For over a decade, enterprise cybersecurity was built on a straightforward setup: a human user sits behind a screen, authenticates and carries out tasks within a session.Traditional identity and access management (IAM) frameworks were designed around this single assumption. They validated credentials at login, established a trusted perimeter for the duration of the session, and monitored subsequent activity.But the emergence of the agentic enterprise is challenging that assumption.The issue facing modern internet security operations is no longer just whether an identity was verified during initial access. As autonomous software agents, coding assistants, and automated workflows are beginning to operate across cloud environments, code repositories, APIs and internal systems are dealing with a level of speed and autonomy that traditional controls were not designed to manage.The issue now is whether organizations can see, govern and control what happens after access is granted, especially when the actor is software making decisions in real time.Attackers increasingly exploit systems through the path of least resistance, rather than searching for complex technical vulnerabilities. This makes stolen or compromised login credentials a prime target, allowing attackers to look legitimate when gaining access without needing sophisticated attack methods.At the same time, shadow AI, short-lived credentials and machine-driven actions are expanding the attack surface. As enterprises continue to deploy AI tools faster than many security teams can secure them, visibility gaps and governance blind spots will persist.Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!Where traditional IAM failsOne of the biggest challenges to securing the agentic enterprise is that traditional identity controls are too static for machines which operate continuously. Legacy IAM and privileged access tools are effective at validating access at a point in time. But AI systems do not authenticate and stop. They make choices, invoke tools and change systems after the initial login has been triggered. This creates a need for identity controls which evaluate behavior in context as actions occur, not just at login.Poor visibility across agentic systems is another barrier. Many organizations still lack a clear inventory of which AI agents exist, what data they can access, who approved them and what actions they are taking on whose behalf. When agents are distributed across fragmented cloud and SaaS environments, those questions become harder to answer and security blind spots grow quickly.Finally, credential exposure presents a significant risk. In human-led systems, long-lived secrets, shared credentials and broad delegated access are already problematic. They become even riskier when handed to autonomous or semi-autonomous tools operating at machine speed. Security leaders need a model that reduces that exposure, improves attribution and preserves a clear chain of accountability back to a human owner or policy decision.Securing the human-AI workforceNavigating this new threat landscape means evolving enterprise security from a system designed primarily for human administrators into infrastructure that can support humans and artificial identities together. This is the broader shift behind IAM infrastructure for the agentic enterprise: making identity easier to operate programmatically, governing AI agents across their lifecycle and evaluating trust continuously as actions occur.One part of that shift is governance. Organizations need to identify AI agents, assign ownership, define boundaries and understand what those agents are allowed to do. Another necessary shift is runtime trust: ensuring access is evaluated in context and that risky behavior can be contained quickly without relying on static credentials or blind trust. The final part of this change is operability. As more work moves into APIs, terminals, orchestration layers and AI-assisted workflows, identity management systems need to be easier to use beyond the admin console.Organizations need to treat this as a key operational design matter, moving beyond asking only who logged in and start asking what is acting in the environment, what it is authorized to do and whether teams can intervene when risk changes.Securing identities at machine speedThe agentic enterprise is no longer theoretical. AI systems are already influencing operations and decision-making across the business.The challenge for cybersecurity leaders is not to restrict what these systems can do outright. It is to ensure they operate safely, accountably and within clear enterprise guardrails. As unglamorous as it may be, governance is going to be one of the most important factors in determining if a company succeeds or fails in the long run with its AI programmes.Organisations which can effectively operate and secure AI will be the ones that build identity, accountability and runtime control into the operating fabric of the enterprise from the start. Innovation must be made governable, without being stifled and the organizations that get this right will be better positioned to use AI with confidence.Make PC protection simple with the best antivirus software.This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
When identity isn’t human: securing the agentic enterprise
Full Article
Original Source
Read the full article at Techradar →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.