AI Agents Shift the Perimeter Before Login

AWS and Bruce Schneier both describe autonomous AI agents that can authenticate, chain actions, and keep working long enough to make old identity-first defenses look misplaced. The practical change is where they get stopped: in the examples, the agent hit captchas, account-age checks, IP reputation filters, and client-side friction before identity verification ever mattered. That matters because the bottleneck is no longer just who the user is. If a machine can create accounts, retry quickly, and carry out multistep workflows on its own, then pre-identity gates become the first effective throttle and can block abuse even when login controls are intact. For teams using AI assistants that browse, email, or open SaaS accounts, the control point has moved outward to the service edge. The exposure that persists is any workflow that assumes authentication is the main choke point; machine-speed abuse can still get far enough to matter before a human review ever starts.

Part of the PlainSec briefing for 2026-09-02

Every edition of this story: AI Agents Shift the Perimeter Before Login

Sources