Three identity moves for security leaders in the age of AI
AI agents increasingly act as digital employees with access rights of their own, and their identities must be governed accordingly. So writes John Zhao, Executive Cybersecurity Advisor, in a blog post published by ISACA on 24 July 2026. Zhao recommends three moves for security leaders: behaviour-based authentication, governing the agent economy, and measuring the maturity of the zero trust architecture. The post cites figures indicating that non-human identities now outnumber human ones by at least 82 to 1, and that only 52% of surveyed organisations have fully deployed zero trust.
What happens technically
The first move shifts authentication from one-off checks to continuous assessment. Instead of a multi-factor login opening the door once, signals such as location, time, biometrics, typing patterns and login history are evaluated continuously, and access is adjusted by risk. Zhao points to the tool classes ITDR, identity threat detection and response, and risk-adaptive access control as the way there. The backdrop is that attacks decreasingly need malware at all. The post cites figures from CrowdStrike's 2026 threat report that 82% of detections were malware-free, meaning attacks that use valid access instead of malicious code.
The second move concerns the AI agents themselves. Zhao describes them as digital employees capable of executing contracts, committing spend and reading sensitive customer and financial data, and he warns that an agent with access to a financial system is an attack vector that can be hijacked through prompt injection. The countermeasures he recommends are least privilege for each agent, short-lived credentials that cannot be reused, and audit trails that cannot be altered after the fact. The third move is measuring maturity: access granted just in time, policy decision and enforcement points, and cryptographic verification of the commands agents send.
What this means for you if you own access management
The advice lands in a shift many Norwegian organisations are in right now. If you are connecting AI assistants to email, document stores and line-of-business systems, every connection gives you a new identity with access rights of its own. Treat those identities as technical details, and a shadow of accounts grows that nobody owns, nobody monitors and nobody removes. We would read the figures the post cites as vendor figures, with the caveats that entails. The direction still matches what we see in practice: identity, not malware, has become the main way in.
In our view this is a governance question before it is a tooling question, and the questions land with you and your management. Who owns an AI agent's identity, who approves its access, and who answers when it is abused? If you already have access management for people in order, you have the framework ready. Extending it to agents is demanding enough, but it is an extension and not a rebuild.
Berigo recommends
- Build an inventory of all non-human identities, service accounts and AI agents included, with a named owner for each.
- Give every AI agent least privilege, and remove access the agent no longer needs, just as in employee offboarding.
- Replace long-lived keys and secrets with short-lived credentials where possible.
- Ensure audit trails of agent actions that cannot be altered, and review them regularly.
- Treat prompt injection as a real attack vector in the risk assessment of every AI integration.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch