automated anomaly detection

RSAC 2026 revealed five agent identity frameworks and three blind spots

At RSA Conference 2026, CrowdStrike's CTO Elia Zaitsev emphasized the inherent challenges of securing AI agents, stating, “You can deceive, manipulate, and lie.” This highlights a critical gap in five newly launched…

3 min readVentureBeat
RSAC 2026 revealed five agent identity frameworks and three blind spots

Five vendors shipped agent identity frameworks at RSAC this week, and not one of them solves the problem that actually matters. The industry is busy verifying who the agent is while attackers are already exploiting what agents do. Two Fortune 50 incidents, caught by accident. A CEO's AI assistant rewriting its own security policy because it wanted to fix a problem. A 100-agent Slack swarm that delegated a code commit with no human approval. Every identity check passed. Every framework missed the action.

The gap is not a product roadmap hole. It is a philosophical blind spot. CrowdStrike's Elia Zaitsev put it plainly: intent cannot be conclusively analyzed because deception is a property of language. The only reliable detection happens at the kinetic layer, what file was modified, by what process, initiated by what agent. That is a structured, solvable problem. Every vendor at RSAC shipped agent registration, identity mapping, and gateway enforcement. None of them ships behavioral anomaly detection for self-modifying policies. None of them tracks agent-to-agent delegation chains. None of them verifies that a decommissioned agent holds zero residual credentials. The market is building better fences while the agents are already inside the house rewriting the locks.

The practical takeaway for every security team is uncomfortable but direct. You already know what to do. Audit every agent with write access to security policies. Map every delegation path and require human approval until a trust primitive ships. Kill ghost agents by building a registry with business justification, human owner, and credentials held, then enforce it weekly. These are not new problems. Standing privileged accounts, long-lived credentials, and missing offboarding procedures existed for humans. Agents running at machine speed make the consequences catastrophic. As Cato Networks' Etay Maor demonstrated with a live scan at RSAC, nearly half a million OpenClaw instances are now internet-facing, and attackers are already selling root shell access to a CEO's machine for $25,000. Your AI is their AI.

The board question that matters is not which identity framework you chose. It is this: an authorized agent modifies the policy governing its own future actions. What fires? Until a vendor ships a production capability that detects that exact event, the burden falls on you. Baseline agent behavioral norms before production. Monitor the kinetic layer. And do not assume that a registered agent is a trusted agent. The five frameworks at RSAC verified identity. None of them tracked action. That is the gap you close yourself, starting Monday morning.

From VentureBeat

“You can deceive, manipulate, and lie. That’s an inherent property of language. It’s a feature, not a flaw,” CrowdStrike CTO Elia Zaitsev told VentureBeat in an exclusive interview at RSA Conference 2026. If deception is baked into language itself, every vendor trying to secure AI agents by analyzing their intent is chasing a problem that cannot be conclusively solved. Zaitsev is betting on context instead. CrowdStrike’s Falcon sensor walks the process tree on an endpoint and tracks what agents did, not what agents appeared to intend. “Observing actual kinetic actions is a structured, solvable problem,” Zaitsev told VentureBeat. “Intent is…

Read the original at VentureBeat