{"id":89210,"date":"2026-06-29T09:07:16","date_gmt":"2026-06-29T09:07:16","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/89210\/"},"modified":"2026-06-29T09:07:16","modified_gmt":"2026-06-29T09:07:16","slug":"identity-infrastructure-fails-to-secure-ai-agents","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/89210\/","title":{"rendered":"Identity Infrastructure Fails to Secure AI Agents"},"content":{"rendered":"<p class=\"mt-6 first:mt-0\">For data teams and security engineers building agentic systems, the central operational challenge is replacing human-centric authentication and authorization with machine-native identity and continuous control. As AI agents gain the ability to transact autonomously, existing identity infrastructure was not designed to verify, authorize, or audit them at scale.<\/p>\n<p>Scale of the shift<\/p>\n<p class=\"\">According to Johnny Ayers (CEO, Socure), writing in PYMNTS on June 29, 2026, by Black Friday 2025 AI-driven traffic to US retail sites rose 805% year over year, with agents driving over $22 billion in global online sales (citing Adobe data). The global AI agents market, valued at $5.4 billion in 2024, is projected to reach $236 billion by 2034 (Grand View Research, per the article). Ayers also notes via WEF (January 2026) that bots now generate almost 50% of all internet traffic, with bad bots comprising nearly a third (Imperva data) &#8211; making human-verification-only frameworks structurally inadequate.<\/p>\n<p>The KYA framework<\/p>\n<p class=\"\">The article frames a Know Your Agent (KYA) framework, modeled on historical Know Your Customer (KYC) practices. Per Ayers, KYA requires four capabilities:<\/p>\n<p>\u2022Establishing who and what the agent is\u2022Confirming the agent&#8217;s permitted actions and limits\u2022Maintaining accountability for every action taken\u2022Continuously monitoring behavior against approved parameters<\/p>\n<p class=\"mt-5\">Ayers emphasizes that KYA must sit on top of robust KYC: &#8220;Agent identity is only as trustworthy as the underlying human or organizational identity it represents.&#8221;<\/p>\n<p>Engineering implications<\/p>\n<p class=\"\">Implementing KYA at scale touches identity-proofing, delegated-authorization standards (OAuth 2.0\/2.1, DPoP-like patterns, OIDC), machine attestation, cryptographic key management, and high-frequency telemetry for anomaly detection. NIST&#8217;s National Cybersecurity Center of Excellence published a concept paper in February 2026 identifying MCP, OAuth 2.0\/2.1, OIDC, SPIFFE\/SPIRE, and SCIM as candidate standards for agent identity. For practitioners, these map to: machine-identity lifecycle, policy-expressed authorization, tamper-evident logging, and real-time policy enforcement.<\/p>\n<p>Risk framing<\/p>\n<p class=\"\">Gartner projects that 1 in 4 enterprise breaches by 2028 could stem from AI-agent exploitation (per Ayers\/WEF). Without interoperable identity and authorization primitives, each agentic integration creates bespoke trust gaps that are difficult to audit or remediate at scale.<\/p>\n<p>What to watch<\/p>\n<p class=\"\">Track whether standards bodies (NIST, IETF), major identity providers (Okta, Ping), or cloud vendors publish interoperable machine-identity and delegation primitives. Okta&#8217;s &#8220;AI Agents at Work 2026&#8221; report and IANS Research coverage indicate the gap between enterprise agentic ambitions and actual IAM maturity is widening. Absent standardization, bespoke solutions will increase integration friction and detection blind spots.<\/p>\n","protected":false},"excerpt":{"rendered":"For data teams and security engineers building agentic systems, the central operational challenge is replacing human-centric authentication and&hellip;\n","protected":false},"author":2,"featured_media":89166,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[25476,4077,405,7537,35017,2162,570,314],"class_list":["post-89210","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agent-economy","tag-agents","tag-ai-agents","tag-artificial-intelligence-agents","tag-authorization","tag-fraud-prevention","tag-identity","tag-security"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/89210","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=89210"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/89210\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/89166"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=89210"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=89210"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=89210"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}