financial modeling

When your agents work faster than your access controls can keep up.

As AI agents increasingly manage critical tasks like updating hospital records and conducting factory inspections, a significant structural challenge emerges: enterprise identity and access management (IAM) systems are…

4 min readVentureBeat
When your agents work faster than your access controls can keep up.

The rise of AI agents that can edit medical records in real time or run factory‑floor inspections at machine speed is a double‑edged sword. On one hand, these agents promise to free human workers from repetitive tasks and to push productivity into a new realm. On the other, they expose a blind spot that most enterprises have yet to address: identity governance that keeps pace with machine autonomy. AI agents are running hospital records and factory inspections. Enterprise IAM was never built for them" highlights that the 85 % of companies still stuck in pilot mode are not held back by model limitations but by an absence of robust, machine‑speed access controls. This is why the discussion around agent‑centric IAM is not a niche security concern but a fundamental prerequisite for any organization that wants to move beyond experimentation.

The piece draws on insights from Cisco's Jeetu Patel and Michael Dickman, who argue that the trust gap is architectural. It is not enough to bolt security onto an AI system after the fact; the very structure of identity, policy, and enforcement must be rethought. "If you're feeling constrained by traditional spreadsheets, it's time to explore a solution that empowers your data journey." Similarly, enterprises must explore a governance framework that registers each agent with a defined human owner, clear permissions, and a policy‑governed access scope. Without this, an agent that can update patient records or reconfigure network settings can become an uncontrolled vector for breaches, especially when attackers exploit the same public‑facing applications that have seen a 44 % rise in attacks in 2026.

Dickman's framework, detailed in the trust gap matrix, offers a practical roadmap. First, agent identity governance must move from human‑centric IAM to an agent‑centric model that can inventory, scope, and revoke identities at machine speed. Second, blast radius containment requires microsegmentation, ensuring that even a compromised agent cannot lateral‑move beyond its least‑privileged boundary. Third, cross‑domain visibility demands a unified data fabric that captures actual system‑to‑system communications, enabling real‑time policy enforcement. Fourth, a governance‑to‑enforcement pipeline must translate business intent into automated network rules. Fifth, cultural and workflow readiness ensures that teams rethink processes rather than simply automating the status quo. These five priorities are not optional; they are the foundation upon which any production‑ready agent can rest.

What makes this discussion resonate today is the broader shift in how organizations view data. 85 % of enterprises are running agent pilots while only 5 % have reached production, and this gap is a trust problem that can no longer be ignored. As the industry moves toward AI‑native spreadsheets and AI‑driven data management, the same principles that govern AI agents will apply to the spreadsheets of tomorrow. If enterprises can embed agent identity governance into their core data platforms, they will not only protect sensitive information but also unlock new levels of automation that are both trustworthy and scalable. This alignment of technology, policy, and culture is essential for a future where data tools are truly human‑centered and forward‑focused.

Looking ahead, one question that will shape the next wave of adoption is how organizations balance the need for rapid deployment with the rigor of agent‑centric IAM. Can we develop tooling that automates the creation of agent identities, assigns human owners, and enforces microsegmentation without stalling innovation? Or will the lag in governance become a strategic barrier, pushing some firms into a perpetual pilot state while others leapfrog into production? The answer will hinge on how quickly the industry can transform identity governance from a reactive add‑on into a proactive, machine‑speed foundation. The future of AI‑enabled productivity depends on it.

From VentureBeat

A doctor in a hospital exam room watches as a medical transcription agent updates electronic health records, prompts prescription options, and surfaces patient history in real time. A computer vision agent on a manufacturing line is running quality control at speeds no human inspector can match. Both generate non-human identities that most enterprises cannot inventory, scope, or revoke at machine speed.

That is the structural problem keeping agentic AI stuck in pilots. Not model capability. Not compute. Identity governance.

Read the original at VentureBeat