AI Agents Are Taking Over Enterprise Systems. Nobody Knows Who They Are.
A four-hour outage. A room full of people who couldn't say which human authorized the last action. A new six-stage model explains why AI agents are breaking identity security, and what it takes to fix it.

Key points
- A single AI agent with unchecked access to a production system caused a four-hour outage during a 2025 client engagement, and no one could identify who had authorized its last action.
- KuppingerCole's 2026 Leadership Compass found that non-human identities (accounts used by software, not people) now outnumber human user accounts in many companies by 25 to 50 times.
- The OWASP GenAI Security Project listed identity abuse among its top four dangers for AI agents in its 2025 taxonomy.
- A joint advisory from CISA, NSA, and intelligence agencies from Australia, Canada, New Zealand, and the UK, published 1 May 2026, named unchecked AI agent privileges as the foundational security concern.
- A six-stage maturity model, detailed in CSO Online, gives organizations a ladder from invisible and ungoverned to auditable and contained.
Last year, during a security review, an AI agent quietly pushed a broken configuration to a company's server management system. The system went down for four hours. When the review team asked which human had approved the agent's last decision, nobody could answer.
That same question went unanswered across three separate client engagements in three different industries. Identical gap, different companies.
In each case the agent appeared in the company's identity system (the software that tracks who or what has access to which resources) as a service account: a digital identity assigned to software rather than a person. It held a permanent access key, had no multi-factor authentication (the extra verification step that makes stolen passwords useless on their own), and offered no quick way to shut it off.
How did nobody notice this was a problem?
They noticed AI. Identity, they missed.
Every major company is adding slides about AI agents to its strategy decks. Far fewer have a slide about who these agents actually are inside the systems that control access, what they're permitted to do, and whether the organization can cut them off in seconds.
Gartner's Top Cybersecurity Trends 2026, written by Director Analyst Alex Michaels, flags both problems by name. One is a strategy question. The other is about control, and that's the one auditors and regulators will ask about.
Traditional service accounts do one narrow job: fetch a backup, run a report. Their permissions are set once and rarely touched. An AI agent works differently. It receives a goal, works out its own steps, calls whatever tools it judges useful, and produces a result nobody scripted in advance. That flexibility is the point. It's also the risk.
KuppingerCole's 2026 Leadership Compass found that the tooling enterprises use to manage access was built around employees joining or leaving organizations, and it was never designed to track thousands of AI agents at scale. We covered a related blind spot on 2 July in our look at how legacy identity governance tools handle autonomous agents.
OWASP, the nonprofit behind widely used security checklists, catalogued the resulting risks in its 2025 Agentic AI Threats taxonomy. Three of the four highest-rated dangers are identity problems: software agents misusing their tools, agents abusing inherited permissions, and agents drifting outside their intended behavior.
Six requirements must be met before any AI agent goes live in a production environment. Each agent needs its own unique identity, no sharing. It must act on behalf of a named human, not from its own standing authority. Access keys must expire within an hour. Every action must be logged with a timestamp and a record of who instructed it. Identity must be re-checked at intervals during long tasks. And the organization must be able to cut the agent off within seconds.
If a company can't meet all six, it doesn't have a governance problem. It has a readiness problem and the agent shouldn't be deployed.
Should you worry?
The six-stage maturity model built around these requirements runs from Stage 0 (agents exist but are completely invisible to security teams) up to Stage 5 (anomalies are caught automatically and trigger instant review or shutdown). Stage 3 is the minimum defensible position. Below it, deployment isn't something a board or an incident review team should accept.
For ordinary employees, the question is practical. If your organization is rolling out AI tools that act on your behalf, ask your IT team whether those tools have unique identities, expiring access credentials, and a documented off switch. They're not technical questions. They're accountability questions, and someone in your organization needs to be able to answer them.
The honest read on this space: the maturity model is useful, but most enterprises aren't close to Stage 3 yet. Watch whether the NIST AI Agent Standards Initiative, launched in February 2026, produces requirements that give procurement teams something to hold vendors to. That's where the real enforcement pressure will come from.



