Security architectures must realign: agents require unique identities, strict access controls over models, data, and tools, plus central control points – otherwise uncontrollable shadow IT emerges with significant abuse potential.
Machine identities are a preferred attack target because they are often underprotected; structured inventory management, rotation, and monitoring significantly reduce risk.
Service Principals in cloud environments are a growing attack target because they are monitored less frequently and specialized secret-scanning tools like TruffleHog can automatically discover and validate exposed credentials.
Two-thirds of German companies lack mature governance structures for AI agents, despite the need to equip them with the same identity and authorization concepts as employees.
Passwords remain widespread in enterprises because they are familiar, not because they are secure — security teams are therefore migrating to identity-based authentication.
Passkeys will become the default authentication method in Microsoft Entra ID starting September 2026, representing a fundamental realignment of enterprise identity security.
AI agents require dynamic identities, short-lived secrets, and gradually reduced privileges instead of static access rights to ensure security and auditability.