{"id":55288,"date":"2026-05-29T14:42:08","date_gmt":"2026-05-29T14:42:08","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/55288\/"},"modified":"2026-05-29T14:42:08","modified_gmt":"2026-05-29T14:42:08","slug":"why-agentic-ai-and-identity-sprawl-add-up-to-massive-security-risk-experts","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/55288\/","title":{"rendered":"Why Agentic AI And Identity Sprawl Add Up To Massive Security Risk: Experts"},"content":{"rendered":"<p>Identity is the crucial area to focus on when it comes to preventing cyber exposure through the use of AI agents, security experts tell CRN.<\/p>\n<p>Identity will increasingly be the crucial area for solution providers to focus on when it comes to preventing the potential for massive cyber exposure through the use of AI agents, security experts told CRN.<\/p>\n<p>Particularly in the era of AI agents, there\u2019s no question that identity \u201cabsolutely is the perimeter at this point,\u201d said Rob Gregory, CISO at Denver-based Optiv, No. 28 on CRN\u2019s 2025 <a href=\"https:\/\/www.crn.com\/sp-500\/sp2025\" rel=\"nofollow noopener\" target=\"_blank\">Solution Provider 500<\/a>.<\/p>\n<p>[Related: <a href=\"https:\/\/www.crn.com\/news\/security\/2026\/analysis-amid-claude-mythos-fud-don-t-forget-about-identity\" rel=\"nofollow noopener\" target=\"_blank\">Analysis: Amid Claude Mythos FUD, Don\u2019t Forget About Identity<\/a>]<\/p>\n<p>Even with the huge concern around accelerated vulnerability discovery and exposure through frontier AI models such as Anthropic\u2019s Claude Mythos, vulnerabilities are \u201cstill not the most accessed ingress vector for an attack\u2014that really still lies in identity,\u201d Darktrace\u2019s Nicole Carignan said.<\/p>\n<p>The expected surge in agentic AI usage, meanwhile, will only exacerbate existing risks around identity sprawl, according to experts. Many predictions suggest there will be 50 or more autonomous agents for every human identity in the near future, which will have \u201cthe same credentials of human identities,\u201d said Carignan, senior vice president of security and AI strategy at Cambridge, U.K.-based Darktrace.<\/p>\n<p>Thus, \u201cif you have a compromised human identity that\u2019s now running 50 autonomous agents, you have kind of permissive accesses and capabilities across an organization,\u201d she said. \u201cThat\u2019s quite terrifying.\u201d<\/p>\n<p>Identity will therefore still be a critical area of focus because so much is tied to the identity control plane, according to Carignan.<\/p>\n<p>This means that tracking the behavior of agents will be essential, experts said.<\/p>\n<p>\u201cAgents in and of themselves are identities. And what they can do\u2014or what they should be able to do\u2014needs to be tracked, reviewed, attested to,\u201d Optiv\u2019s Gregory said. \u201cThere should be an approval process. So it should have your traditional life-cycle management. It should have your traditional IAM [identity and access management] practices.\u201d<\/p>\n<p>Organizations should also follow the principles of least privilege for the identities associated with their AI agents, Gregory told CRN.<\/p>\n<p>        Blueprint For Securing Agentic<\/p>\n<p>Identity security vendor Okta recently disclosed what it\u2019s calling the \u201cnew blueprint for the secure agentic enterprise,\u201d with the unveiling of a new framework for addressing the most critical questions amid the adoption of agentic AI.<\/p>\n<p>The framework addresses the questions of, \u201cWhat agents do I have? Do I know what agents are actually running inside my company?\u201d said David Bradbury, chief security officer at San Francisco-based Okta.<\/p>\n<p>The next question addressed by the framework is, \u201cOnce I know that I have agents, what actually do they have access to?\u201d Bradbury told CRN. \u201cAnd then lastly, what can they actually do with that access? Those are the three big questions that we solve as a company.\u201d<\/p>\n<p>Ultimately, \u201cif you\u2019re not securing identity, you\u2019re not securing AI,\u201d he said.<\/p>\n<p>        Extending Identity Practices To Agents<\/p>\n<p>The bottom line is that with all of the existing fundamentals around securing human identities, \u201cwe have to continue to do them around agents,\u201d Optiv\u2019s Gregory said. \u201cThe same tool you\u2019re using around IAM should be able to handle agentic AI life-cycle management.\u201d<\/p>\n<p>If that\u2019s not the case, Gregory said that organizations should reconsider whether the identity platform they\u2019re using will enable them to combat growing AI risks.<\/p>\n<p>Because the reality is that \u201cthose AI risks of today are only going to become larger risks,\u201d he said.<\/p>\n","protected":false},"excerpt":{"rendered":"Identity is the crucial area to focus on when it comes to preventing cyber exposure through the use&hellip;\n","protected":false},"author":2,"featured_media":55289,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,24,405,399,25,8916,12722,313,31114,415,404,318],"class_list":["post-55288","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-ai","tag-ai-agents","tag-application-and-platform-security","tag-artificial-intelligence","tag-cloud-security","tag-cyberattacks","tag-cybersecurity","tag-latest-videos","tag-llm","tag-saas","tag-vulnerabilities"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/55288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=55288"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/55288\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/55289"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=55288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=55288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=55288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}