With AI copilots demanding access, identity is under strain as CISOs juggle new risks and old defences
Identity and access management (IAM) has always been the linchpin of enterprise security, but the arrival of AI agents is testing those systems in ways few security leaders anticipated.
For years, CISOs have been told that identity is the new perimeter. With AI now deployed on both sides of the fence – empowering employees while also arming attackers – that perimeter is looking less like a neat boundary and more like a shifting, contested zone.
Machine identities multiply
Generative AI has already infiltrated the daily workflow. Microsoft, Google and Salesforce are all pitching copilots to automate tasks from email drafting to sales forecasting, developers are leaning on GitHub Copilot and similar assistants to accelerate coding, and HR teams are experimenting with AI to screen CVs or generate policy documents.
In each case, the AI agent requires access to documents, email, source code repositories, and sensitive personnel records. That access is often extensive, automated and difficult to oversee. The question for enterprises is whether their IAM systems are equipped to handle not just human identities but machine ones too.
The first challenge is scale. Every new AI assistant, bot or plugin effectively creates a new identity. Where a finance team might have previously had one shared reporting tool, they may now be trialling three different AI dashboards, each connected to payroll and ERP data.
IAM systems that were designed to map roles to people are now mapping roles to code. This risks an explosion in machine identities that few organisations are tracking effectively. Research from analysts has long warned about “identity sprawl”, but the rise of AI agents could push it into overdrive.
Trust, deception and compliance
The second challenge is trust. Human users, however fallible, are subject to training, contracts and accountability. An AI agent is not. It will carry out instructions based on its training data and prompts, without any inherent sense of risk or compliance. That makes it vulnerable to manipulation. A poorly designed prompt – or, worse, a malicious one – can persuade an AI agent to exfiltrate data, generate poisoned code or leak credentials. For IAM, that means the traditional models of authentication and authorisation may not be sufficient.
There’s also the problem of impersonation. Attackers have always sought to compromise identities through phishing, credential stuffing or SIM swaps. With generative AI, those attacks are becoming more convincing.
“Attackers are already using AI to generate plausible voice or text imitations,” said Taras Tymoshchuk, CEO and Co-Founder at Geniusee. “This directly undermines classic identification methods, so the future of IAM is inevitably associated with multi-level verification.”
But he does have an answer: “Businesses need to move towards contextual authentication: checking not only who is logging in, but how they are doing it. Behavioural patterns are becoming a new security factor.”
AI is changing the face of fraud-deepfakes, synthetic identities, and automated attacks are making traditional defenses obsolete. As fraud tactics evolve with machine speed, businesses face escalating threats that jeopardize both revenue and trust. Explore how AI is transforming the fraud landscape and gain actionable insights into next-gen detection strategies and adaptive security frameworks that actually work.
The fightback
Enterprises are beginning to experiment with adaptive access controls as a countermeasure against unauthorised access.
Rather than relying on static roles and passwords, systems monitor behavioural signals in real-time: unusual login times, odd data access patterns, or uncharacteristic keystroke dynamics. If an AI agent suddenly requests sensitive files at 3am, the system can demand re-authentication or block the action.
Yet these approaches come with a cost. False positives can frustrate employees, and highly restrictive policies risk stifling productivity.
Regulators are also circling. The European Union’s AI Act has already set out rules for high-risk AI systems, with potential implications for identity governance. Meanwhile, frameworks such as NIST’s guidance on AI risk management are encouraging enterprises to treat AI agents as distinct entities requiring oversight.
For organisations already grappling with NIS2, DORA or sector-specific compliance regimes, AI adds another layer of complexity. IAM teams will find themselves not only securing access but proving to auditors that AI identities are managed, logged and limited.
The moving perimeter
Vendors are, unsurprisingly, responding with new product pitches. Identity platforms are rolling out dashboards for machine identities, promising visibility across bots, APIs and AI assistants. Cloud providers are extending their IAM services to cover service accounts, cryptographic keys and workload identities.
Yet many enterprises still struggle to enforce least-privilege access for human staff, let alone for hundreds of autonomous agents. Consolidating IAM across hybrid environments is already difficult; adding AI makes it harder.
The strategic implication is that IAM can no longer be treated as a back-office hygiene issue. Boards are beginning to understand that identity compromises often underpin the most significant breaches. The MGM Resorts hack, for example, was reportedly triggered by attackers socially engineering a helpdesk into resetting credentials.
As AI lowers the barrier for such attacks, IAM becomes a frontline defence. That means investing not just in technology but in governance: clear policies on which AI tools may access which systems, processes for reviewing machine entitlements, and education for staff experimenting with generative models.
Long-term solutions
Looking further ahead, some in the industry believe decentralised identity could provide a solution. Instead of a proliferation of usernames and access tokens, digital credentials could be cryptographically signed and verified, limiting the scope for impersonation.
Projects such as the EU’s Digital Identity Wallet hint at where this might go, but these are long-term bets, not immediate fixes. For most enterprises, the pressing issue is how to integrate AI into their existing IAM frameworks without losing control.
The rise of AI agents is exposing the brittleness of identity systems built for an earlier era. Passwords, roles and static permissions were never designed to govern autonomous software that can act faster, at greater scale, and with less oversight than a human. Enterprises that treat IAM as a dynamic, adaptive process will be best placed to withstand the turbulence. Those who assume yesterday’s identity models will suffice may find that their AI “helpers” become an attacker’s best friends.
AI is not going away, nor are the efficiencies and competitive advantages it offers. The task for CISOs is to ensure that every new agent is welcomed into the enterprise with the same scepticism and scrutiny as a new employee. In the age of AI, identity is still the perimeter – but the fence posts are moving faster than ever.
More articles by Carly Page