Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Why AI Agents Are The Identity Crisis Nobody’s Logging

Why AI Agents Are The Identity Crisis Nobody’s Logging

2 September 2026
The companies getting the most from AI are rethinking how work gets done

The companies getting the most from AI are rethinking how work gets done

2 September 2026
Why AI Investments Fail Without Comprehensive Process Transformation

Why AI Investments Fail Without Comprehensive Process Transformation

2 September 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Why AI Agents Are The Identity Crisis Nobody’s Logging
Innovation

Why AI Agents Are The Identity Crisis Nobody’s Logging

Press RoomBy Press Room2 September 20266 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Why AI Agents Are The Identity Crisis Nobody’s Logging

Brian Contos is the Field CISO at Mitiga with 30+ years of experience building successful companies and evangelizing cybersecurity.

​We need to stop treating identity as a human problem. Inside modern enterprises, identity has already expanded beyond people, beyond service accounts and beyond anything traditional IAM was built to understand. AI agents are now operating as autonomous actors with credentials, delegated access and the ability to chain actions across cloud and SaaS environments. They use identity, but more importantly, they operationalize it.

Unfortunately, most organizations can no longer answer a basic question in real time: What did my agent just do once I put it in motion?

As these systems move from experimentation into production, that visibility gap is becoming a security problem in its own right. It’s something I’ve observed time and time again as a cybersecurity leader. Agents are live, wired into workflows and operating at machine speed across systems that were never designed for autonomous decision-making.

The Identity Model Has Become Incomplete

Traditional identity models were built on the simple assumption that identities are stable and their actions are predictable. A user logs in, a service account runs a known function and access is reviewed, granted and periodically audited.

​AI agents aren’t static identities. They’re decision loops wrapped in credentials. They interpret prompts, chain actions across systems and dynamically extend their own reach by interacting with other agents or services. The clean boundary between “identity” and “execution” no longer exists. Effectively, this means identity is a continuous flow of autonomous behavior.

​That means most failures will not originate from sophisticated adversarial inputs. They will come from ordinary agents doing exactly what they were allowed to do, just not what anyone expected.

Production Outpaced Control

I’ve watched this shift quietly invalidate many of the tools organizations still rely on today. Role definitions, entitlement reviews and periodic audits are built for static conditions, but agents operate in dynamic ones.

AI agents aren’t confined to pilots or isolated sandboxes. They’re embedded directly into production workflows with organizations under pressure to move faster, automate more aggressively and deliver results immediately. Development cycles that once took weeks are now compressed into days or even hours.

In practice, many environments are operating with a “turn it on and see what it does” mentality. This is not because security leaders prefer it, but because velocity demands it.

The pressure is understandable, but the consequences are not. This pattern looks less like governance and more like experimentation at scale. You turn systems on quickly, connect broadly and refine later—if at all. That creates a structural problem: Security controls designed for deliberate change cannot keep up with systems designed for continuous change.

Agents are accessing SaaS systems like Salesforce, Workday, GitHub and Slack, spinning up downstream workflows without clear visibility and, in some cases, interacting with other agents that further expand access boundaries.

The Behavior-Versus-Access Blind Spot

This is an emerging ecosystem of machine-to-machine delegation layered on top of enterprise identity. And most organizations do not have a complete inventory of what exists inside it. Most security programs still focus on authorization at deployment. Registries, approval workflows and policy frameworks define boundaries before deployment. It’s necessary, but I’ve found it’s woefully incomplete.

Once an agent is live, the risk shifts from access to behavior. And behavior rarely conforms to predefined boundaries. An agent with legitimate credentials can perform actions that are technically authorized but operationally unintended. A single agent may trigger another, which interacts with a third system that then expands access or initiates downstream workflows.

Each step may be valid on its own, but the chain creates emergent behavior that is difficult to trace. By the time something appears suspicious, causality is fragmented across systems, logs and identities. The data exists, but the narrative does not.

The result is a fundamental gap between what is permitted and what is understood. If you cannot reconstruct what the agent accessed, what it triggered, what systems it interacted with and how that sequence unfolded, then you do not have visibility into security events. You have a partial inference stitched together after impact, and an inference alone is not a response strategy.

The Return Of ‘Any-Any-Any’ At Identity Scale

I’ve found that a familiar pattern is re-emerging under these new conditions. In earlier infrastructure eras, teams routinely adopted “any-any-any” configurations, otherwise known as open firewall rules that allowed any source, any destination and any protocol. It was the fastest way to make systems function, but it came at the expense of control.

