
May 27, 2026

At RSAC 2026 in San Francisco, three of the world's largest technology companies - Microsoft, Cisco, and Google - each unveiled major new security frameworks specifically designed for agentic AI. The timing was not a coincidence. Enterprise AI adoption has moved faster than anyone anticipated, and the security infrastructure required to govern it has not kept pace.
Gartner projects that 40% of enterprise applications will embed task-specific AI agents by 2026, up from less than 5% in 2025. A survey of over 900 executives and technical practitioners published earlier this year found that 81% of technical teams have already moved past the planning phase into active testing or production deployments of AI agents. Only 14.4% of those teams reported that their agents went live with full security and IT approval.
That gap - between the speed of agentic AI adoption and the maturity of the governance frameworks designed to control it - is where the next wave of enterprise security incidents will originate. For CISOs and CIOs who are either deploying AI agents or approving the systems that do, closing that gap is now a first-order priority.
Enterprise automation is not new. Robotic process automation, scheduled scripts, and API integrations have been part of the enterprise technology stack for years. What makes agentic AI categorically different is the combination of autonomous reasoning, cross-system access, and delegated authority - operating at a speed and scale that makes human oversight in real time effectively impossible.
A traditional automation script executes a defined set of steps. An AI agent reasons about what steps to take, decides which systems to access, determines what actions to perform, and may delegate sub-tasks to other agents - all without human approval at each step. In a controlled red-team exercise cited by Bessemer Venture Partners, McKinsey's internal AI platform was compromised by an autonomous agent that gained broad system access in under two hours.
The identity problem is the core of the challenge. Most enterprise IAM frameworks were designed around human identities - a person authenticates, is granted permissions, and their actions are logged against their identity. AI agents do not fit this model. They are often ephemeral, created on demand for a specific task and destroyed when it is complete. They may operate across multiple systems simultaneously. And in most enterprise environments today, they are running on shared API keys or inherited human credentials with no individual identity of their own.
Identity without accountability
Only 22% of organisations treat AI agents as independent, identity-bearing entities. The majority still run agents on shared API keys or generic service accounts. When an agent takes an action that causes harm, there is no individual identity to trace it to - and no accountability chain.
Overpermissioned access
Agents typically inherit the permissions of the human or system account they are associated with, rather than being granted the minimum permissions required for their specific task. A coding agent with access to production databases, financial systems, and customer data is not a productivity tool - it is a privilege escalation risk.
Shadow AI deployment
81% of technical teams are past the planning phase on agentic AI, but only 14.4% have full security approval. That means the majority of AI agents now running in enterprise environments were deployed without security review. When agents interact with production data before they are vetted, shadow AI becomes a backdoor.
Prompt injection vulnerability
AI agents that process external inputs - emails, documents, web content, API responses - are vulnerable to prompt injection attacks, where malicious instructions are embedded in that content to redirect the agent's behaviour. Prompt injection has been called the SQL injection of the AI era, and most enterprise agents have no structural defence against it.
Audit trail absence
If an AI agent deletes data, triggers a financial transaction, or exfiltrates information, can you reconstruct what happened, why, and under whose authority? In most current deployments, the answer is no. Agentic actions are faster, more complex, and cross more system boundaries than human actions - making post-incident forensics significantly harder without purpose-built audit infrastructure.
The connection between agentic AI governance and hardware authentication is not immediately obvious - but it is direct. The credential theft epidemic that phishing-resistant MFA addresses is being amplified by agentic AI in two ways.
First, stolen credentials are increasingly being used to provision AI agents with inappropriate access. An attacker who compromises a privileged human credential can now use that credential to authenticate an AI agent to enterprise systems - gaining persistent, autonomous access that operates at machine speed and is far harder to detect than a human intruder. The session cookie theft that AiTM phishing enables does not just give attackers access to an inbox. It gives them the ability to authenticate as that user to any system that trusts the stolen session - including agentic platforms.
Second, the non-human identity sprawl created by agentic AI deployment is expanding the credential attack surface dramatically. Every API key, service account, and agent identity is a potential target. Organisations that have not yet established phishing-resistant authentication for their human workforce are building agentic infrastructure on a compromised foundation.
The principle of least privilege - giving each identity, human or agent, only the minimum access required for its specific function - is the connecting thread. FIDO2 hardware authentication enforces strong human identity at the boundary. Zero-trust agent identity governance enforces strong machine identity within the network. Together, they form the foundation of a security posture that can withstand both credential-based attacks and agentic threat vectors.
The announcements at RSAC 2026 signal that the major platform vendors have accepted that existing identity and access management frameworks are not sufficient for the agentic era. Microsoft introduced Agent 365, a control plane for governing AI agents at scale. Cisco extended Zero Trust Access to AI agents, introducing agent identity management that maps every agent to an accountable human owner. Google published M-Trends 2026 and introduced agentic SOC capabilities built on continuous identity verification.
The EU AI Act adds regulatory weight to these technical imperatives, with broad enforcement provisions rolling out through 2026 and SOC 2 and GDPR audits increasingly scrutinising AI agent access patterns. For organisations operating in or with the European market, agentic AI governance is not just a security best practice - it is becoming a compliance requirement.
Trust Panda's enterprise hardware authentication capability addresses the human identity layer - ensuring that the credentials used to provision, manage, and authenticate to agentic AI systems are phishing-resistant at the point of human interaction. Tech Dot's managed IT and cybersecurity capability addresses the governance layer - helping growing organisations build the identity frameworks, access controls, and audit infrastructure that agentic AI deployment requires.
If your organisation is deploying agentic AI and wants to understand how your current authentication and identity governance posture measures up, either team is well-placed to help.