29/09/2026
Every AI Agent Is Becoming An Identity
Cybersecurity has spent years improving the management of human and machine identities. Users are provisioned, assigned roles, required to use multifactor authentication, restricted through least privilege, monitored and eventually deprovisioned.
The same disciplines increasingly need to apply to AI agents. An agent that can access Microsoft 365, GitHub, a financial system or an internal database effectively has an identity. If it can call an API, execute code or modify a configuration, it has privileges and authority that need to be managed just like any other privileged identity.
AI agents are moving from answering questions to taking action, creating a new cybersecurity attack surface for businesses and government.