AI Agents Outgrow Human-Centric IAM

Cybersecurity Dive and CSO Online say AI agent adoption has outrun the identity systems built for people, with more than 3 million agents operating globally, thousands being spun up each week, and initial scans uncovering thousands of previously unknown agents. The concern is not hypothetical: the articles frame agent security as a runtime problem now, not a deployment-time approval problem. The mechanics are simple and awkward for current IAM. Agents use real credentials, approved APIs, and trusted paths, then chain many allowed steps so the final outcome is unauthorized even though each step looks legitimate. Because they can also spawn sub-agents and act at machine speed, one identity can turn into a swarm before standard monitoring catches the pattern. For teams putting agents into SaaS, browsers, endpoints, or internal tools, the lasting issue is that human-centric identity controls do not describe what is actually active anymore. The reporting points to a shift toward continuous discovery and behavior-based control, because the hidden exposure is every agent instance that can act like an insider without looking unusual in the logs.

Part of the PlainSec briefing for 2026-09-08

Editions

Sources