Brian Contos is the Field CISO at Mitiga with 30+ years of experience building successful companies and evangelizing cybersecurity.
We need to stop treating identity as a human problem. Inside modern enterprises, identity has already expanded beyond people, beyond service accounts and beyond anything traditional IAM was built to understand. AI agents are now operating as autonomous actors with credentials, delegated access and the ability to chain actions across cloud and SaaS environments. They use identity, but more importantly, they operationalize it.
Unfortunately, most organizations can no longer answer a basic question in real time: What did my agent just do once I put it in motion?
As these systems move from experimentation into production, that visibility gap is becoming a security problem in its own right. It’s something I’ve observed time and time again as a cybersecurity leader. Agents are live, wired into workflows and operating at machine speed across systems that were never designed for autonomous decision-making.
The Identity Model Has Become Incomplete
Traditional identity models were built on the simple assumption that identities are stable and their actions are predictable. A user logs in, a service account runs a known function and access is reviewed, granted and periodically audited.
AI agents aren’t static identities. They’re decision loops wrapped in credentials. They interpret prompts, chain actions across systems and dynamically extend their own reach by interacting with other agents or services. The clean boundary between “identity” and “execution” no longer exists. Effectively, this means identity is a continuous flow of autonomous behavior.
That means most failures will not originate from sophisticated adversarial inputs. They will come from ordinary agents doing exactly what they were allowed to do, just not what anyone expected.
Production Outpaced Control
I’ve watched this shift quietly invalidate many of the tools organizations still rely on today. Role definitions, entitlement reviews and periodic audits are built for static conditions, but agents operate in dynamic ones.
AI agents aren’t confined to pilots or isolated sandboxes. They’re embedded directly into production workflows with organizations under pressure to move faster, automate more aggressively and deliver results immediately. Development cycles that once took weeks are now compressed into days or even hours.
In practice, many environments are operating with a “turn it on and see what it does” mentality. This is not because security leaders prefer it, but because velocity demands it.
The pressure is understandable, but the consequences are not. This pattern looks less like governance and more like experimentation at scale. You turn systems on quickly, connect broadly and refine later—if at all. That creates a structural problem: Security controls designed for deliberate change cannot keep up with systems designed for continuous change.
Agents are accessing SaaS systems like Salesforce, Workday, GitHub and Slack, spinning up downstream workflows without clear visibility and, in some cases, interacting with other agents that further expand access boundaries.
The Behavior-Versus-Access Blind Spot
This is an emerging ecosystem of machine-to-machine delegation layered on top of enterprise identity. And most organizations do not have a complete inventory of what exists inside it. Most security programs still focus on authorization at deployment. Registries, approval workflows and policy frameworks define boundaries before deployment. It’s necessary, but I’ve found it’s woefully incomplete.
Once an agent is live, the risk shifts from access to behavior. And behavior rarely conforms to predefined boundaries. An agent with legitimate credentials can perform actions that are technically authorized but operationally unintended. A single agent may trigger another, which interacts with a third system that then expands access or initiates downstream workflows.
Each step may be valid on its own, but the chain creates emergent behavior that is difficult to trace. By the time something appears suspicious, causality is fragmented across systems, logs and identities. The data exists, but the narrative does not.
The result is a fundamental gap between what is permitted and what is understood. If you cannot reconstruct what the agent accessed, what it triggered, what systems it interacted with and how that sequence unfolded, then you do not have visibility into security events. You have a partial inference stitched together after impact, and an inference alone is not a response strategy.
The Return Of ‘Any-Any-Any’ At Identity Scale
I’ve found that a familiar pattern is re-emerging under these new conditions. In earlier infrastructure eras, teams routinely adopted “any-any-any” configurations, otherwise known as open firewall rules that allowed any source, any destination and any protocol. It was the fastest way to make systems function, but it came at the expense of control.
AI agents are recreating that dynamic at the identity layer. The intention is operational efficiency. The outcome is persistent overreach.
To make matters worse, organizational churn means teams rotate, priorities shift and systems evolve faster than documentation or oversight can keep up. What remains are agents operating with permissions that no longer reflect current intent or human understanding.
What Security Leaders Actually Need To Change
Leaders hoping to address this crisis need to do three things. First, they must establish a complete inventory of non-human identities—not just formally defined agents, but all systems, workflows and automations with credentials and external reach. Most environments are significantly more exposed than assumed.
Second, leaders need to stop optimizing solely for prevention. Design permissions around containment. The goal is not perfect prevention; it is limiting the blast radius when behavior deviates from expectation.
Third, leaders must make reconstruction a core security capability. Organizations must be able to trace agent behavior across cloud and SaaS systems in near-real time, not through post-incident investigations that take days or weeks.
Autonomy Plus Accountability
The next wave of enterprise security incidents may not begin with an attacker at all. Those incidents may stem from a trusted agent operating exactly as designed inside an environment nobody fully understands.
Organizations that want to navigate this shift successfully shouldn’t slow AI adoption or attempt to eliminate risk entirely. They must pair autonomy with accountability and velocity with visibility.
We can’t prevent every failure. But we can ensure failures are understood before they become real crises. When identity becomes autonomous, controlling access is no longer enough. It’s about understanding behavior soon enough to pivot.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?







