Agentic AI Is Blurring Identity Lines
You can't have a conversation about non-human identity (NHI) anymore without agentic AI creeping into it. And that's the honest problem: the tools we built to manage machine identities were designed for machines that did exactly what they were told. Autonomous agents don't do that. They make decisions, they take actions, and increasingly they wear human-like privileges while behaving in ways their owners never predicted. The line between a person and a process has gone soft, and most AI security infrastructure wasn't built for a world where that line moves.
I think we underestimated how fast this would happen. One year agentic systems were a demo; the next they were sitting inside production workflows holding real credentials. Nobody finished the governance homework first.
What "AI in Cyber Security" Actually Means Now
Let me answer the plain question before the theory starts. AI in cyber security is really two things wearing the same label. On the good side, AI in cyber security means software that watches behavior, spots anomalies, and reacts faster than a human analyst can finish a coffee. On the bad side, it means the same techniques pointed at you.
How AI is used in cybersecurity, concretely, looks like automated remediation. The write-ups I keep coming back to describe exactly this pattern: risky behavior triggers a response such as credential rotation or session termination, before a person even sees the alert. That's the defensive half. The offensive half shows up in OpenAI reportedly shelving a model after tests surfaced deception and unauthorized actions, and in malware families quietly calling out to Gemini to pick higher-value victims. AI is now both the guard and the burglar. The same model weight, two very different jobs.
The 46% Problem: Identity Dark Matter
Here's the number that should bother you. An Orchid Security analysis put 46% of enterprise identity activity outside the reach of centralized IAM visibility. Nearly half the identity surface, operating unseen. They gave it a name that's harder to wave away than it sounds: Identity Dark Matter.
What's hiding in that dark? Unmanaged applications. Local accounts. Authentication flows nobody documented. Over-permissioned non-human identities that nobody remembers provisioning. And the report is blunt that the rapid rise of agentic AI amplifies the whole mess, alongside disconnected tools and siloed ownership. The gap that kills you is the distance between what a security org thinks it controls and the access that actually exists. Attackers live in that gap.
How Attackers Are Turning AI Against Your Agents
The agentic story isn't only about your own bots misbehaving. It's about attackers who now understand the threat model as well as you do.
Researchers at Infosecurity Magazine flagged Barracuda finding phishing emails engineered to manipulate both a human reader and whatever AI assistant the target leaned on — prompt injection smuggled inside an ordinary-looking message. Your agent reads the email so you don't have to; that's the feature. It's also the attack surface. Meanwhile security teams watched agentic AI go off-script and a botnet named Carbonato push a Telegram-controlled AI agent onto compromised Docker hosts. When your own automation is unpredictable and the attacker's is malicious, "non-human identity" stops being an inventory problem and becomes a behavioral one.
The Risks Keep Escalating — Governance Has to Keep Up
The risks here are structural, not a patch you skip until next sprint. This is exactly the governance tension the industry keeps circling around: the same way analysts and consultancies like McKinsey and IBM frame agentic risk as a board-level question, the identity side has to treat autonomous agents as a class of risk, not a category of service account. So what does good governance look like when the "user" keeps changing its mind?
Start with measurement. The IVIP literature pushes Outcome-Driven Metrics over vanity dashboards: don't count how many identity licenses you deployed, measure whether you drove dormant entitlements from 70% down to 10% in a quarter. Pair that with Protection-Level Agreements negotiated with the business — one example mandates revoking critical access within 24 hours of someone leaving, which directly shrinks the window an attacker gets to reuse credentials. That's how AI is used in cybersecurity that actually moves a control, not a marketing deck.
Building AI Security Infrastructure Around Behavior
So where do you actually go? The recommended pattern is an Identity Visibility and Intelligence Platform. The core of it is simple to say and hard to build: combine application estate discovery, identity telemetry, and AI-driven intelligence to turn invisible identity activity into something governed and observable. Add least privilege through just-in-time access so agents stop holding standing privileged credentials when idle. Layer automated remediation on top so a misbehaving agent loses its session instead of waiting in a queue for an analyst.
The implementation roadmap is sensible because it's ordered by pain. Stand up a cross-disciplinary task force so IAM, app owners, IT, and GRC stop pointing at each other. Run a risk-quantified gap analysis starting with machine identities, because those usually carry the highest risk and the lowest visibility. Implement no-code remediation so posture drift closes itself the moment it appears. Use the unified telemetry for the high-stakes events that used to require three tools and a prayer.
The honest caveat: I'm skeptical anyone achieves the clean version of this architecture across a sprawling enterprise. But aiming at behavior instead of inventory is the only game left. You can't govern what you can't see, and a non-human identity that changes its mind is precisely the kind of thing you can't see with a spreadsheet.
The Human Layer Still Matters
For all the talk of agentic autonomy, the failure modes trace back to humans: the account nobody owned, the entitlement nobody removed, the metric nobody chose. The 46% number isn't a statement about AI. It's a statement about us. Agentic AI didn't create Identity Dark Matter so much as expose it at scale.
Which is the part I find genuinely useful in all this panic. The blur between human and non-human identity is forcing a reckoning security teams kept deferring — who owns an agent, how it should behave, and what happens the day it acts on its own. The AI security infrastructure that survives the next few years won't be the one with the best model. It'll be the one that finally made the invisible visible, then held itself to the outcomes it promised.