We need to act. #AI #DeAuth now
#toldyouso:
"The report reveals that AI agent identity tends to operate in a gray area. Agents often borrow human or shared identities rather than being managed as distinct entities. This leads to inherited permissions, fragmented ownership, and expanded attack surfaces, making it difficult to enforce consistent policies or clearly attribute actions."

https://www.ien.com/artificial-intelligence/news/22963420/distinguishing-ai-agent-from-human-actions-as-overprivileged-access-becomes-widespread-cloud-security-alliance-study-finds

"Key Takeaways:
AI agents are already operating across core enterprise systems and workflows
Most AI agents lack distinct identities and inherit existing permissions
Fragmented ownership of AI agent access leads to inconsistent controls
Confidence in AI security often exceeds actual IAM maturity
AI agents expand the attack surface through over-privileged access
Governance is compensating for missing identity-centric controls"

Mind that this is no #doomism