts, which undermine auditability and accountability. Instead, establish explicit decision rights for agent onboarding, approval of permitted actions, monitoring thresholds, and revocation triggers.
Questions for leadership teams:
- Who owns an agent’s authority: the business process owner, application owner, or security team?
- Can current IAM, PAM, and audit controls distinguish human actions from delegated agent actions?
- Which high-value use cases justify contextual identity investment first?
- What evidence will prove that agent actions remain compliant, reversible, and attributable?
The next wave of AI is not about generating content — it’s about taking action in a secure and operationalized manner.
At this year’s Forrester Security & Risk Forum in November, I’ll be delivering a keynote on one of the most significant emerging challenges in AI agent adoption and identity security: how to securely operationalize agentic AI at scale. My session will cover why:
- Agentic AI is transforming identity and access management. For years, organizations focused on static controls of human access to applications, data, and infrastructure. Today’s AI agents change that equation. AI agents are performing autonomous tasks on behalf of humans: purchasing goods, processing refunds, accessing databases, interacting with SaaS applications, and making business decisions. As these agents move from experimentation to production, enterprises must ensure that agents are trusted and that the enterprise can manage the AI agents’ identity and access appropriately.
- Old identity and access management designs and patterns are inadequate. Traditional identity and access management approaches were designed for human users and used static permissions. That approach doesn’t work well with agentic AI. Agents are autonomous, dynamic, ephemeral, and capable of taking actions at machine speed. Static roles and binary allow-or-deny models are no longer sufficient.
- Context matters more than ever. My keynote will explore a simple but powerful concept: identity context. This consists of human, AI agent, and resource identity context.
Agentic AI is rapidly becoming the next major identity frontier. Organizations that establish contextual identity foundations today will be better positioned to govern autonomous systems tomorrow. My keynote will discuss the critical dimensions and uses of context and how to leverage context effectively to secure agentic AI.
I hope you can join me at Security & Risk Forum this November 9–10 in Washington, DC!
Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

