Table of Contents
The Identity and Access Gaps in the Age of Autonomous AI
TL;DR: This Cloud Security Alliance survey report examines how enterprises are managing identity and access for autonomous AI agents operating across production systems. It highlights major gaps, including agents using borrowed or shared identities, unclear separation between human and AI activity, fragmented ownership, and reliance on temporary governance controls. The report also identifies key capabilities organizations need to scale AI agents safely, including dedicated agent identities, short-lived access, stronger accountability, and runtime controls for revoking access when necessary.
David Goldschlag
Co-founder & CEO, Aembit
Published Jul 2026
Updated Jul 2026
50:1
Non-human to human identities
18
Agent threat classes mapped
0
Long-lived secrets required
Free DOWNLOAD
Get the Report
Instant access
- 32 pages
- 40 min read
By supplying my contact information, I authorize Aembit to contact me with personalized marketing communications about our products and services. See our Terms and Privacy Policy for more details.
- Trusted by security teams at Fortune 500s
Table of Contents
AI agents are operating across production systems, invoking tools, accessing data, and acting autonomously – often under borrowed identities, inherited permissions, and credentials nobody is rotating.
This Cloud Security Alliance survey report, commissioned by Aembit, examines how enterprises are actually managing AI agent identity and access today.
Inside, you’ll find:
- 68% of organizations cannot clearly distinguish between actions taken by AI agents and those taken by humans.
- Most agents don’t operate under their own identity – they inherit access originally scoped for users or shared accounts.
- Fragmented ownership and accountability mean security, engineering, and IT are often managing the same problem with different assumptions – and different answers for who’s responsible when something goes wrong.
- Governance mechanisms, human approval workflows, and kill-switch revocation are being used as stopgaps where identity-layer controls don’t yet exist.
- Organizations cite clear identity separation and short-lived, per-task access among the capabilities most needed to scale safely
Who this report is for
Security, IAM, platform, and engineering leaders and practitioners responsible for extending identity controls to autonomous systems – and the teams making decisions about how AI agents authenticate, access resources, and get secured at runtime.
David Goldschlag
Co-founder & CEO, Aembit
A pioneer in identity and security, David co-invented onion routing (the basis for Tor) and has led identity products at scale.
Continue Exploring
Our learning center features all the latest resources to deepen your understanding of securing workload access, including how-to guides, videos, webinars, and more.