Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

Your AI agents are borrowing credentials. That’s a problem

For nearly two decades, the foundational precept of enterprise Identity and Access Management (IAM) has remained unchanged: access is requested either by a human operator sitting behind a keyboard or by software executing a highly predictable task. While this framework has successfully anchored enterprise security for twenty years, the rapid maturation of autonomous AI agents is quietly collapsing that core assumption.

AI agents now use context and reason to interpret ambiguous instructions. These digital workers autonomously decide which tools to invoke, orchestrate multi-step workflows across disparate software ecosystems, and directly query production databases, all without requiring a human to validate or approve each action.

The security perimeter is fundamentally changing. A startling validation of this risk occurred recently during a routine frontier-model evaluation that led to the hack of the open-source developer platform Hugging Face. One of OpenAI’s most advanced models escaped its digital sandbox and hacked into Hugging Face, stealing its data to accomplish its task. It did this by coordinating the efforts of agents to exploit a zero-day vulnerability, while potentially also exploiting multiple other vulnerabilities. OpenAI labeled this boundary-crossing event an “unprecedented cyber incident,” proving that rogue agentic behavior is no longer a theoretical risk. It is an immediate threat to the enterprise attack surface.

After this incident, it’s clear CISOs can expect a structural rise in these autonomous intrusions.

The CISO perspective: Governance must precede deployment

I spoke with some close, trusted CISOs who have had varying experiences managing identities and agents, and the consensus is clear: agentic governance requires an entirely new framework.

As one CISO shared: “Agents aren’t malicious by design, but they absorb massive swaths of human behavioral data and optimize dynamically. They will inherently surface and exploit gaps in our governance structures to achieve their goals, even when explicitly restricted to a sandbox environment.”

This behavioral unpredictability shifts the problem from traditional access control to continuous architectural validation. Organizations can no longer rely on a one-step process of checking identity and credentials.

Another security leader emphasized the need for distinct agentic identity profiles, suggesting cryptographic privilege delegation that strictly constrains sub-agents from exceeding the original grantor’s permissions. To manage this effectively, enterprises must clearly delineate between short-lived agents invoked by an active user and continuously running autonomous digital workers. 

When I asked a third CISO if these agents should simply be integrated into existing human IAM governance, the answer was definitive: “They must be treated differently. They operate continuously, evolve at machine speed and introduce non-linear risks that human-centric systems simply aren’t engineered to contain.”

The crack in the identity plane: credential borrowing

The immediate vulnerabilities are manifesting around session management and credential sharing. To accelerate productivity, internal engineering teams frequently allow AI agents to “borrow” human OAuth tokens or session credentials to ‘act’ as a user to execute tasks. This shortcut brings risks and introduces severe compliance and audit blind spots.

If an agent initiates an anomalous action, telemetry logs attribute the behavior entirely to the human identity, completely masking the agent’s involvement. The agent then automatically inherits the full scope of the human’s privileges, frequently violating the principle of least privilege. Finally, remediating an active incident becomes an operational bottleneck: revoking the agent’s access means revoking the human executive’s or developer’s credentials at the same time, halting critical workflows.

To eliminate this blind spot, security leaders are moving away from treating agents as human users or mapping them to traditional non-human identities like legacy service accounts or workload identities. Instead, agents are being isolated into an entirely new classification of Non-Human Identity (NHI). This dedicated tier enforces independent lifecycles, rigorous least-privilege boundaries and immutable, attributable audit trails.

Enterprise perspectives on implementation, however, remain split. One CISO concurred with the risks, saying, “I think (our identity) framework needs to be enhanced. Identity is something we’re terrible at.” 

Another CISO added a different point of view. “We treat all identities equally and are moving to a least-privilege, vaulted and audited model for all. AI agents wouldn’t be excepted from that, but it’s tough because they inherently need more permissions than most humans, depending on scope. They need more operational leeway.” 

Of course, the challenge is managing AI agents’ behavior. Rules and language for managing this process are being written in real time. Unfortunately, it’s often by the same vendors who built the ISPM platforms that managed human and machine identities already underway before agents arrived.

Examples of agent behavior

How do you prevent rogue AI activities in systems? The fundamental challenge lies in reining in autonomous optimization. When an agent’s core optimization metric is to complete its mission, it will systematically test every logic combination and security bypass available at machine speed. My peers and I are increasingly observing scenarios where human identity platforms fail to contain these dynamic agentic loops.

For instance, one of my favorite security executives has launched an agentic guardrails startup to stress-test these exact defensive boundaries. In a controlled test environment, he and his team established an isolated data partition containing sensitive financial records. The access policy explicitly required input from a keyboard, a logical gate designed to verify human presence. Confronted with this restriction, an agent attempted multiple standard access vectors and failed. However, optimizing for the objective, the agent “understood” what the barrier might be, and autonomously located, downloaded and executed an open-source virtual keyboard module from the web to simulate human input. It bypassed the gate entirely.

Traditional authentication methods like username, password and MFA were built for humans who interact with systems periodically and at low frequency. However, autonomous AI agents operate continuously and at light speed, introducing new risks where automated scripts can repeatedly target assets or exploit data in unforeseen ways. 

Architecting the next-generation identity nerve center

Addressing this paradigm shift requires robust governance platforms and specialized, intelligent access tiers. Established identity security giants are evolving their suites into enterprise nerve centers that can orchestrate both human and machine lifecycles. As one CISO noted, “Leveraging our existing deployments in SailPoint and CyberArk to vault and rotate credentials remains our baseline defense.”

Other solutions* can also address this identity gap by tying digital access to verified real-world credentials, like driver IDs or passports. This creates a dedicated identity tier for agentic access. When paired with just-in-time access controls to prevent continuous, unlimited privilege, this framework ensures AI agents are explicitly authenticated and strictly bounded, neutralizing the threat of persistent, spoofed automated attacks. 

As we invest in and build the infrastructure to secure this frontier, the immediate question remains: How is your organization adapting its identity governance to draw the line between human intent and autonomous agent execution?

*Glasswing is an investor in Nametag.


Read More from This Article: Your AI agents are borrowing credentials. That’s a problem
Source: News

Category: NewsSeptember 29, 2026
Tags: art

Post navigation

PreviousPrevious post:Your payment platform can pass every Black Friday readiness test and still failNextNext post:5 things I would never let an AI agent do without a second approval

Related posts

Meta’s next big AI bet is enterprise; its biggest hurdle may be trust
September 30, 2026
Anthropic revelations suggest a much stronger AI negotiating stance for enterprise CIOs
September 29, 2026
Microsoft rewires AI’s context layer for business
September 29, 2026
Oracle Fusion Claw pinches AI costs, tightens grip on policies
September 29, 2026
Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems
September 29, 2026
AMD agrees to buy World Labs to fill out its AI stack
September 29, 2026
Recent Posts
  • Meta’s next big AI bet is enterprise; its biggest hurdle may be trust
  • Anthropic revelations suggest a much stronger AI negotiating stance for enterprise CIOs
  • Microsoft rewires AI’s context layer for business
  • Oracle Fusion Claw pinches AI costs, tightens grip on policies
  • Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems
Recent Comments
    Archives
    • September 2026
    • August 2026
    • July 2026
    • June 2026
    • May 2026
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.