The Replicant in Your Directory: AI Agents and the Identity Security Gap

In a growing concern for organizations worldwide, artificial intelligence (AI) agents are exposing a gaping hole in identity security. These non-human entities, which include service accounts, OAuth applications, and machine identities, already outnumber human users by as much as 50 to one in many enterprise environments.

The issue lies in the fact that identity security was built around human behavior – people join companies, change roles, take vacations, and eventually leave. However, AI agents don’t follow this pattern. They can be created automatically, inherit permissions from other identities, interact with systems at machine speed, and even create additional identities as they work.

According to the Non-Human Identity Management Group, most organizations still struggle to answer basic questions about who owns these AI agents, why they still exist, or what they can access. This lack of visibility creates an attack surface that grows quietly in the background, making it easier for threat actors to exploit trusted machine identities and gain access to sensitive data.

The problem is not unique to any particular organization or industry. In 2025, a threat actor tracked as UNC6395 obtained an OAuth token associated with Salesloft’s Drift chat integration and used it to move through Salesforce environments across hundreds of organizations. The token wasn’t exploited due to a software vulnerability; rather, it was already trusted because of its connection to the legitimate application.

AI agents don’t create this problem, but they do accelerate it by creating more identities, inheriting permissions, interacting across systems, and expanding the number of trusted credentials operating inside the environment. If security teams don’t know these identities exist or understand what they can access, the attack surface grows exponentially.

The root cause of the issue lies in the fact that human identity programs assume someone owns an account, reviews access periodically, and eventually removes it. AI agents don’t naturally fit this lifecycle, making it challenging for organizations to govern them effectively.

To mitigate this risk, organizations need to prioritize continuous visibility into their identity population. This means answering four essential questions: What identities exist? Who owns them? What can they access? When should they no longer exist?

Investing in governance practices and tools is crucial, but it’s not enough. As our 2026 Data and Identity Security Report found, organizations where AI significantly expanded the number of identities in their environment reported a 43% breach rate over the previous year, compared with 11% among organizations where AI hadn’t changed their identity footprint.

The surprising part was that these organizations generally had stronger governance practices than their peers. They were more likely to monitor shadow AI, govern non-human identities, and maintain continuous visibility into sensitive data. However, they still got breached.

In conclusion, the identity security gap exposed by AI agents requires immediate attention from security teams. By prioritizing continuous visibility and answering the essential questions about AI identities, organizations can reduce their risk of a breach.


Source: Bleeping Computer — 2026-07-10