Back Issues This Week → Current Issue → Popular →

All issuesVolume 337, Issue 1IT NewsAI

How Treating AI Agents As Identities Can Reduce Enterprise AI Risk

Security Boulevard, Thursday, April 2nd, 2026

AI agents are no longer experimental. They're running production workloads, calling APIs, querying databases, provisioning infrastructure, and making decisions across cloud environments. Ironically these agents often end up with more access than the developers who built them. They operate with real credentials, real permissions, and real consequences when something goes wrong.

What most enterprise security teams haven't caught up to yet is that this is fundamentally an identity problem. AI agents function as non-human identities inside cloud IAM models. They carry IAM roles, service accounts, and API keys just like any other machine identity and they inherit every weakness in how those identities are currently managed: excess permissions (92% of cloud identities are overprivileged), no ownership, and governance processes that were never built to scale.

more →  ·  More from AI →