AI Agents Need Passports, Not Passwords
Companies are handing more decisions to autonomous AI agents, and the old rules about who gets access to what are breaking down. Here is what needs to change.

Key points
- AI agents, software programs that act and decide without a human clicking each step, are moving faster than the identity controls designed to govern them.
- Five areas need new rules: how agents prove who they are, how they talk to each other, how they handle secrets like passwords, how much access they carry, and how they connect to human worker accounts.
- Static credentials, meaning fixed usernames and passwords that never change, aren't safe for AI agents that touch dozens of systems in seconds.
- The principle of least privilege, giving any account only the minimum access needed for one specific job, becomes more urgent as agents hand tasks down a chain.
- Every action an AI agent takes should be traceable back to a human being who approved it.
Companies are deploying AI agents to book meetings, process invoices, query databases, and execute contracts. These aren't chatbots waiting for a question. They log in, pull data, trigger other processes, sometimes handing work to a second agent before a human sees the result.
The security controls built for human employees were never designed for this.
That gap is the subject of a detailed piece from CSO Online, which maps out five areas where today's identity management, the whole system of deciding who can access what, falls short for agentic AI. We've been tracking the governance gap since our June story on guardian agents, and this framing from CSO Online is the most operationally precise account of what's actually missing.
How do you even know which AI agent is which?
Right now, nobody fully agrees. Some organisations treat AI agents like service accounts, the faceless machine logins that software uses to connect to databases. Others argue agents deserve their own category. Either way, each agent needs something like a digital certificate: a verifiable credential that can be recognised across cloud platforms, on-premises systems, and third-party software.
Without that, there's no way to know which agent did what, or whether a rogue process snuck in pretending to be a trusted one.
The secrets problem is equally sharp. Passwords and API keys (the private codes that let one piece of software talk to another) typically sit in a vault until an IT team hands them out. That's too slow for agents that complete tasks in milliseconds. The smarter approach works like a modern hotel key card: issued for one stay, useless the moment you check out. Generate a credential, use it once, retire it. SailPoint's acquisition of Entro Security in June was a direct bet that this kind of dynamic secrets management is where the market is heading.
Should you worry about agent-to-agent handoffs?
Access creep is the quiet danger here. An agent might start a workflow carrying the same permissions as a senior analyst. But as it hands the task to a sub-agent, and that agent to another, those broad permissions shouldn't travel the whole chain. Each handoff should trim access until only the bare minimum needed for the next step remains.
For ordinary people, the practical concern is this: if your employer, bank, or hospital uses AI agents to process your data, you have a legitimate interest in whether those agents are properly identified and constrained. Ask whether the organisation can produce an audit trail, a log of every action an agent took and what permission authorised it.
If they can't, the agents are running loose.
MFA, multi-factor authentication, where you confirm your identity through two separate checks such as a password plus a code to your phone, wouldn't directly solve most of these problems. The challenge sits a layer below individual logins. It lives in the architecture itself, and patching the surface won't fix what's broken underneath.



