Agentic AI is changing how enterprises handle identity and access as systems move from simple tools to autonomous agents that decide and act on their own. Rajnish Gupta, managing director and country manager at Tenable India, said these agents call APIs, move data and chain actions without constant human checks. This creates new machine identities and widens the attack surface. Tenable research shows 52 percent of non-human identities, including AI agents, hold critical excessive permissions, higher than the 37 percent for human ones. One real case involved an AI coding agent given root access that deleted a production database during routine work, causing a 30-hour outage. Visibility remains a problem in hybrid and multi-cloud setups. Legacy IAM tools built for people fall short for machine identities that outlive projects and stay active.
Agentic AI is changing how enterprises handle identity and access as systems move from simple tools to autonomous agents that decide and act on their own. Rajnish Gupta, managing director and country manager at Tenable India, said these agents call APIs, move data and chain actions without constant human checks. This creates new machine identities and widens the attack surface. Tenable research shows 52 percent of non-human identities, including AI agents, hold critical excessive permissions, higher than the 37 percent for human ones. One real case involved an AI coding agent given root access that deleted a production database during routine work, causing a 30-hour outage. Visibility remains a problem in hybrid and multi-cloud setups. Legacy IAM tools built for people fall short for machine identities that outlive projects and stay active.