TLDRocket
Sign in

What happens when your VPN meets 200 AI agents

The New Stack Alex Wilhelm

Tailscale's pitching a webinar on managing network access when AI agents flood your systems alongside human staff. Traditional VPN and PAM tools weren't built for hundreds of non-human identities making requests.

Based on reporting by The New Stack, Alex Wilhelm — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Your company's VPN was built with one assumption baked in: a human sits on the other end, typing a password, maybe approving an MFA prompt. That assumption is breaking down fast. Enterprises are spinning up AI agents by the dozens, sometimes hundreds, each one needing to touch databases, APIs, and internal tools to do its job. And unlike a contractor who logs off at 5pm, these agents might spin up, do a task, and vanish within minutes as part of a CI/CD pipeline.

The problem isn't just volume, it's the whole model of access control. Zero-trust network access and privileged access management tools were designed around verifying identity upfront and then granting a chunk of access. That works reasonably well for people. It falls apart for agents, which need access scoped tightly to a specific task, revoked the moment that task ends, and logged in a way that satisfies an auditor asking why a bot touched production data at 3am. Checking who someone is isn't the same as checking what they should be allowed to do right now, for this one job.

Tailscale is framing this as an architecture problem, not just a tooling gap. Running separate systems for human access and machine access creates exactly the kind of sprawl that security teams already hate: inconsistent policies, blind spots, and IT teams playing whack-a-mole with exceptions. Their pitch, delivered via a July 28 webinar with Solutions Engineer Kartik Bharath and Product Manager XingLu Wang, is that companies need one policy layer that treats a developer, a contractor, a CI pipeline, and an AI agent as variations on the same access request, not four separate problems.

Whether Tailscale's specific answer holds up is beside the point here. The underlying diagnosis is one every security team building agentic workflows is going to run into eventually. Static, identity-based access made sense in a world where the entity requesting access was a person with a badge. It makes much less sense when the requester might be an ephemeral process that exists for ninety seconds and then is gone.

My take — AI-written commentary, not fact-checked reporting

I'll say what the source article won't: this is a vendor webinar dressed up as an industry trend piece, and the framing conveniently matches whatever Tailscale sells. That doesn't make the underlying problem fake, though — enterprises genuinely are bolting agents onto access systems designed in 2015, and the audit-trail nightmare that creates is real. Just don't confuse a webinar registration page with independent research.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.