Table of Contents

Aembit Reports

The Identity and Access Gaps in the Age of Autonomous AI

TL;DR: This Cloud Security Alliance survey report examines how enterprises are managing identity and access for autonomous AI agents operating across production systems. It highlights major gaps, including agents using borrowed or shared identities, unclear separation between human and AI activity, fragmented ownership, and reliance on temporary governance controls. The report also identifies key capabilities organizations need to scale AI agents safely, including dedicated agent identities, short-lived access, stronger accountability, and runtime controls for revoking access when necessary.

Aembit Team

Product & Research

Published Mar 2026

Updated Sep 2026

50:1

Non-human to human identities

18

Agent threat classes mapped

0

Long-lived secrets required

Identity and Access Gaps in the Age of Autonomous AI-cover
Free DOWNLOAD

Get the Report

Instant access

By supplying my contact information, I authorize Aembit to contact me with personalized marketing communications about our products and services. See our Terms and Privacy Policy for more details.

Table of Contents

AI agents are operating across production systems, invoking tools, accessing data, and acting autonomously – often under borrowed identities, inherited permissions, and credentials nobody is rotating.

This Cloud Security Alliance survey report, commissioned by Aembit, examines how enterprises are actually managing AI agent identity and access today.

Inside, you’ll find:

Who this report is for

Security, IAM, platform, and engineering leaders and practitioners responsible for extending identity controls to autonomous systems – and the teams making decisions about how AI agents authenticate, access resources, and get secured at runtime.

David Goldschlag

Co-founder & CEO, Aembit

A pioneer in identity and security, David co-invented onion routing (the basis for Tor) and has led identity products at scale.

Continue Exploring

Our learning center features all the latest resources to deepen your understanding of securing workload access, including how-to guides, videos, webinars, and more.

Workload Identity Federation Resource

What is Workload Identity Federation?

A secret can grant access. It cannot prove which workload is presenting it. Trace how federation changes the equation at scale.
Aembit and CrowdStrike AIDR data sheet for AI agent identity, access control, and content inspection share image

Aembit + CrowdStrike AIDR for AI Agent Security

Aembit and CrowdStrike AIDR combine AI agent identity and MCP access controls with real-time content inspection and enforcement.
Auditing and Governance for Workload and AI Agent Identity

Auditing and Governance in Modern Identity

Aembit turns workload and AI agent access activity into detailed audit trails, policy insights, and operational visibility.