The Security Strategist 27 August 2026 28 MIN

Who Owns an AI Agent? Rethinking Identity, Security, & Accountability

“A real-time layer of continuous authorisation which revalidates an agent's access as it acts and catches behaviour. When this drifts mid-session, the protect capability enforces policy based on the intent of the user or the intent of the agent at that moment.”

Especially as rogue AI agents are increasingly escaping safe testing environments, such as OpenAI’s rogue AI agent attacking Hugging Face, it’s now more important than ever for enterprises to implement AI agent identity governance strategies that prevent unauthorised access to their systems.

As AI agents seem to be turning into employees in enterprises, the majority of identity security strategies were never created with software that can act on its own.

As a result, a new security issue has emerged concerning AI agent identity governance and the security of non-human identities (NHI). Since enterprises are now using agents who can access data and choose tools while carrying out actions on the employee's behalf, the conventional approach of granting access once and then reviewing it later is starting to appear increasingly unsuitable.

Levent Besik, Chief Product Officer at SailPoint, believes that the solution is continuous authorisation. It means evaluating, as soon as an AI agent tries to carry out a particular action, whether it should be allowed to do so.

In the recent episode of The Security Strategist podcast, Besik joined host Nitish Deshpande, a Senior Analyst at KuppingerCole, to talk about why AI agent governance needs restrategising, starting with continuous authorisation for non-human identities. Besik said that identity had to be something that you assessed at every action rather than something that you could check simply at the door.

“The question most security leaders are asking is: Is this AI agent authorised with one-time permission?” Besik added, “It should be: Is this specific action by this agent on behalf of this human that has access to this data still authorised right now, in that very moment?”

However, it goes to show a pivot from the static provisioning time process to a continuous, real-time plane of authorisation. “Identity has to be evaluated at every action, not something you can check once at the door,” Besik said. 

The change is necessary in a rapidly changing technology environment in the cybersecurity industry. In the past, human identities have been the main focus in the area of identity and access management (IAM), but the growing influence of agentic AI is quickly increasing the number of non-human identities working within enterprise environments.

Also Watch: Why AI Agents Demand a New Approach to Identity Security

How to Tackle AI Agent Identity Governance in an Enterprise?

The first challenge facing security teams is knowing exactly what they possess. AI agents can be found on cloud platforms, in web browsers, on endpoints and in developer environments, and at the same time employees may also cause the emergence of 'shadow AI' without security teams having full visibility.

Besik maintains that AI agent discovery is necessary yet not sufficient.

He said that if you can't see something, then you can't secure it. While discovery is critical, there are three key capabilities that security teams need to think about. The first one is discovery to gain real visibility into every agent, non-immune, operating in an enterprise environment, and not just the ones provisioned, but the ones that showed up through Shadow AI. A critical part of discovery is coverage - across not just types of agents and platforms that are provisioned but also alse the mediums like browsers, endpoints or CLI to catch Shadow AI 

The second capability is life-cycle governance with clear human ownership. While most enterprises have ok discovery capabilities, many lack proper lifecycle management. 

The third capability, which Besik says is the most important one, is to protect and authorise. “A real-time layer of continuous authorisation which revalidates an agent's access as it acts and catches behaviour. When this drifts mid-session, the protect capability enforces policy based on the intent of the user or the intent of the agent at that moment.”

Overall, NHI governance must move on from relying on static inventories to adopting a continuous lifecycle management approach, which should include handling ownership, carrying out certification, reviewing permissions, and carrying out deprovisioning.

Also Watch: Can Real-Time Identity Governance Replace Access Reviews for Good?

Why is Continuous Authorisation Essential in AI Agent Security?

The most significant change could be the shift from static authorisation to continuous authorisation for AI agents.

Traditional identity security decides whether or not an identity has permission when access is granted. That permission then stays in effect until it is reviewed again, when a role changes or when a provisioning event occurs.

The idea that AI should be agentic goes against that assumption. Besik tells Deshpande, “agents break that model since they have goals, choose their own tools and can alter their behaviour in a matter of seconds.”

SailPoint divides AI agent security into three areas of protection: the prompt, pre-action and runtime stages.

At the prompt stage, enterprises evaluate the request and decide if the identity making the request should be given access to the information in question.

At the pre-action stage, there is an examination of what the agent intends to do before acting, such as making tool calls, establishing connections via the MCP and sending API requests.

Next is runtime authorisation, which involves constantly verifying whether the agent should still be allowed access as it carries out the task.

That last layer is especially important since the circumstances may alter after the agent has started operating; for instance, if a human account is compromised, the organisation should have the capability to end the agent's session and withdraw its access rather than having to wait for the next scheduled review.

Are you enjoying the content so far?

The aim is therefore not merely to restrict AI agents; it is to make sure that their autonomy stays within clear identity and access limits.

Why does AI Agent Governance Need an Audit Trail?

According to Besik, businesses need three basic principles: human ownership coupled with deep context, an unchangeable record of agent activity, and constant risk assessment.

A real-time ledger of all the agentic activities is what’s needed, the Saipaint Chief Product Officer notes. “An immutable record that agents cannot alter, because we've seen these agents erasing their tracks.”

It’s like "something which you would have read about in a science fiction book ten years ago is now actually taking place."

Without such an unchangeable record, enterprises run the risk of establishing what Besik refers to as "autonomy without accountability".

The other option is what SailPoint refers to as “governed autonomy.” This comes in because an agent should never have the capability to exceed the permissions of a human.

While AI agents can function on their own, they cannot go beyond the permissions granted to the human user they represent; all of their activities can be monitored, and their level of risk is constantly assessed.

For Besik, this eventually leads to a convergence of the governance of human and non-human identities.

He says that the identity, human governance and agentic NHI governance should all be brought together since each side needs the context from the other side. As enterprises go from experimenting with AI agents to putting them into use across their business-critical processes, AI agent identity governance may well serve as the link between AI autonomy and enterprise security.

Takeaways

  • AI agent governance must go beyond discovery.
  • Agents need clear human ownership and context.
  • Authorisation should be validated continuously.
  • AI security must cover prompts, planning/MCP actions and runtime.
  • Human oversight should match the level of risk.
  • Immutable logs are key to agent accountability.
  • Human and non-human identity governance will converge.

Chapters

00:00 Introduction to the episode and guest

01:01 Levent's background and expertise in identity and security

02:05 Emerging challenges in AI trust and security

03:22 The impact of AI waves on enterprise security

04:21 From static to continuous trust in AI environments

07:19 Discovery as a foundation for AI governance

09:15 Lifecycle management of AI agents

12:39 Real-time protection and continuous authorisation

16:29 Layered security model for AI agents

21:35 Balancing autonomy and human oversight in AI

23:46 Converging human and AI governance strategies

25:37 Final thoughts and industry outlook

Visit sailpoint.com for further information on AI agent governance when dealing with non-human identities (NHI). 

SailPoint equips the modern enterprise to seamlessly manage and secure access to applications and data through the lens of identity – at speed and scale. As a category leader, we continuously reinvent identity security as the foundation of the secure enterprise. SailPoint delivers a unified, intelligent, extensible platform built to defend against today’s dynamic, identity-centric cyber threats while enhancing productivity and efficiency. SailPoint helps many of the world’s most complex, sophisticated enterprises create a secure technology ecosystem that fuels business transformation.

Sponsored insight

Liked what Levent had to say?

Get in touch with the team at SailPoint to continue the conversation.

SailPoint Featured partner

Ready to put SailPoint thinking to work in your stack?

Tell us about your goals. We will put you in touch with the right person on the SailPoint team.

Contact SailPoint