Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    I’ve Waited 8 Years for Overwatch’s D.Mon. Her Gameplay Didn’t Disappoint

    August 7, 2026

    Our Favorite Fans Are on Sale to Help With Summer Heat Waves (2026)

    August 7, 2026

    What Chocolate Finance got right about S’pore’s changing savings habits

    August 7, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»The Hidden Security Problem Holding Enterprise AI Back
    Cybersecurity

    The Hidden Security Problem Holding Enterprise AI Back

    InfoForTechBy InfoForTechJuly 30, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    The Hidden Security Problem Holding Enterprise AI Back
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    When an AI agent completes a task inside your enterprise systems, can you say with certainty which agent did it, on whose authority, and under what constraint? For most organizations, the honest answer is no. I’ve sat through enough incident reviews to know exactly what that uncertainty costs once something goes wrong.

    That gap just became measurable.

    The Okta Enterprise AI Index, drawn from anonymized sign-on data across more than 20,000 organizations between June 2022 and June 2026, found that AI-native vendors such as Anthropic, OpenAI, and Cursor quadrupled their enterprise customer base over that period, with Anthropic overtaking OpenAI in enterprise accounts in March 2026 and in monthly active users a month later.

    Behind that growth curve sits a pattern that gets far less attention: enterprises are still authorizing AI agent workflows with service accounts, static API keys, and, in some cases, the login credentials of actual employees.

    “When an AI agent inherits a human’s login, you completely lose your audit trail,” Okta’s Fei Liu said of the findings. That line should stop every CISO mid-scroll. It describes the default state of AI deployment at most companies today, not an edge case.

    The Okta data explains a number that would otherwise look alarming. VentureBeat’s Q3 2026 trends survey of 800 IT leaders across the US and UK found that the share of organizations describing their AI deployment as “mature” fell from 40% to 23% in six months. That looks like a confidence collapse until you dig into what the survey actually measured. Then it reads as the opposite: leaders finally grading their AI programs on whether anyone can govern them, instead of on how fast they got adopted.

    Non-human identity governance is the least mature control the survey measured, in place at just 21% of organizations, even though non-human identities already outnumber human users at 83% of the companies surveyed. That is not a rounding error. At four out of five enterprises, the identity type with the largest population inside core systems is also the one least likely to have any dedicated access controls or lifecycle management applied to it.

    The gap is costing those enterprises more than clean audit logs. The same survey found that top-tier organizations, the ones that had built non-human identity governance, were five times more likely to report no barriers to expanding their AI agent deployments. That cuts against the common assumption that governance slows AI programs down. The data says the opposite: it’s the missing governance that creates the drag.

    The instinct inside most IT organizations has been to treat AI agent identity as a variant of existing identity and access management: provision a service account, rotate an API key, apply the same role-based policy used for a human employee, and move on. That instinct is the mistake.

    A human logs in once and then acts within a session a person can explain if asked. An AI agent authenticates constantly, often invoking dozens or hundreds of downstream actions per task, chaining calls across multiple systems and sometimes multiple models. When that agent operates under a shared service account, or worse, a borrowed human credential, every one of those actions collapses into a single anonymous line in the log. Nobody can distinguish the agent’s action from the human’s, or one agent’s action from another’s operating under the same account.

    Static credentials compound the problem. An API key issued to an AI workflow typically carries far broader permissions than any single task requires, and it persists long after the task is done, sitting in configuration files, prompts, or agent memory where it can be extracted or reused for something the original approval never covered. Broad, standing access is the design pattern identity teams spent the last decade trying to eliminate from human accounts. Enterprises are reintroducing it now for agents, mostly without noticing.

    Fixing this starts with giving every AI agent its own governed identity, separate from any human’s and from generic shared accounts, with permissions evaluated at the moment of each request rather than granted once and forgotten. Access decisions need to happen per action, based on which agent is asking, what data is involved, and what task is being performed, extending the same attribute- and role-based discipline enterprises already apply to human access to the agents now working alongside them.

    Credentials themselves need to move out of the agent’s reach entirely. A model or agent should never hold or pass along the raw credential used to authorize its actions. Authorization should happen at the point where the agent requests data or takes an action, not sit embedded in the agent’s context, where a prompt injection or a misconfigured tool call can expose it.

    This is the architecture that a new class of data governance platforms is building toward, Kiteworks among them: per-request, scoped enforcement that keeps credentials out of the model’s context and produces a clean, attributable record of exactly which identity, human or agent, did what, under whose authority, at what moment. It’s a governance layer built for humans and agents together, not a separate track bolted on for machines.

    Done well, this does not slow agents down. It’s what let the survey’s top-tier organizations report they were five times more likely to face no barriers to scaling. Confident AI expansion and rigorous non-human identity governance turn out not to be competing priorities. The data says they’re the same priority.

    The Okta and VentureBeat findings, read together, describe an industry that scaled its AI workforce faster than it built the identity infrastructure to govern it. The 17-point drop in confidence isn’t the industry losing faith in AI. It’s the industry finally checking the audit trail, and not liking what it finds.

    You might also like: Microsoft is retiring its standalone Threat Intelligence experience on Aug. 1. Learn what the change means for security teams and how to prepare before the transition to Microsoft Defender.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

    August 7, 2026

    ChatGPT Atlas Shuts Down Aug. 9: What Users Must Save Before Migrating

    August 7, 2026

    CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

    August 6, 2026

    Apple briefly removes Telegram from App Store over reported CSAM violation

    August 6, 2026

    Detect East-West Traffic Threats with Fidelis Network

    August 5, 2026

    Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

    August 5, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.