AI agent security and the rise of non-human identities
AI agent security is the discipline of governing, authenticating, authorizing, and monitoring autonomous software agents that act on behalf of people or systems across digital environments, often at machine speed and without direct human supervision. As enterprises deploy these agents into production, they are discovering that every agent is a new non-human identity that can hold credentials, invoke APIs, and touch sensitive data. Traditional identity and access controls, designed for human users and static applications, struggle to answer basic questions in real time: which agent is acting, for whom, using what authority, and with which intent. This shift is driving a new wave of non-human identity management, identity verification agents, and AI agent access control technologies that focus on continuous decisions rather than one-time approvals, giving security teams a way to constrain agents without blocking innovation.
SailPoint bets on non-human identity with Entro
SailPoint’s planned acquisition of Entro marks a clear pivot toward non-human identity management as a first-class security concern. Entro specializes in securing non-human identities and credentials, which now include AI agents, workloads, and automated workflows. SailPoint intends to plug this into its Agentic Fabric, described as a new paradigm for securing autonomous AI agents and non-human identities at scale through discovery, governance, and protection. According to SailPoint CEO Mark McClain, the combined platform aims to give customers “frictionless, complete visibility into every non-human identity” and the credentials those identities use to reach critical data. This move shows how identity platforms are expanding beyond human lifecycle management into continuous oversight of keys, tokens, and secrets that AI agents depend on, closing the gap between identity governance and day-to-day agent behavior in production.
CrowdStrike and Saviynt push real-time authorization for agents
CrowdStrike and Saviynt are both centering AI agent security on real-time authorization rather than static roles or standing privileges. CrowdStrike’s Continuous Identity for AI Agents builds on the Falcon platform and technology from its SGNL acquisition, granting or revoking access based on live risk signals. Each agent receives a cryptographically verifiable identity aligned to the SPIFFE standard, replacing fragile API keys and enforcing continuous checks on who owns the agent, who is calling it, and the device posture involved. Saviynt’s Agent Access Gateway adds Intent-Aware Runtime Authorization, evaluating identity, context, policies, and intent on every agent action and blocking off-policy behavior at runtime. These controls aim to match agents’ superhuman speed with equally fast decisions, turning identity verification agents and runtime policy engines into the new enforcement layer for tools, data, APIs, and even other agents.

Akamai’s agentic security framework and trusted commerce
Akamai is approaching AI agent security through an agentic security framework that blends identity, observability, trust, and edge security into one decision layer. The company’s Bot & Agent Control solutions now integrate with payment and identity ecosystems to authenticate agents and bind them to real users. In cooperation with Visa, Akamai supports Visa’s Trusted Agent Protocol, which defines how agents are authenticated and authorized for transaction-level trust in commerce flows. Akamai is also working with Skyfire and Experian on a “Know Your Agent” framework that standardizes how agents declare identity, origin, and intent. As Visa notes, “Without trusted identity and explicit permissioning, AI agents cannot participate in commerce at scale.” By pushing these checks to the edge, Akamai helps merchants and service providers apply user-centric authentication and risk assessment to AI-driven interactions without rebuilding their existing systems.
New security playbook for autonomous, high-volume AI actions
The common pattern across SailPoint, CrowdStrike, Akamai, and Saviynt is a move toward continuous, risk-based AI agent access control. AI agents can execute thousands of actions across business systems within seconds, delegating to sub-agents, invoking tools, and touching sensitive records far beyond a single user session. Static permissions, one-time approvals, and standing privileges cannot keep pace. Security teams now need an agentic security framework that treats agents as a new class of identity with their own lifecycle, policies, and audit trails. That means clear ownership, cryptographic identity, runtime policy enforcement, and constant verification of who the agent represents and why it is acting. As organizations move from experiments to production, success will depend on designing controls that let agents operate autonomously yet within strict, observable boundaries that can adapt to changing risk in real time.






