Govern the AI agent as the identity it is
Oct 6, 2026
AI agents are non-human identities. They hold credentials, carry permissions, and act on systems around the clock, usually with standing access nobody reviews. The Salesloft Drift breach reached more than 700 organizations through exactly that kind of over-scoped, non-expiring token, with no prompt injection involved. The controls already exist: inventory every agent, scope it to least privilege, expire its access, review it on a schedule, and detect when it's abused.
When a company hires a person, that person goes through a process. HR provisions an account, security scopes it to a role, the access gets reviewed on a schedule, and on the last day someone revokes it. Well, it should be that way, but reality looks different. The machine workforce now embedded across the enterprise never went through any of that, not even in theory. Service accounts, API keys, OAuth tokens, and the AI agents built on top of them were stood up to get something working, granted whatever access made the job easy, and then left running. According to Palo Alto Networks' 2026 Identity Security Landscape, a survey of 2,930 security decision-makers, machine identities outnumber human employees 109 to 1, and 79 of every 109 are AI agents.
Strip away the headline noise around AI attacking AI and what remains is an AI agent that is a non-human identity. It holds credentials, receives permissions, and takes actions on systems. That's a thing security teams already know how to govern.
The industry is responding to this the way it responds to anything with "AI" in the name: by proposing a new category. New tools, new teams, and new budget lines for "AI security" and "agentic security." The pressure on a CISO is to buy an AI security platform, and the reports feeding that pressure are pointed: the Cloud Security Alliance, in a 2024 survey of 818 practitioners, found that only 15% feel highly confident they could stop an attack involving these identities.
But let's relieve that pressure: you're further along than the panic implies. You already have a playbook for an identity that holds credentials, carries permissions, and acts on systems. You inventory it, scope it to least privilege, expire its standing access, review it, and detect when it is abused. The task is to extend that discipline to cover the machine workforce, the same way it already covers people.
For MITRE ATT&CK an AI-based attack is still an attack on identity
The Salesloft Drift incident is the entire case in a single event. Between Aug. 8 and Aug. 18, 2025, the intrusion cluster tracked as UNC6395 reached more than 700 organizations, among them Cloudflare, Palo Alto Networks, Zscaler, and Proofpoint, through the OAuth and refresh tokens issued to an AI chatbot integration. Google's Threat Intelligence Group and Mandiant found no Salesforce platform vulnerability behind it. There was no prompt injection and no model poisoning. In MITRE ATT&CK terms, it was Valid Accounts (T1078) and Application Access Token abuse (T1550.001): the same identity attack the industry has defended against for a decade, aimed this time at a non-human identity holding standing, over-scoped, non-expiring credentials.
An AI agent doesn't have to be jailbroken to breach you. It only has to keep the standing credentials you handed it. The most advanced technology in the building can fail in the most old-fashioned way there is.
Govern AI agents the way you govern privileged accounts
Start with the control most teams reach for. Multi-factor authentication protects a login, but a machine identity holding a refresh token never logs in again. It mints fresh access tokens continuously and quietly. MFA has no purchase on this class of attack. What governs a machine identity is expiry, scoping, and just-in-time issuance.
The exposure is standing privilege, and that is a governance property you can measure today. Netwrix's 2026 Data and Identity Security Report found that 76% of organizations don't fully govern or monitor non-human identities (NHI). Teleport's 2026 survey of 205 security leaders found that 70% grant AI systems higher access than a human would need for the same task, and JumpCloud's The Silent Rollback report put the share of organizations relying on static, unexpiring keys and tokens for their agents at 49%. These are the numbers of ungoverned identity at machine scale, and the governance gap is precisely what an attacker reaches for.
These identities also slip past the human playbook, because the playbook was written for humans. They run around the clock, so no window of abnormal hours ever stands out. Offboarding rarely comes either: the Cloud Security Alliance found that only 20% of organizations have a formal process to revoke credentials such as API keys. The remedy is the boring one: rotation, just-in-time access, periodic access reviews, and identity threat detection, applied to a population that was quietly exempted from all four.
Then there is the question a CISO already asks about any privileged human: what could this identity reach if its credential were in the wrong hands right now? That's a blast-radius question, and blast radius is a function of access. The discipline to answer it is already in the building, but it has never been turned toward the bots.
But there is more to watch out for
There are novel agent problems, and identity governance does not solve them. Prompt injection is real. So is the confused-deputy problem, where an agent with legitimate access is manipulated into misusing it, and so is the autonomous chaining of actions across systems. Those belong to a separate defensive layer, and anyone claiming that least privilege closes them is overselling. The narrower claim is the one that holds: the identity and access layer of agent risk (i.e., who the agent is, what it can reach, for how long, and whether that access is being abused) is a discipline the industry already runs elsewhere. Prompt-injection defense is the frontier worth investing in. The exposure walking through the door this year is duller than that. It's a standing credential that never expires, on an identity nobody reviews.
Your identity security portfolio must include and address agents
The agent lifecycle maps cleanly onto controls that already span the identity fabric. Governing and reviewing non-human identities alongside human ones is identity governance, the work of Netwrix Identity Manager. Stripping out their standing privilege and issuing scoped, just-in-time access is privileged access management, handled by Netwrix Privilege Secure. And when a valid identity is driven by the wrong hands, catching it in the act is identity threat detection and response, where Netwrix Threat Manager sits. A point vendor selling a standalone non-human-identity tool is building the very parallel program the market has been told it needs. The alternative is to run one identity discipline across humans and machines and let it cover the agents too.
The machine workforce is hired without onboarding and never offboarded. It holds more keys than the humans beside it and works around the clock, acting where no one is watching. Treat each agent as what it is, an identity with access, and the door that UNC6395 walked through at more than 700 organizations becomes one you can close with the controls already in your stack.
Share on
Learn More
About the author
Dirk Schrader
VP of Security Research
Dirk Schrader is a Resident CISO (EMEA) and VP of Security Research at Netwrix. A 25-year veteran in IT security with certifications as CISSP (ISC²) and CISM (ISACA), he works to advance cyber resilience as a modern approach to tackling cyber threats. Dirk has worked on cybersecurity projects around the globe, starting in technical and support roles at the beginning of his career and then moving into sales, marketing and product management positions at both large multinational corporations and small startups. He has published numerous articles about the need to address change and vulnerability management to achieve cyber resilience.
Learn more on this subject
Convergence of ITDR, PAM and IGA. Which of the three is standing there when the attack lands?
They did everything right on identity hygiene. They got breached 4x more often
Automating Entra ID tenant destruction with AI
Mythos and the cost of attacking
Endpoint management system breach: why privileged access management (PAM) is now critical