SailPoint's newly released Horizons of Identity Security report puts a name to a problem many of us in incident response have been watching develop for the past eighteen months: the velocity paradox. Enterprises are racing to deploy autonomous AI agents — systems that read email, query databases, call APIs, execute workflows, and in many cases act on behalf of human employees — while continuing to govern those identities with identity and access management (IAM) architectures designed for quarterly access reviews and human-speed provisioning tickets.
The report's core finding is stark: organizations are operating business processes at AI speed but securing them at human speed. The result is a rapidly expanding population of non-human identities (NHIs) — service accounts, API keys, OAuth tokens, service principals, and now agentic AI identities — that are provisioned in minutes, granted broad standing privileges, rarely reviewed, and almost never decommissioned on time.
This is not a theoretical concern. In our IR practice, the majority of cloud intrusions we investigate in 2025–2026 involve compromised or abused machine identities rather than human credentials. Attackers have figured out that the fastest path into an environment is no longer phishing an analyst — it's finding an over-privileged service principal with no owner, no rotation policy, and no behavioral baseline. The mass deployment of AI agents multiplies that attack surface by orders of magnitude.
Why AI Agents Are a Fundamentally Different Identity Class
Traditional service accounts were predictable. They ran a known workload, on a known schedule, from a known host, touching a known set of resources. Autonomous AI agents break every one of those assumptions:
- Dynamic scope of action. An agent tasked with "resolve this customer issue" may legitimately touch CRM data, email, billing systems, and knowledge bases in a single session — a scope that would be an instant red flag for a human user.
- Delegation chains. Agents increasingly spawn sub-agents and call other agents, creating nested delegation that legacy IAM tooling simply cannot model. Who is accountable when Agent A delegates to Agent B which acts on behalf of user C?
- Prompt-influenced behavior. An agent's effective permissions are the intersection of its granted privileges and whatever instructions it ingests — including malicious instructions delivered via prompt injection. Standing privileges that seem reasonable for a deterministic workload become dangerous when the workload's behavior can be hijacked by untrusted input.
- Velocity of provisioning. Business units spin up agents in hours. Legacy joiner-mover-leaver processes measured in days or weeks cannot keep pace, so teams bypass governance entirely — or grant broad access "temporarily" that becomes permanent.
SailPoint's report frames this as security being "decades behind" AI ambition, and from where we sit, that's accurate. Most organizations we assess still cannot answer three basic questions: How many non-human identities exist in your environment? Who owns each one? What can each one actually reach?
The Defensive Implications
From a defender's perspective, the velocity paradox creates four concrete exposure categories:
- Privilege accumulation without review. Agents granted broad API scopes at creation never have those scopes re-evaluated. Quarterly human access reviews don't scale to an identity population that can grow 10x in a quarter.
- Orphaned and shadow agents. Agents deployed by departed employees, deprecated projects, or unsanctioned business units persist with valid credentials. These are prime lateral-movement vehicles.
- Credential exposure at machine scale. Agents handle secrets programmatically — in environment variables, config files, prompt contexts, and logs. A single misconfigured agent can leak credentials to a telemetry pipeline or an LLM provider.
- Blind spots in detection. SOC behavioral analytics tuned for human users either ignore machine identities entirely or drown in false positives. An agent behaving anomalously — pulling unusual data volumes, calling novel API endpoints, operating at 3 a.m. — frequently triggers no alert at all.
Executive Takeaways
Because this story concerns an architectural and governance gap rather than a specific exploitable vulnerability, our recommendations are organizational. These are the controls we are implementing with clients right now to close the velocity gap:
1. Build a complete, continuously updated inventory of non-human identities. You cannot govern what you cannot see. Enumerate service accounts, service principals, API keys, OAuth grants, workload identities, and AI agent identities across cloud providers, SaaS platforms, and on-prem directories. Assign every one a named human owner and a business justification. Any identity without an owner is decommissioned or quarantined — no exceptions.
2. Eliminate standing privilege for AI agents. Move agent authorization to just-in-time, task-scoped access models. An agent should receive the minimum permissions required for a specific task, for the duration of that task, with automatic revocation on completion. Where your IdP supports it, use ephemeral credentials and short-lived tokens rather than static API keys. This single control neutralizes the majority of prompt-injection blast radius.
3. Deploy agent-aware behavioral detection in the SOC. Baseline normal behavior per agent identity: expected API call patterns, data volumes, resource touchpoints, and operating hours. Alert on deviations — novel endpoint access, data egress volume spikes, delegation to unknown identities, or activity inconsistent with the agent's stated function. Treat each agent as a first-class monitored entity in your SIEM, not an invisible service account.
4. Govern the delegation chain. Require explicit, auditable authorization for agent-to-agent delegation. Log every hop: which identity initiated an action, which agent acted, on whose behalf, and with what scope. If your current IAM stack cannot represent delegated authority, that is a procurement requirement for your next renewal cycle — not a nice-to-have.
5. Apply identity lifecycle automation at machine speed. Provisioning, review, and deprovisioning of NHIs must be automated and policy-driven, with review cadences measured in days (or continuously), not quarters. Integrate agent creation into your IGA platform so that no agent receives credentials outside a governed workflow. Shadow agent deployment should be a detectable policy violation.
6. Red-team your agents before attackers do. Include agentic AI systems in penetration testing and purple-team scope: prompt injection, privilege escalation via tool misuse, credential extraction from agent context, and abuse of delegated authority. Our offensive teams consistently find that agents will exceed their intended authority when instructed cleverly enough — better to learn that in an engagement than in an incident.
The Bottom Line
The velocity paradox is not a reason to slow AI adoption — it's a reason to modernize identity security to match it. The organizations that will avoid the next wave of agent-mediated breaches are the ones treating AI agents as privileged identities today: inventoried, owned, minimally privileged, behaviorally monitored, and automatically decommissioned. Every agent deployed without those controls is a pre-positioned insider threat waiting for the right prompt, the right token leak, or the right attacker to activate it.
The question SailPoint's report forces every CISO to answer is simple: is your identity program running at the speed of your AI ambitions — or at the speed of your last access review cycle?
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.