{"id":81387,"date":"2026-06-22T07:08:11","date_gmt":"2026-06-22T07:08:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/81387\/"},"modified":"2026-06-22T07:08:11","modified_gmt":"2026-06-22T07:08:11","slug":"ai-agents-become-first-class-identities-identity-management-must-adapt","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/81387\/","title":{"rendered":"AI agents become \u2018first-class identities\u2019 \u2013 identity management must adapt"},"content":{"rendered":"<p><img decoding=\"async\" width=\"816\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/06\/0IrwpmMmfpyYjtU_JYodbJ3l8Jqt-T8YCM6hNh5ei95GHlZAu8cOtas-QTScVS-L_77MzNHqK0FsR5nqAtACM7-P98MuorsRsf9Q.jpeg\" alt=\"Neil van Wyngaard, Solutions Architect, According to iOCO Automation &amp; Cybersecurity Cluster.\" fetchpriority=\"high\" loading=\"eager\" style=\"max-width:100%;object-fit:fill;\"\/><\/p>\n<p>Neil van Wyngaard, Solutions Architect, According to iOCO Automation &amp; Cybersecurity Cluster. <\/p>\n<p>According to iOCO Automation &amp; Cybersecurity, AI agents are fast being deployed across organisations and within business units, often with unchecked access to sensitive systems and data. Businesses need to move quickly to enforce new identity strategies to mitigate the new risks this presents.<\/p>\n<p>Neil van Wyngaard, Solutions Architect at iOCO Automation &amp; Cybersecurity Cluster, says: \u201cAI agents are now approving transactions, accessing systems, triggering workflows and making decisions autonomously. But uncontrolled AI agents are becoming one of the largest security gaps in modern enterprises. AI agents don\u2019t behave like humans \u2013 they operate autonomously across multiple systems, scale instantly, spawn additional agents and act continuously \u2013 not just at login. Most security models were built for humans: they authenticate users, assign permissions and log actions, but they weren\u2019t designed to govern AI agents.\u201d<\/p>\n<p>Van Wyngaard notes organisations are very strict about what their staff can access, and even more strict about what external vendors can and cannot do on the network. \u201cBut currently, many AI agents have no controls,\u201d he adds. <\/p>\n<p>\u201cThere are no real regulations or standards in the industry for building or deploying AI agents: you can download them or write your own. So people build and deploy them, give them elevated permissions and they could just run amok and access data they shouldn&#8217;t be accessing, doing things that they shouldn&#8217;t be doing. And central IT departments have no way of controlling what AI agents are being deployed on various platforms, or what they&#8217;re doing.\u201d<\/p>\n<p>iOCO notes that because AI agents are making decisions that have financial, regulatory and reputational impact, it is crucial they are properly secured and governed. Van Wyngaard says: \u201cWithout proper governance, organisations cannot confidently scale AI, prove compliance, mitigate risk or contain incidents quickly.\u201d<\/p>\n<p>He warns that AI agents are now \u2018first-class identities\u2019 and must be treated as non-human identities (NHIs) with clear ownership, permissions and life cycle controls. \u201cThey should also be monitored and audited constantly, and companies should have the power to revoke their permissions instantly, if necessary. Identity is now the control plane for AI,\u201d he emphasises.<\/p>\n<p>Van Wyngaard says <a href=\"https:\/\/www.okta.com\/\" target=\"_blank\" rel=\"sponsored nofollow noopener\">Okta<\/a>, an identity and access management (IAM) service, has moved to address AI agent risks through its AI IAM and governance platform. iOCO is an Okta reseller in South Africa. <a href=\"https:\/\/www.okta.com\/newsroom\/articles\/ai-at-work-2025--securing-the-ai-powered-workforce\/\" target=\"_blank\" rel=\"sponsored nofollow noopener\">Okta reports <\/a>that 91% of organisations are already using AI agents, 80% have experienced unintended agent behaviour and 23% report credential exposure via agents. Despite the risks, 44% have no governance in place.<\/p>\n<p>Okta for AI Agents is one of the first IAM platforms to directly address AI agent IAM. It enables organisations to manage agent identity and access on a single platform, with features such as ownership assignment, life cycle management and the ability to deactivate rogue agents. The platform\u2019s AI Agent Discovery feature allows companies to detect and identify agents across the environment, while the AI Agent Registry allows for agents to be registered as identities with a clear human owner and baseline governance policies. Okta for AI Agents also has system logs and telemetry to support compliance and stream to a SIEM for rapid incident response.<\/p>\n<p>Van Wyngaard says: \u201ciOCO has a number of customers already running the Okta platform \u2013 for them, Okta for AI Agents is an add-on IAM security tool. Okta scales very well in large organisations and proves more cost-effective than other solutions. With Okta for AI Agents, businesses can now enforce the same controls over AI agents as they do their staff and partners. Okta for AI Agents facilitates the discovery of AI agents within their environments, detects when they\u2019re accessing data or making connections they shouldn\u2019t, and shuts them down quickly.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Neil van Wyngaard, Solutions Architect, According to iOCO Automation &amp; Cybersecurity Cluster. According to iOCO Automation &amp; Cybersecurity,&hellip;\n","protected":false},"author":2,"featured_media":81388,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[25612,44398,405,7537,44395,13475,14674,44394,44393,44397,23259,44396],"class_list":["post-81387","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agent-discovery","tag-ai-agent-registry","tag-ai-agents","tag-artificial-intelligence-agents","tag-first-class-identities","tag-iam","tag-identity-management","tag-ioco-automation-cybersecurity-cluster","tag-neil-van-wyngaard","tag-nhis","tag-non-human-identities","tag-okta-for-ai-agents"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/81387","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=81387"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/81387\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/81388"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=81387"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=81387"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=81387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}