AI Agents Become Identity Risk, Not Just Output Risk

Security teams are moving past the question of whether AI gives bad answers. The harder problem is that agents can now carry human access across tools, keep it after the person is gone, and create actions no one can cleanly own. That shifts AI security from validation to identity and delegation control. The 2026 SANS survey shows broad adoption. It says 78% of organizations now use AI in cybersecurity strategy, up from 50% in 2025, and 63% report significant shortcomings in detection and response. Unit 42 and Microsoft’s guidance push the same point: agents should be treated as first-class principals with managed identities, tight roles, and scoped tool access, because combined access across mail, files, tickets, and code can exceed what any one system looks like on its own. The forward risk is drift. As agentic workflows spread, inherited credentials, cross-system reach, and weak audit trails can make abuse hard to attribute or contain. The standard human-speed inventory model does not keep up with principals that act, chain, and persist across systems.

Part of the PlainSec briefing for 2026-07-17

Sources