In a recent discussion with several IT directors, one word kept coming up: democratization. The idea was to put AI agents in the hands of employees, connect them to business processes, and allow each team to create its own assistants.
A few days later, the topic resurfaced in a meeting with information security leaders. Enthusiasm had given way to more concrete questions: who can use these agents, with what permissions, and how to ensure accountability and traceability of their actions?
A single question then arose: should we manage AI agents as human users, or are we facing a new category of identities that requires rethinking our governance models? This question is becoming urgent.
Gartner estimates that up to 40% of enterprise applications could integrate specialized agents by the end of 2026, up from less than 5% in 2025. The movement is therefore no longer limited to a few experiments. Agents are beginning to seep into business, financial, legal, and operational processes.
An identity unlike any other
An agent can act on behalf of a colleague, access multiple systems, and delegate actions to other agents. Giving it the same rights may be suitable for a short task, but becomes risky if its mission lasts longer. It must therefore be treated as a workload identity: temporary, limited, and ephemeral.
But unlike a traditional identity, the AI agent can adapt its behavior and broaden its scope depending on instructions, the tools, or modules used. The agent is thus not merely an identity to authenticate; it is an identity capable of acting autonomously.
The problem is no longer just access, but authority
When an agent accesses a client file, it must be determined what it can actually do with it: analyze it, transmit it, modify it, trigger a procedure, or commit the company to action.
Having technical access does not mean you are authorized to make all related decisions. This is the blind spot of many current programs: they know who can enter, but not as clearly what that identity may decide. The risk grows when agents pass tasks along. At each level, permissions can be transferred and create a broader access chain than anticipated.
Non-human identities are also hard to control. Unlike a person, an agent has neither a clearly identifiable role nor a direct interlocutor. In the event of an incident, teams must reconstruct its intent, its accesses, and the decisions it could have taken.
Governance at the speed of machines
Authentication and the principle of least privilege are not enough to guarantee that an agent’s actions remain aligned with its mission. Governance must therefore monitor its behavior in real time, blocking risky accesses, tightening sensitive validations, and removing unjustified permissions.
This evolution also takes place in a European regulatory context marked by NIS2 and the AI Act, which strengthen risk management, security, and oversight requirements for AI systems. The identity of agents thus extends beyond the traditional IAM perimeter.
The first measures to take
Businesses must harden their directories, inventory their non-human identities, and apply the principle of least privilege. Each agent should have a responsible owner, a defined purpose, and time-limited rights.
Multifactor authentication (MFA) designed to resist phishing attacks should protect accounts, tokens, sessions, and delegations. It is also necessary to anticipate the compromise of an identifier through segmentation, ephemeral access, and continuous monitoring.
These measures are not unique to AI agents. They reflect the same governance principles that should apply to all of the company’s digital identities. But with agents, it is no longer possible to postpone them.
*Michael Adams is Chief Information Security Officer at DocuSign