Every enterprise identity program was designed around a simple assumption: the thing logging in is a person. A person with a password, an MFA device, a predictable workday, and a manager who approves their access.
That assumption is now wrong most of the time. Machine identities outnumber human ones by anywhere from 80 to 1 to more than 100 to 1 in the modern enterprise, and AI agents are the fastest-growing slice of that population. The identity systems most organizations run today weren't just unprepared for this shift — they were architecturally built for a different problem.
Traditional IAM rests on three assumptions, and autonomous AI breaks all of them.
It assumes human-speed, human-shaped sessions. Legacy IAM authenticates a user once, issues a session, and largely trusts it until expiry. That model tolerates a person clicking through a CRM for eight hours. It collapses when the "user" is an agent making hundreds of API calls per minute, spawning sub-agents, and chaining requests across services faster than any anomaly detection tuned for human behavior can flag.
It assumes access needs are known in advance. Role-based access control works when a new hire's entitlements can be mapped to a job description. AI agents are dynamic — they request new permissions at runtime and delegate work to sub-agents, accumulating tool access and execution authority faster than governance processes can map it. There is no quarterly access review fast enough for an identity whose scope changes mid-task.
It assumes someone is accountable for every credential. Every human identity has an owner, an offboarding date, and an HR record. The service accounts, API keys, and OAuth grants that agents run on frequently have none of those things. This isn't a hypothetical concern: security leaders themselves don't trust their current stack here, with only 18% expressing high confidence that their existing identity systems can effectively manage agent identities.
The result is a widening gap between what your IAM can see and what's actually happening on your network. And attackers have noticed.
Non-human identities are already the soft underbelly of enterprise security. Sophos found that 71% of enterprises experienced an identity-related breach in 2025 — and NHIs were the root cause in 41% of those incidents. SpyCloud recaptured 18.1 million exposed API keys and tokens in 2025 alone.
Why are NHIs such an attractive target? Three structural reasons:
They carry static, long-lived credentials. A stolen OAuth refresh token doesn't need to pass MFA. It doesn't get suspicious about a login from a new country. The Salesloft-Drift breach showed exactly how this plays out: persistent refresh tokens gave attackers access across 700+ organizations, with months between initial compromise and detection.
They're shared and over-privileged. A March 2026 CSA survey found that 43% of organizations use shared service accounts for their AI agents. When five agents share one identity, least privilege is impossible by construction — every agent inherits the union of every other agent's permissions.
They're invisible in the audit trail. The same CSA survey found that more than two-thirds of organizations cannot clearly distinguish AI agent actions from human actions in their logs. When an incident happens, "who did this?" becomes unanswerable — and for agentic systems compromised through prompt injection, the agent's own logs can't be trusted anyway.
Now layer autonomy on top. An AI agent isn't just a service account with a fancier name. It makes runtime decisions about which tools to invoke and which data to touch, based partly on untrusted input from the outside world. A compromised service account executes an attacker's script; a compromised agent reasons on the attacker's behalf, with every credential it holds.
The answer isn't to slow agents down or bolt more approvals onto old infrastructure. It's to make identity the enforcement layer — verified continuously, at runtime, for every request. In practice, identity-first security for autonomous AI means four things:
Every agent gets its own identity. No shared service accounts, no inherited human credentials. Each agent is a first-class principal with its own scoped permissions, tied to the human or system that delegated its authority. When Agent A calls Service B which calls Service C, identity propagates across every hop, so the accountability chain never breaks.
Credentials are short-lived and never live in the agent. Static API keys sitting in an execution environment are a single prompt injection away from exfiltration. Identity-first architectures issue ephemeral, cryptographically signed tokens per session — there's simply nothing durable to steal.
Policy is enforced per request, outside the agent. A compromised agent will not honor its own restrictions. Enforcement has to happen at the infrastructure layer — an identity-aware proxy in front of every service the agent touches, evaluating who the agent is, what it's allowed to do, and whether this specific action falls within its delegated scope. A coding agent shouldn't be able to read the HR system, and with per-request policy enforcement, it structurally can't.
Every action is logged with identity context, independently of the agent. Audit trails must be immutable and generated by infrastructure the agent can't tamper with. That's what turns "we think the agent did this" into a compliance-grade record.
This is the same zero trust architecture that security teams have spent a decade building for human users — never trust, always verify, enforce at the point of access. Agents don't need a new philosophy. They need the same one, applied at machine speed and machine scale.
That's precisely what Pomerium does. As a context-aware, identity-aware access proxy, Pomerium sits between your agents and everything they touch: issuing short-lived credentials, enforcing policy on every request, propagating identity across every hop, and writing an immutable audit log the agent can't edit. No agent rearchitecture required — the enforcement lives at the network layer, invisible to the workload and not bypassable from within a compromised execution environment.
The organizations that get this right won't be the ones that deployed agents most cautiously. They'll be the ones that gave every agent an identity, verified it on every request, and never had to wonder what their machines were doing in the dark.
Read our documentation on deploying Pomerium as an identity-aware access proxy for AI agent workloads, or talk to our team about your architecture.
Stay up to date with Pomerium news and announcements.
Embrace Seamless Resource Access, Robust Zero Trust Integration, and Streamlined Compliance with Our App.