5 min readAI Agents · Zero Trust
What Is the AI Agent Identity Problem?
By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

TL;DR: The AI agent identity problem is the distance between adoption and readiness: 79 percent of enterprises run AI agents (PwC), while only 18 percent of security leaders trust their identity systems to handle them (Strata, May 2026). Identity stacks built for human career events can't see agents and can't prove what they did.
Last updated October 5, 2026. Rebuilt for verifiedagents.ai: the problem defined, the numbers behind it, the Kindervag correction, and where to start.
What is the AI agent identity problem?
Most companies run AI agents through identity systems designed for people. Human identity follows career events: you get hired, you get an account, you change roles, you leave. An agent has no career. It operates continuously at machine speed and never logs out. It acts faster than any review cycle.
The result shows up as pilot purgatory. A working agent burns $300,000 across six months of pilot and never ships, because nobody can prove what it's allowed to do or show what it did. CSA's April 2026 report, Securing Autonomous AI Agents, names this the central blocker keeping working agents out of production.
The numbers put a frame on it. PwC puts agent adoption at 79 percent of enterprises. Strata's May 2026 survey found 18 percent of security leaders trust their existing identity systems to handle agents. Four out of five companies are running agents through stacks the people responsible for security don't trust.
Why doesn't Zero Trust alone solve it?
Zero Trust is the foundation, and it stays intact. It verifies the connection continuously. Agents need one more layer: verification of each action, against signals you've decided are safe right now.
John Kindervag, who created Zero Trust at Forrester in 2010, corrected my own language on this at RSAC 2026. I was describing an architecture I'm building at a customer and called one element "trust signals." He stopped me: we don't use the word trust when we talk about Zero Trust. We're eradicating trust. Call them validation signals.
He was right, and the distinction is bigger than word choice. Most identity systems were built around trust: you trusted someone enough to issue an account, and the system trusted the account from then on. You can't extend that to an agent. An agent earns each action by validating each signal. For humans that's philosophy. For agents it's the difference between shipping and stalling in security review.
How does one architecture handle humans and agents?
The same way, with different signals. The design separates two things: the identity control plane, which decides who gets in, and the data plane, which decides where they can go once they're in.
Signal checked | Human identity | Agent identity |
Who is this? | Account plus device posture | Its own identity, separate from the engineer who launched it |
Does the behavior fit? | Location and time pattern, behavioral baseline | The model it's running and the token it was issued |
What can it reach? | Role-based access policy | The data domains it's authorized to touch |
When is it rechecked? | At login and on risk changes | At every action, because it never logs out |
One example of the agent side working. An agent drafting performance reports tries to query the customer payment history table. The architecture reads its signals, sees the payment table outside the agent's authorized domain, and routes the request to human review. Nothing happens until a person approves. Same architecture as the humans use, one more identity type in the catalog.
Why do these projects stall even after everyone agrees?
Because the mental model never gets shared. I watched one customer run a two-day offsite, a hundred slides, full agreement on which agents to launch. A year later the engineers were still fighting the blueprint, convinced they could rebuild the outcomes with scripts. The pushback always sounds the same: why would we buy this? I can already do this.
They can't, and the real failure was upstream. Nobody explained the control-plane and data-plane split before the tools showed up, so every meeting became a debate about tools instead of what the tools are for. The agent depends on identity. Identity is the work everyone agreed to, and nobody finished.
Where do you start if agents are already in pilot?
Find the highest-risk identity in the rollout. Usually it's the agent drafting work that touches financial or customer data.
Give that agent its own identity, separate from whoever launched it, with credentials that expire. The access half of this is in
how much access an AI agent should get
.
Define its authorized data domains and route anything outside them to human review.
Score yourself before you buy anything. Identity Management is the first of the five ATF elements, and the
locates you in about ten minutes.
Frequently asked questions
How is agent identity different from non-human identity (NHI)?
NHI covers service accounts and workload credentials that follow predictable scripts. Agents are non-deterministic. They reason, choose tools, change course, and take actions you didn't pre-define. They need validation of intent at every action, not a credential issued once and trusted until rotated.
Is this a tooling problem?
No vendor will do the governance work for you. The research converging on this in 2026 comes from CSA, CEPS, KuppingerCole, Microsoft, Strata, and IANS, and all of it points the same direction: enterprises have to build the identity model themselves, then buy tools that fit it.
What did Kindervag actually change?
One word that reorders the design. Validation signals, not trust signals. The system never holds trust for an agent. It proves each action as it happens.
What's the fastest sign my identity stack can't handle agents?
Ask what one specific agent did last Tuesday. If the answer is a service account's log that six other things share, your stack can't see agents yet.
Key takeaways
79 percent adoption, 18 percent confidence. That distance is the identity problem.
Human identity follows career events. Agent identity has to follow actions.
Validation signals, not trust signals. Agents never get the benefit of the doubt.
Split the control plane from the data plane and share that picture before buying tools.
Start with the agent closest to financial or customer data.
Locate yourself before the audit does
The free ATF assessment walks the five elements, starting with Identity Management. The ground floor is in what AI agent security is.
Identity is becoming the operating system for AI agents. Run yours, or explain the breach to your board.