{"id":112852,"date":"2026-07-21T04:43:12","date_gmt":"2026-07-21T04:43:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/112852\/"},"modified":"2026-07-21T04:43:12","modified_gmt":"2026-07-21T04:43:12","slug":"ai-agents-are-still-logging-in-as-humans","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/112852\/","title":{"rendered":"AI agents are still logging in as humans"},"content":{"rendered":"<p>Most large companies run more than one <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/24\/product-showcase-prophet-security-ai-soc-platform\/\" rel=\"nofollow noopener\" target=\"_blank\">AI platform<\/a> at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep their options open.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/enterprise_AI_identity_risk.webp\" class=\"aligncenter\" alt=\"enterprise AI identity risk\" title=\"AI authentication\"\/><\/p>\n<p>Sanctioned tools and personal accounts sit side by side inside many organizations. Anonymized sign-on data from more than 20,000 organizations on the Okta tracked this spread from June 2022 through June 2026. Each new tool arrives with its own set of logins and permissions.<\/p>\n<p>The index draws on sanctioned applications that reach users through corporate single sign-on. The research team tracked over a hundred distinct AI products and consolidated them into 74 vendor suites, sorted across categories that span foundational models, developer tooling, enterprise search, collaboration and productivity, meeting AI, and creative suites.<\/p>\n<p>A two-speed market<\/p>\n<p>The Okta Enterprise AI Index sorts vendors into two groups by how fast their enterprise customer base grew across the study period. AI-native companies such as Anthropic, OpenAI, and Cursor multiplied their corporate customers by more than four times.<\/p>\n<p>A data-driven cutoff separated the two clusters. Established software makers such as Microsoft, Google Workspace, Figma, Slack, Adobe, and Notion grew under that mark and took the AI-enhanced label. Both groups gained ground. Startups won new use cases, and incumbents added AI features for the customers they already had.<\/p>\n<p>From chat to action<\/p>\n<p>The kind of AI landing in these companies changed along the way. Early tools completed code and answered questions. The three phases trace a move from autocomplete to chat to agents. The shift toward agents gathered force in spring 2025, when coding tools began running longer chains of work with less human prompting.<\/p>\n<p>Newer systems move through codebases and finish multi-step tasks on their own. Anthropic passed OpenAI in enterprise accounts in March 2026 and led it in monthly active users the following month. Microsoft 365 still sits far ahead on raw volume, with Anthropic reaching under half of its enterprise account total.<\/p>\n<p>Credentials scatter as vendors add up<\/p>\n<p>Every added platform brings its own connections. AI chat and agentic features reach into corporate knowledge through app-to-app links built on secrets and tokens, and those credentials spread across many systems. The count of platforms and the security exposure rise together.<\/p>\n<p>\u201cOur data shows that as the number of platforms grows, so does the risk of over-permissioned apps and orphaned tokens,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/fei-liu-pt\/\" target=\"_blank\" rel=\"nofollow noopener\">Fei Liu<\/a>, Principal Emerging Tech Researcher at Okta, told Help Net Security. She calls for a change in mindset: \u201cSecurity teams need to stop thinking about this merely as \u2018adding a new software vendor\u2019 and start treating it as an expansion of their identity fabric.\u201d Least-privilege access and a lifecycle tied to real usage keep each grant in check.<\/p>\n<p>Agents borrowing human logins<\/p>\n<p><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/03\/26\/ciso-ai-agent-identity-security-report\/\" rel=\"nofollow noopener\" target=\"_blank\">Credentials for AI agents<\/a> come mostly from older methods. Companies lean on service accounts, static API keys, and, in some cases, shared human logins to authorize agent workflows. \u201cWe\u2019re seeing a heavy reliance on traditional service accounts and static API keys, and unfortunately, we still see instances of shared human logins being used to authorize agentic workflows,\u201d Liu said.<\/p>\n<p>The audit trail suffers when an agent runs under a person\u2019s account. \u201cWhen an AI agent inherits a human\u2019s login, you completely lose your audit trail \u2014 you can no longer distinguish whether a critical action was taken by an employee or autonomously by an algorithm,\u201d she said. Okta\u2019s guidance puts three questions to every agent: where it runs, what it can connect to, and what it can do. Demand is rising for dedicated non-human identities that carry their own lifecycle management and access reviews.<\/p>\n<p>The shadow AI layer<\/p>\n<p>A large share of AI use sits outside the sanctioned tools measured by the index. Employees spin up their own instances in personal cloud environments or reach unsanctioned models through personal accounts. \u201cFor every enterprise-grade AI tool provisioned by IT, there are inevitably pockets of developers or marketing teams spinning up separate instances in their own cloud environments or using personal accounts,\u201d Liu said.<\/p>\n<p>By her account, this <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/29\/products-ai-pentesting\/\" rel=\"nofollow noopener\" target=\"_blank\">shadow layer<\/a> runs larger than the sanctioned footprint. The risk centers on data movement. \u201cIf an employee uses a personal account to access an unsanctioned LLM, and pastes proprietary source code or customer data into the prompt, the security team has zero visibility and no ability to revoke that access,\u201d she said.<\/p>\n<p>A single identity layer sits at the center of the response. Companies should \u201cprovide \u2018paved roads\u2019 to bring the most requested AI tools into the SSO and governance fold so employees don\u2019t feel forced to bypass IT in the first place,\u201d Liu said. More vendors, more agents, and more credentials raise the value of one place to grant, review, and revoke access across every platform in use.<\/p>\n","protected":false},"excerpt":{"rendered":"Most large companies run more than one AI platform at the same time. Developers pull up coding assistants,&hellip;\n","protected":false},"author":2,"featured_media":112853,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,24,10649,57891,313,4182,30],"class_list":["post-112852","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-ai","tag-authentication","tag-credentials","tag-cybersecurity","tag-okta","tag-report"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/112852","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=112852"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/112852\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/112853"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=112852"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=112852"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=112852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}