AI Agent Identity Is the New Attack Surface CISOs Aren’t Ready For

Share

When security teams think about identity management, they think about people: employees, contractors, privileged admins. That mental model is now dangerously incomplete. Forrester Research is drawing a sharp line in the sand for CISOs: AI agents are generating a new class of non-human identity that enterprises are systematically unprepared to govern, monitor, or defend.

The Non-Human Identity Problem

Agentic AI systems — software that autonomously plans, executes multi-step tasks, and interacts with external tools and APIs — don’t just consume compute. They acquire identities. An AI agent needs credentials to access databases, permissions to call APIs, tokens to authenticate against third-party services, and in many architectures, the ability to spawn sub-agents with their own access scopes. Each of those touchpoints represents an identity, and each identity is a potential attack vector.

The scale of the problem compounds quickly. A single enterprise deployment of an agentic workflow — say, an AI system that autonomously handles procurement, interfaces with an ERP, queries a data warehouse, and communicates via email — can generate dozens of non-human identities in a single orchestration chain. Multiply that across business units, and the non-human identity surface can dwarf the human one within months.

Traditional Identity and Access Management (IAM) frameworks were built for a slower-moving problem: provisioning and deprovisioning access for human users, enforcing least-privilege policies, and logging authentication events. They were not designed to handle the dynamic, ephemeral, and nested identity structures that agentic AI creates. Most enterprise IAM tooling lacks the visibility to even enumerate non-human identities at runtime, let alone apply coherent governance policies to them.

Why Agentic Systems Break Existing Controls

The architectural characteristics of modern AI agent frameworks make conventional security controls a poor fit in several specific ways.

  • Ephemeral credentials at scale: Agents frequently spawn, execute, and terminate within short windows. Static credential management — the kind most secrets management tools are optimized for — struggles to track credentials that exist for minutes or seconds.
  • Delegated trust chains: In multi-agent architectures, a root agent may delegate authority to sub-agents, which may delegate further. If the root agent’s identity is compromised or manipulated, that trust propagates downstream automatically. There is no human in the loop to catch lateral movement across agent boundaries.
  • Prompt injection as an identity attack: Adversaries can manipulate agent behavior by injecting malicious instructions into data the agent consumes — a web page it reads, a document it processes, an API response it receives. If successful, the attacker effectively hijacks the agent’s identity and its associated access rights without ever touching a credential directly. This is not a theoretical risk; prompt injection attacks against production agents have already been demonstrated in research settings.
  • Inadequate audit trails: Agents operating at high velocity across many systems generate action logs that existing SIEM and UEBA tools are not calibrated to interpret. Distinguishing anomalous agent behavior from expected behavior requires telemetry and baselines that most organizations haven’t built.

The IAM Gap Is Structural, Not Just a Gap in Tooling

The root issue isn’t simply that security vendors haven’t shipped agent-aware IAM products yet — though that’s true. The deeper problem is conceptual. IAM governance has historically been organized around the principle of attributing access to accountable humans. Non-human identities in agentic systems challenge that principle at the foundation. Who is accountable for what an autonomous agent does with the credentials it holds? The developer who built it? The business owner who deployed it? The AI model provider whose reasoning drives its actions?

This accountability ambiguity has direct regulatory implications for Canadian enterprises operating under PIPEDA and its provincial equivalents, as well as for any organization with exposure to the EU AI Act’s requirements around high-risk AI systems. When an agent with broad data access makes a consequential decision — or is manipulated into making one — the audit trail needs to answer questions that current architectures aren’t capturing.

What Security Teams Should Prioritize Now

Forrester’s analysis points toward a set of near-term actions that CISOs can take without waiting for the vendor ecosystem to fully mature.

  • Inventory non-human identities aggressively: Before governance is possible, visibility is required. Security teams should treat agent identity discovery as a first-order task, cataloguing every service account, API token, and OAuth credential associated with AI workloads — and establishing processes to keep that inventory current as deployments scale.
  • Apply least-privilege rigorously to agents: Agents should be provisioned with the minimum access required for their specific task scope, not the maximum access that makes development convenient. This is a cultural and process challenge as much as a technical one, requiring security to be involved in agent design, not just deployment review.
  • Treat prompt injection as a first-class threat: Input validation and output filtering for AI agents should be integrated into secure development standards. Agents that consume external data — from the web, from user inputs, from third-party APIs — should be considered potentially adversarial environments.
  • Build agent-specific monitoring baselines: UEBA and SIEM teams need to develop behavioral profiles for agentic workloads: what normal API call volumes look like, what constitutes anomalous data access, and how to flag unexpected delegation chains. This work needs to begin now, before the anomaly signal is buried in noise.
  • Push for accountability frameworks internally: Establish clear internal ownership for each agent deployment — a named human or team responsible for its behavior, access, and lifecycle. This is the organizational foundation that makes everything else enforceable.

A Window Before the Risk Compounds

Enterprise adoption of agentic AI is accelerating. Microsoft Copilot Studio, Google Agentspace, and a growing roster of third-party orchestration platforms are making it straightforward for business units to deploy agents without deep security review. The window to establish governance frameworks before non-human identities become unmanageable is real, but it is not indefinitely open.

Forrester’s message to CISOs is essentially: the perimeter has already expanded. The question is whether security programs will expand with it, or spend the next several years responding to incidents that were predictable from the architecture alone.

Source

Forrester: AI Agents Pose New Cybersecurity Risks for CISOs

Scott Holmes
Scott Holmes
Scott Holmes is the Founder and Editor of InsightTrack AI, a Canadian publication covering artificial intelligence news, governance, security, and infrastructure. Based in Ontario, Canada, he brings more than 20 years of technology experience, including at Ericsson Canada, and holds PMP, CCNA, ITIL v3 Foundations, and Six Sigma certifications. His areas of expertise include AI governance, telecommunications, critical infrastructure, cybersecurity, and automation.

Read more

Local News