AI agents are recreating that dynamic at the identity layer. The intention is operational efficiency. The outcome is persistent overreach.

To make matters worse, organizational churn means teams rotate, priorities shift and systems evolve faster than documentation or oversight can keep up. What remains are agents operating with permissions that no longer reflect current intent or human understanding.​

What Security Leaders Actually Need To Change

Leaders hoping to address this crisis need to do three things. First, they must establish a complete inventory of non-human identities—not just formally defined agents, but all systems, workflows and automations with credentials and external reach. Most environments are significantly more exposed than assumed.

Second, leaders need to stop optimizing solely for prevention. Design permissions around containment. The goal is not perfect prevention; it is limiting the blast radius when behavior deviates from expectation.

Third, leaders must make reconstruction a core security capability. Organizations must be able to trace agent behavior across cloud and SaaS systems in near-real time, not through post-incident investigations that take days or weeks.

Autonomy Plus Accountability

The next wave of enterprise security incidents may not begin with an attacker at all. Those incidents may stem from a trusted agent operating exactly as designed inside an environment nobody fully understands.

Organizations that want to navigate this shift successfully shouldn’t slow AI adoption or attempt to eliminate risk entirely. They must pair autonomy with accountability and velocity with visibility.

We can’t prevent every failure. But we can ensure failures are understood before they become real crises. When identity becomes autonomous, controlling access is no longer enough. It’s about understanding behavior soon enough to pivot.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Brian Contos
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Why AI Investments Fail Without Comprehensive Process Transformation

Why AI Investments Fail Without Comprehensive Process Transformation

2 September 2026
Why Accurate Data Alone Won’t Create Value

Why Accurate Data Alone Won’t Create Value

2 September 2026
​The Agentic Web Needs A Trust Layer

​The Agentic Web Needs A Trust Layer

1 September 2026
How Agentic AI Is Coming For The Seat, Not The System

How Agentic AI Is Coming For The Seat, Not The System

1 September 2026
The GENIUS Act And CLARITY Act Are Infrastructure Opportunities For Banks

The GENIUS Act And CLARITY Act Are Infrastructure Opportunities For Banks

1 September 2026
Broad AI Adoption Built Fluency, Agents Demand Focus

Broad AI Adoption Built Fluency, Agents Demand Focus

1 September 2026
Don't Miss
Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

By Press Room22 October 2024

Azura, a new platform for decentralized finance, launched on Tuesday after raising $6.9 million in…

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

27 December 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Why Accurate Data Alone Won’t Create Value

Why Accurate Data Alone Won’t Create Value

2 September 20262 Views
Fed’s Austan Goolsbee says AI is ‘not far’ from overheating the economy

Fed’s Austan Goolsbee says AI is ‘not far’ from overheating the economy

2 September 20262 Views
Galderma’s 0M bet on US manufacturing captures Europe’s new investment playbook

Galderma’s $650M bet on US manufacturing captures Europe’s new investment playbook

2 September 20264 Views
San Francisco Dems break with party over billionaire tax—and reveal how Prop 40 has split the left

San Francisco Dems break with party over billionaire tax—and reveal how Prop 40 has split the left

2 September 20262 Views

Recent Posts

  • Why AI Agents Are The Identity Crisis Nobody’s Logging
  • The companies getting the most from AI are rethinking how work gets done
  • Why AI Investments Fail Without Comprehensive Process Transformation
  • Single American adults say partners should ideally be earning $139,000 a year
  • Why Accurate Data Alone Won’t Create Value

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Why AI Agents Are The Identity Crisis Nobody’s Logging

Why AI Agents Are The Identity Crisis Nobody’s Logging

2 September 2026
The companies getting the most from AI are rethinking how work gets done

The companies getting the most from AI are rethinking how work gets done

2 September 2026
Why AI Investments Fail Without Comprehensive Process Transformation

Why AI Investments Fail Without Comprehensive Process Transformation

2 September 2026
Most Popular
Single American adults say partners should ideally be earning 9,000 a year

Single American adults say partners should ideally be earning $139,000 a year

2 September 20262 Views
Why Accurate Data Alone Won’t Create Value

Why Accurate Data Alone Won’t Create Value

2 September 20262 Views
Fed’s Austan Goolsbee says AI is ‘not far’ from overheating the economy

Fed’s Austan Goolsbee says AI is ‘not far’ from overheating the economy

2 September 20262 Views

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.