Securing AI Agents: Why Managing Non-Human Identities Is the Ultimate Cyber Challenge

A study reveals that 91% of organizations use AI agents, yet only 10% manage them securely. Experts urge adopting First-Class Identities to enforce human ownership, least-privilege tokens, and kill switches.

GeektimeAuthor: Guest Author
Source
Securing AI Agents: Why Managing Non-Human Identities Is the Ultimate Cyber Challenge
Photo: Geektime / בגישת First-Class Identities, כל סוכן משויך לבעלים אנושיים שלוקח עליו אחריות (צילום: Dreamstime)

The integration of AI agents into workflows has become nearly standard: they make decisions, access sensitive data, and execute actions rapidly—often without direct human involvement or even below the security team's radar. Assuming the old Identity model is no longer relevant, the critical question is: who manages them?

A study by Okta reveals that already in 2024, 91% of organizations used AI agents, yet only 10% reported having a cohesive strategy for managing non-human identities. Furthermore, 58% of managers pointed to governance as their primary security concern, and 88% reported security incidents or suspected incidents related to agents. This gap between rapid adoption and a lack of true control represents one of today's most significant risks.

The Solution: First-Class Identities Approach

To solve the agent management problem, Okta has formulated a framework treating them as First-Class Identities—exactly like human employees. Each agent has a clear ownership assigned, along with a full lifecycle, permissions, monitoring, and a one-click kill switch. This approach enables organizations to apply dynamic access control, real-time monitoring, and Zero Trust enforcement.

Implementing this framework requires a clear action plan based on three core questions:

1. Where Are My Agents?

Most organizations cannot genuinely answer this question. Alongside known agents, Shadow AI exists—agents created independently by employees in browsers or external platforms without IT's knowledge. An organization cannot manage what it cannot see, and most are unable to even count their agents.

Various monitoring tools on the market enable continuous discovery of both known agents and Shadow AI. One such tool is Okta for AI Agents, where every agent registers in the Universal Directory as a First-Class Identity with clear human ownership and a single source of truth. This provides complete visibility into who the agent is, who owns it, where it runs, and its risk level.

«Using this tool, a financial institution discovered dozens of agents created independently by the marketing department to analyze customer data. Nobody knew they existed, and they were connected to CRM systems with broad permissions.»

2. Where Can My Agents Connect?

Agents connect to MCP Servers, SaaS applications, APIs, databases, and other agents. The problem is that many run with rigid credentials—long-lived API keys—and overly broad permissions. Once an agent is compromised or goes rogue, the potential damage is massive.

The solution is to replace rigid credentials with short-lived, least-privilege tokens and enforce clear policies: which systems the agent is authorized to access, under what conditions, and for how long. Every connection passes through the identity layer.

3. What Can My Agents Do?

This is where runtime enforcement, access certifications, full auditing, and a kill switch come into play. The question is not only what an agent connects to, but what it actually does in real-time—and whether it can be stopped immediately if it violates policy.

The solution is to apply the same governance processes used for employees: periodic access reviews, real-time monitoring, and a kill switch to immediately disconnect an agent and prevent it from acquiring new tokens. Every action is logged in a full audit trail.

«Imagine a scenario where a coding agent starts deleting files in the production environment. The security team identifies abnormal behavior, hits the kill switch, and the agent is immediately disconnected from all systems before irreversible damage occurs.»

The Guiding Principle: Every Agent Must Have an Owner

Under the First-Class Identities approach, every agent is assigned a human owner who takes responsibility throughout its lifecycle. For instance, a customer service agent connected to a CRM system has a clear owner responsible for reviewing permissions, approving changes, and ensuring adherence to policy. If the agent behaves anomalously, there is an accountable human who can shut it down instantly.

Recent events highlight how critical this is. In April 2026, an AI coding agent at a technology company received a routine task and within seconds accidentally wiped the production database and its backups. No external cyberattack took place; it was governance failure, forcing the company to rebuild systems from scratch. Other reported incidents underscore why clear ownership and a kill switch are paramount.

Fear of Laydowns and Hope in Human Identity

It is difficult to discuss AI agents without mentioning tech sector layoffs. Data published in 2026 shows tens of thousands of technology workers losing their jobs, with companies frequently citing AI as a primary factor. Nevertheless, research from the World Economic Forum, McKinsey, and Gartner indicates that while AI models transform roles and automate tasks, they simultaneously create new positions requiring irreplaceable human skills: judgment, accountability, ethics, business acumen, and decision-making in complex environments.

Ultimately, while agents execute tasks at scale, they still require a human identity to oversee, approve, take responsibility, and know when to pull the plug. Identity remains the ultimate defense layer.

Related News