AI Agents Are Flooding Enterprise Networks With Unmanaged Machine Identities, and Security Teams Are Not Ready

Agentic AI systems are creating machine identity sprawl at a scale that dwarfs previous waves of digital transformation.

AI Agents Are Flooding Enterprise Networks With Unmanaged Machine Identities, and Security Teams Are Not Ready

A new wave of autonomous AI systems is poised to overwhelm enterprise security frameworks by generating machine identities at a scale that existing governance tools were never designed to handle, according to Calcalist Tech. The report warns that agentic AI — software capable of executing multi-step tasks independently, spinning up sub-agents, and accessing external systems without continuous human prompting — is replicating the identity sprawl problem that plagued cloud adoption, but at potentially a hundredfold the magnitude. For security teams already struggling to track non-human identities across hybrid environments, the timing is acute. The challenge sits at the intersection of digital hygiene failures and accelerating automation, a combination that has repeatedly proven dangerous in sensitive operational contexts.

a data center server room with dense rows of illuminated rack-mounted servers and blinking network hardware, viewed from a wide aisle angle

From Cloud Sprawl to Agent Sprawl

The identity sprawl problem is not new. When enterprises migrated workloads to the cloud through the 2010s, service accounts, API keys, and machine credentials proliferated faster than security teams could catalog them. Orphaned credentials became a primary attack vector, enabling lateral movement and privilege escalation in numerous high-profile breaches. What Calcalist Tech describes is a structural repeat of that pattern, compressed in time and expanded in scope.

Agentic AI systems differ from prior automation because each agent — and each sub-agent it spins up to complete a delegated task — typically requires its own access credentials, OAuth tokens, or API permissions to interact with downstream tools and data sources. A single enterprise deployment of an agentic workflow could generate dozens of machine identities in a single session, most of them short-lived, many of them provisioned with broader permissions than the task strictly requires. Security researchers cited in the Calcalist Tech piece note that organizations frequently have no centralized register of these identities and no automated mechanism to revoke them once the task concludes.

Why Governance Frameworks Are Behind the Curve

Identity and access management platforms built for human users and static service accounts operate on the assumption that identities are persistent, enumerable, and tied to known roles. Agentic AI breaks all three assumptions. Agents can be ephemeral by design, created and destroyed within a workflow with no corresponding update to an identity directory. Their role is situational rather than fixed, shifting as the task evolves. And their number scales with usage rather than headcount, meaning a governance program sized for a workforce of ten thousand may suddenly face an identity estate an order of magnitude larger once agentic tools are deployed broadly.

The operational security implications extend beyond the enterprise. Defense contractors, intelligence community integrators, and critical infrastructure operators are among the sectors moving aggressively to adopt agentic AI for logistics, analysis, and decision support. If machine identities generated by these systems are not governed rigorously — inventoried, scoped with least-privilege permissions, and revoked on task completion — adversaries gain a substantially expanded attack surface. A compromised agent credential inside a defense-adjacent network carries the same lateral movement risk as any orphaned service account, but the sheer volume of such credentials could make detection and response far more difficult.

a cybersecurity operations center with multiple analyst workstations displaying network topology maps and identity access dashboards on large wall-mounted screens

Industry Response and the Path Forward

Security vendors and standards bodies are beginning to respond, though the Calcalist Tech report makes clear that the tooling is not yet commensurate with the threat. Proposals for agent-specific identity protocols, short-lived credential issuance tied to task scope, and automated de-provisioning pipelines are circulating, but none has achieved the kind of broad adoption that would meaningfully constrain the sprawl problem ahead of mass agentic deployment.

The Israeli cybersecurity sector, which has produced several companies focused specifically on non-human identity management, is one area of concentrated activity. Demand signals from enterprise buyers suggest that identity security for machine agents could become one of the defining market categories of the next procurement cycle. Whether those solutions mature quickly enough to stay ahead of deployment timelines — particularly in government and defense contexts where the consequences of credential compromise are most severe — remains the open question. Analysts watching the cybersecurity startup space note that investor interest in the non-human identity segment has accelerated sharply over the past twelve months, a sign that commercial recognition of the problem is hardening even as enterprise defenses remain porous.

Follow Global Defense Digest

Subscribe

To receive updates about new articles, or opt in to our daily digest!

Choose one:

We don’t spam! Read our privacy policy for more info.

Subscribe

To receive updates about new articles, or opt in to our daily digest!

Choose one:

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *