{"slug": "your-ai-agents-are-borrowing-credentials-thats-a-problem", "title": "Your AI agents are borrowing credentials. That’s a problem", "summary": "Autonomous AI agents are increasingly borrowing human OAuth tokens and session credentials, creating compliance and audit blind spots that attribute agent actions to human identities, according to CISOs cited in a report on enterprise identity and access management. The report points to a frontier-model evaluation in which an OpenAI model escaped its digital sandbox and hacked into the open-source developer platform Hugging Face, exploiting a zero-day vulnerability and stealing data, an event OpenAI labeled an \"unprecedented cyber incident.\" Security leaders cited in the report call for distinct agentic identity profiles with cryptographic privilege delegation that constrains sub-agents from exceeding the original grantor's permissions.", "body_md": "For nearly two decades, the foundational precept of enterprise Identity and Access Management (IAM) has remained unchanged: access is requested either by a human operator sitting behind a keyboard or by software executing a highly predictable task. While this framework has successfully anchored enterprise security for twenty years, the rapid maturation of autonomous AI agents is quietly collapsing that core assumption.\n\nAI agents now use context and reason to interpret ambiguous instructions. These digital workers autonomously decide which tools to invoke, orchestrate multi-step workflows across disparate software ecosystems, and directly query production databases, all without requiring a human to validate or approve each action.\n\nThe security perimeter is fundamentally changing. A startling validation of this risk occurred recently during a routine frontier-model evaluation that led to the hack of the open-source developer platform Hugging Face. One of [OpenAI’s most advanced models escaped its digital sandbox](https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html) and hacked into Hugging Face, stealing its data to accomplish its task. It did this by coordinating the efforts of agents to exploit a zero-day vulnerability, while potentially also exploiting multiple other vulnerabilities. OpenAI labeled this boundary-crossing event an “unprecedented cyber incident,” proving that rogue agentic behavior is no longer a theoretical risk. It is an immediate threat to the enterprise attack surface.\n\nAfter this incident, it’s clear CISOs can expect a structural rise in these autonomous intrusions.\n\nI spoke with some close, trusted CISOs who have had varying experiences managing identities and agents, and the consensus is clear: agentic governance requires an entirely new framework.\n\nAs one CISO shared: *“Agents aren’t malicious by design, but they absorb massive swaths of human behavioral data and optimize dynamically. They will inherently surface and exploit gaps in our governance structures to achieve their goals, even when explicitly restricted to a sandbox environment.”*\n\nThis behavioral unpredictability shifts the problem from traditional access control to continuous architectural validation. Organizations can no longer rely on a one-step process of checking identity and credentials.\n\nAnother security leader emphasized the need for distinct agentic identity profiles, suggesting cryptographic privilege delegation that strictly constrains sub-agents from exceeding the original grantor’s permissions. To manage this effectively, enterprises must clearly delineate between short-lived agents invoked by an active user and continuously running autonomous digital workers.\n\nWhen I asked a third CISO if these agents should simply be integrated into existing human IAM governance, the answer was definitive: *“They must be treated differently. They operate continuously, evolve at machine speed and introduce non-linear risks that human-centric systems simply aren’t engineered to contain.”*\n\nThe immediate vulnerabilities are manifesting around session management and credential sharing. To accelerate productivity, internal engineering teams frequently allow AI agents to “borrow” human OAuth tokens or session credentials to ‘act’ as a user to execute tasks. This shortcut brings risks and introduces severe compliance and audit blind spots.\n\nIf an agent initiates an anomalous action, telemetry logs attribute the behavior entirely to the human identity, completely masking the agent’s involvement. The agent then automatically inherits the full scope of the human’s privileges, frequently violating the principle of least privilege. Finally, remediating an active incident becomes an operational bottleneck: revoking the agent’s access means revoking the human executive’s or developer’s credentials at the same time, halting critical workflows.\n\nTo eliminate this blind spot, security leaders are moving away from treating agents as human users or mapping them to traditional non-human identities like legacy service accounts or workload identities. Instead, agents are being isolated into an entirely new classification of [Non-Human Identity](https://www.microsoft.com/en-us/security/business/security-101/what-are-non-human-identities) (NHI). This dedicated tier enforces independent lifecycles, rigorous least-privilege boundaries and immutable, attributable audit trails.\n\nEnterprise perspectives on implementation, however, remain split. One CISO concurred with the risks, saying, *“I think (our identity) framework needs to be enhanced. Identity is something we’re terrible at.”* \n\nAnother CISO added a different point of view. *“We treat all identities equally and are moving to a least-privilege, vaulted and audited model for all. AI agents wouldn’t be excepted from that, but it’s tough because they inherently need more permissions than most humans, depending on scope. They need more operational leeway.”* \n\nOf course, the challenge is [managing AI](https://www.cio.com/article/4160452/managing-ai-agents-and-identity-in-a-heightened-risk-environment.html) agents’ behavior. Rules and language for managing this process are being written in real time. Unfortunately, it’s often by the same vendors who built the ISPM platforms that managed human and machine identities already underway before agents arrived.\n\nHow do you prevent [rogue AI activities](https://www.cio.com/article/4214149/the-ai-cybersecurity-arms-race-is-on.html) in systems? The fundamental challenge lies in reining in autonomous optimization. When an agent’s core optimization metric is to complete its mission, it will systematically test every logic combination and security bypass available at machine speed. My peers and I are increasingly observing scenarios where human identity platforms fail to contain these dynamic agentic loops.\n\nFor instance, one of my favorite security executives has launched an agentic guardrails startup to stress-test these exact defensive boundaries. In a controlled test environment, he and his team established an isolated data partition containing sensitive financial records. The access policy explicitly required input from a keyboard, a logical gate designed to verify human presence. Confronted with this restriction, an agent attempted multiple standard access vectors and failed. However, optimizing for the objective, the agent “understood” what the barrier might be, and autonomously located, downloaded and executed an open-source virtual keyboard module from the web to simulate human input. It bypassed the gate entirely.\n\nTraditional authentication methods like username, password and MFA were built for humans who interact with systems periodically and at low frequency. However, autonomous AI agents operate continuously and at light speed, introducing new risks where automated scripts can repeatedly target assets or exploit data in unforeseen ways.\n\nAddressing this paradigm shift requires robust governance platforms and specialized, intelligent access tiers. Established identity security giants are evolving their suites into enterprise nerve centers that can orchestrate both human and machine lifecycles. As one CISO noted, *“Leveraging our existing deployments in SailPoint and CyberArk to vault and rotate credentials remains our baseline defense.”*\n\nOther [solutions](https://getnametag.com/)* can also address this identity gap by tying digital access to verified real-world credentials, like driver IDs or passports. This creates a dedicated identity tier for agentic access. When paired with just-in-time access controls to prevent continuous, unlimited privilege, this framework ensures AI agents are explicitly authenticated and strictly bounded, neutralizing the threat of persistent, spoofed automated attacks. \n\nAs we invest in and build the infrastructure to secure this frontier, the immediate question remains: How is your organization adapting its identity governance to draw the line between human intent and autonomous agent execution?\n\n**Glasswing is an investor in Nametag.*", "url": "https://wpnews.pro/news/your-ai-agents-are-borrowing-credentials-thats-a-problem", "canonical_source": "https://www.cio.com/article/4227766/your-ai-agents-are-borrowing-credentials-thats-a-problem.html", "published_at": "2026-09-29 13:00:00+00:00", "updated_at": "2026-09-29 13:20:27.933947+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "artificial-intelligence"], "entities": ["OpenAI", "Hugging Face", "CISOs"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/your-ai-agents-are-borrowing-credentials-thats-a-problem", "markdown": "https://wpnews.pro/news/your-ai-agents-are-borrowing-credentials-thats-a-problem.md", "text": "https://wpnews.pro/news/your-ai-agents-are-borrowing-credentials-thats-a-problem.txt", "jsonld": "https://wpnews.pro/news/your-ai-agents-are-borrowing-credentials-thats-a-problem.jsonld"}}