In the AI era, identity evolves into the control plane for trust
SiliconANGLE Zeus Kerravala ● Covered by 8 sources
AI agents are multiplying fast, and most companies can’t even count them. That makes identity the control point, not just another security layer.
Based on reporting by SiliconANGLE, Zeus Kerravala — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
The big shift in AI security is not really about models. It’s about permission. As more work gets done by agents instead of people, the old username-and-password world starts to look quaint, and a lot less safe. The uncomfortable part is that many organizations still can’t say how many agents they have, what those agents can reach, or who is on the hook when something goes wrong.
The numbers in the source make the problem hard to shrug off. Palo Alto Networks’ 2026 Identity Security Landscape report says companies now manage an average of 109 machine identities for every human identity, and expect AI agent identities to rise 85% over the next 12 months. The same report says more than half of organizations can’t consistently enforce least-privilege access for service accounts across cloud, SaaS and on-premises systems. SailPoint’s own research is sharper still: 97% of AI agents have access to sensitive data, while only 21% of organizations are highly confident they can manage AI agent security risks.
That is already turning into real mess, not theoretical worry. On SailPoint’s latest earnings call, management said a proof-of-concept at a Fortune 500 company found more than 10,000 previously unknown AI agents plus thousands of related risks. And the problem is moving fast. Shadow IT took years to spread. Shadow agents are spreading in months. A ZK Research datapoint in the piece says almost half of AI use is on mobile devices, much of it invisible to IT.
Containment tools still matter. Sandboxes, secure runtimes, guardrails and hardware enforcement can all help. But they do not answer the basic governance questions: who created the agent, whose authority it is using, whether it should still exist, and how to shut it down quickly. That’s why the article argues identity has become the control plane for trust. Containment says what an agent cannot do. Identity says what it is, who owns it, what it can touch and when that access should end.
SailPoint is leaning into that idea with Agentic Fabric, launched in May and generally available in August as part of its Identity Security offering on the Atlas platform. The system is meant to discover AI agents and machine identities, map them to human owners and enforce authorization in real time. It also includes endpoint and browser sensors, Model Context Protocol servers, inline redaction for personal data and a centralized kill switch. The next test is whether customers can prove it works in production, because this part of AI security is no longer about theory. It’s about paperwork, ownership and the ability to pull the plug.
My take — AI-written commentary, not fact-checked reporting
This is one of those rare AI stories where the boring answer is the right one: identity beats vibes. Every vendor wants to sell a shiny wrapper around the agent problem, but if no one can name the owner or revoke access, the whole thing is just automated freelancing with better marketing. The industry keeps acting surprised that machines behave like machines; the real surprise is how often humans forget to put a leash on them.
Read more about this at: SiliconANGLE