Identity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals proliferate across enterprise environments, the governance mode

The traditional approach to managing digital identities, known as identity lifecycle management, is ill-equipped to handle the growing presence of artificial intelligence agents within enterprise systems. These systems were originally designed to track human employees, with lifecycles defined by hiring, management, and termination processes. AI agents, however, do not fit this model.
Current identity management frameworks are built on the assumption of a human user with a defined employment history, a reporting structure, and a clear end date for their role. This structure dictates how identities are provisioned, deprovisioned, and how their access rights are managed over time.
AI agents, by contrast, are autonomous entities that operate without these human-centric attributes. They may not have a direct manager, an employment record in the traditional sense, or a predictable departure date. Their operational lifecycles are driven by task completion, algorithmic changes, or system integration rather than HR processes.
As these autonomous AI agents become more prevalent and integrated into enterprise workflows, the existing governance models for identity management face significant challenges. The lack of a human framework for AI agents means that current provisioning and deprovisioning workflows are not directly applicable.
This mismatch raises concerns about how to effectively govern and secure the identities of AI agents. Without a clear understanding of their lifecycle and access requirements, organizations risk creating security vulnerabilities.
The proliferation of AI agents as autonomous principals within enterprise environments necessitates a re-evaluation of identity governance strategies. Existing systems, designed for human users, may not provide the necessary controls for these new types of digital entities.
Organizations need to consider how to adapt or replace their current identity management systems to accommodate the unique characteristics of AI agents. This could involve developing new frameworks for provisioning, access control, and deprovisioning that are tailored to the operational needs and security implications of AI.
The fundamental architectural assumptions of identity lifecycle management, rooted in human employment, are proving to be a limitation in the face of increasingly sophisticated and autonomous AI agents operating within corporate networks. Addressing this gap is becoming a critical aspect of modern cybersecurity and IT governance.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets