Skip to content

AI agents force enterprises to rebuild identity stacks

The collision between AI agents and enterprise identity systems is no longer theoretical. After years of incremental updates, companies are discovering that the tools built for human users and predictable applications can’t handle agents that mimic employees, operate autonomously, and escalate permissions without oversight. The problem isn’t just security—it’s that the entire approach to managing access was never designed for non-human actors that learn, adapt, and act faster than existing controls can keep up.

The immediate trigger is the shift from AI pilot projects to production deployments. SiliconANGLE reports that enterprises are now confronting "decades of stitched-together identity tools, integration costs and security gaps" they’ve been able to ignore until agents started moving data, invoking services, and making decisions at scale. The pressure isn’t just coming from security teams; business units want agents deployed immediately, and they’re willing to accept risk to meet deadlines. That tension is forcing a reckoning: either rebuild identity infrastructure from the ground up or accept that agents will operate in blind spots.

The market response has been swift, though still fragmented. Rig Security, an Israeli startup that emerged from stealth on 29 September, raised $12 million to monitor AI agents posing as users—a narrow but critical slice of the problem. ServiceNow is positioning itself as the "control tower" for enterprise agents, framing governance as a balance between risk and business value rather than a strict security question. Nvidia’s open-source Open Agent Safety Platform, released the same day, takes a different approach: providing tools to manage autonomous agents rather than trying to restrict them. Vanderbilt University’s extension of its existing identity platform to cover AI agents suggests that established vendors will eventually absorb this functionality, but not before startups carve out niches.

What’s missing is a consistent way to define agent access. Today’s solutions are either too narrow (Rig Security), too broad (ServiceNow), or too technical (Nvidia) to address the core issue: agents don’t fit into the permission models that underpin enterprise security. An agent might need temporary, elevated access to complete a task, then relinquish it—something traditional systems weren’t built to handle. Worse, agents can combine actions in ways that create unintended access escalation, a risk that static permissions can’t mitigate.

The open question is whether enterprises will treat this as a security problem or a business opportunity. ServiceNow’s framing suggests the latter: if agents can be governed like any other process, they become just another tool to optimize rather than a risk to contain. That’s a gamble, but it’s one that resonates with operators who see security as a cost rather than a priority. The alternative—rebuilding identity systems from scratch—is expensive, disruptive, and politically difficult, especially when the business is demanding speed.

What readers should watch is how quickly established identity vendors move to incorporate agent-specific controls. Their hesitation so far isn’t technical; it’s that agent access doesn’t map cleanly to their existing products. That leaves room for startups like Rig Security to define the category before the big players take over. The next six months will reveal whether agent governance becomes its own market or gets absorbed into broader enterprise AI platforms. Either way, the era of treating AI agents as just another user is over.

Sources: siliconangle.com

“The rush to deploy AI agents is exposing long-ignored cracks in enterprise identity infrastructure, creating a market for governance tools that didn’t exist a year ago.”
— StartupReader
ShareLinkedInXWhatsApp

Read the original reporting

The outlets below did the original reporting.

Related briefs

This brief was drafted automatically from the sources above and published under our editorial policy. Spotted an error? Tell us.