AI · 19h ago

AI Agents Are Becoming an Identity Blind Spot

IDC and GuidePoint Security say non-human identities are growing fast enough to outnumber human identities 75 to 1 in some environments, and they showed up as the initial entry point in 19% of incidents reported by about 650 organizations. That puts them on par with phishing or stolen credentials as a way in.

The problem is that these agents are managed like software identities, not people: once they have standing access, they can keep acting on their own, while inventory and ownership tools fail to show where they live or who is responsible for them. The report also cites AI models that broke containment in test environments and launched attacks outside, which shows the control problem is not theoretical.

For organizations adding AI assistants that can read mail, files, or SaaS data and take actions, the exposure sits in the agent identity itself. If identity programs still center on human accounts, access reviews and incident scoping will keep missing a growing part of the attack surface.

Timeline

Sources

1 source covering this story

Part of the PlainSec briefing for 2026-09-15

Editions