verifiedagents.ai
All posts

5 min readAI Agents · Zero Trust

What Is the AI Agent Identity Problem?

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Hero: What Is the AI Agent Identity Problem?

TL;DR: The AI agent identity problem is the distance between adoption and readiness: 79 percent of enterprises run AI agents (PwC), while only 18 percent of security leaders trust their identity systems to handle them (Strata, May 2026). Identity stacks built for human career events can't see agents and can't prove what they did.

Last updated October 5, 2026. Rebuilt for verifiedagents.ai: the problem defined, the numbers behind it, the Kindervag correction, and where to start.

What is the AI agent identity problem?

Most companies run AI agents through identity systems designed for people. Human identity follows career events: you get hired, you get an account, you change roles, you leave. An agent has no career. It operates continuously at machine speed and never logs out. It acts faster than any review cycle.

The result shows up as pilot purgatory. A working agent burns $300,000 across six months of pilot and never ships, because nobody can prove what it's allowed to do or show what it did. CSA's April 2026 report, Securing Autonomous AI Agents, names this the central blocker keeping working agents out of production.

The numbers put a frame on it. PwC puts agent adoption at 79 percent of enterprises. Strata's May 2026 survey found 18 percent of security leaders trust their existing identity systems to handle agents. Four out of five companies are running agents through stacks the people responsible for security don't trust.

Why doesn't Zero Trust alone solve it?

Zero Trust is the foundation, and it stays intact. It verifies the connection continuously. Agents need one more layer: verification of each action, against signals you've decided are safe right now.

John Kindervag, who created Zero Trust at Forrester in 2010, corrected my own language on this at RSAC 2026. I was describing an architecture I'm building at a customer and called one element "trust signals." He stopped me: we don't use the word trust when we talk about Zero Trust. We're eradicating trust. Call them validation signals.

He was right, and the distinction is bigger than word choice. Most identity systems were built around trust: you trusted someone enough to issue an account, and the system trusted the account from then on. You can't extend that to an agent. An agent earns each action by validating each signal. For humans that's philosophy. For agents it's the difference between shipping and stalling in security review.

How does one architecture handle humans and agents?

The same way, with different signals. The design separates two things: the identity control plane, which decides who gets in, and the data plane, which decides where they can go once they're in.

Signal checked

Human identity

Agent identity

Who is this?

Account plus device posture

Its own identity, separate from the engineer who launched it

Does the behavior fit?

Location and time pattern, behavioral baseline

The model it's running and the token it was issued

What can it reach?

Role-based access policy

The data domains it's authorized to touch

When is it rechecked?

At login and on risk changes

At every action, because it never logs out

One example of the agent side working. An agent drafting performance reports tries to query the customer payment history table. The architecture reads its signals, sees the payment table outside the agent's authorized domain, and routes the request to human review. Nothing happens until a person approves. Same architecture as the humans use, one more identity type in the catalog.

Why do these projects stall even after everyone agrees?

Because the mental model never gets shared. I watched one customer run a two-day offsite, a hundred slides, full agreement on which agents to launch. A year later the engineers were still fighting the blueprint, convinced they could rebuild the outcomes with scripts. The pushback always sounds the same: why would we buy this? I can already do this.

They can't, and the real failure was upstream. Nobody explained the control-plane and data-plane split before the tools showed up, so every meeting became a debate about tools instead of what the tools are for. The agent depends on identity. Identity is the work everyone agreed to, and nobody finished.

Where do you start if agents are already in pilot?

  1. Find the highest-risk identity in the rollout. Usually it's the agent drafting work that touches financial or customer data.

  2. Give that agent its own identity, separate from whoever launched it, with credentials that expire. The access half of this is in

    how much access an AI agent should get

    .

  3. Define its authorized data domains and route anything outside them to human review.

  4. Score yourself before you buy anything. Identity Management is the first of the five ATF elements, and the

    free ATF assessment

    locates you in about ten minutes.

Frequently asked questions

How is agent identity different from non-human identity (NHI)?

NHI covers service accounts and workload credentials that follow predictable scripts. Agents are non-deterministic. They reason, choose tools, change course, and take actions you didn't pre-define. They need validation of intent at every action, not a credential issued once and trusted until rotated.

Is this a tooling problem?

No vendor will do the governance work for you. The research converging on this in 2026 comes from CSA, CEPS, KuppingerCole, Microsoft, Strata, and IANS, and all of it points the same direction: enterprises have to build the identity model themselves, then buy tools that fit it.

What did Kindervag actually change?

One word that reorders the design. Validation signals, not trust signals. The system never holds trust for an agent. It proves each action as it happens.

What's the fastest sign my identity stack can't handle agents?

Ask what one specific agent did last Tuesday. If the answer is a service account's log that six other things share, your stack can't see agents yet.

Key takeaways

  • 79 percent adoption, 18 percent confidence. That distance is the identity problem.

  • Human identity follows career events. Agent identity has to follow actions.

  • Validation signals, not trust signals. Agents never get the benefit of the doubt.

  • Split the control plane from the data plane and share that picture before buying tools.

  • Start with the agent closest to financial or customer data.

Locate yourself before the audit does

The free ATF assessment walks the five elements, starting with Identity Management. The ground floor is in what AI agent security is.

Identity is becoming the operating system for AI agents. Run yours, or explain the breach to your board.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.