started · updated
AI Agents Become Unmanaged Identities, Raising Enterprise Security Risks
Enterprise security teams have traditionally protected risk by controlling identities such as employee accounts, service accounts and API keys. A new wave of AI agents is now being deployed across organizations to summarize meetings, draft emails, query data and even write and deploy code. These agents are increasingly connected to critical business services like Salesforce, Snowflake, GitHub, Jira and production databases.
Because most security programs treat AI agents as ordinary productivity tools, they lack dedicated governance models. According to a 2026 Token Security survey, 82 % of organizations discovered at least one AI agent that had been created without the knowledge of security, IT or governance teams in the past year, and 41 % experienced multiple such incidents. The agents can act autonomously, assume the identities of human users, create, use and renew credentials at machine speed, and operate across multiple systems with privileged access. Misconfiguration, compromised sessions or malicious plugins could turn these agents into pathways for data exfiltration, destructive actions or lateral movement inside corporate networks.