Not AI Agent
Governance.
AI Agent Identity
Governance.
The industry keeps introducing us as an AI agent governance company. We are not one. Arkion plays in the specialized discipline of AI agent identity governance, the foundation the rest is built on: AI agent governance cannot exist without it. This note draws the line between the two spaces, names what each one governs, and marks exactly where we stand.
There is a correction we make in almost every first meeting, and it fits in one sentence: Arkion is not an AI agent governance company. The meeting usually pauses, because from a distance the two names look identical. They are not. One word sits between them, and that word decides what a product watches, what it can prove, and what it can take away. This note is the long version of the correction, written so we only have to make it once.
The Big Room: AI Agent Governance
AI agent governance is the discipline of making sure agents behave. It asks whether an agent’s outputs are accurate, safe, unbiased, and within policy. It runs evaluations and red-team exercises before deployment, watches behavior in production, applies guardrails at run time, keeps a human in the loop where the stakes demand one, and produces the documentation that risk teams and regulators expect.
The frameworks that govern this room say so themselves. NIST’s AI Risk Management Framework is voluntary guidance for managing the risks AI poses to individuals, organizations, and society. ISO/IEC 42001 specifies an organizational AI management system: policies, objectives, and processes for responsible development and use. The EU AI Act’s Article 14 requires that high-risk systems “can be effectively overseen by natural persons” while in use. And when an AI governance platform defines the term, the definition centers on rules, systems, and oversight mechanisms that keep agents operating “safely, ethically, and in alignment with human values.” Behavior, end to end. Not a credential in any of those definitions.
That room is real, necessary, and enormous. Some of the most serious work in enterprise AI is happening inside it, and every company deploying agents at scale will need what it produces. We admire the teams building it. We are not one of them, and when someone files Arkion in that room, both sides lose an hour discovering the mistake. It does not help that at least one large platform now folds identity into the agent-governance pitch: an agent control plane offering identity and access control inside the same product. We understand why: the two rooms share a wall. But a control plane that watches behavior and a governance layer that issues, owns, and revokes identity are different machines, and it is worth asking which of the two a given product actually is.
The Small Room: AI Agent Identity Governance
Arkion’s discipline never reads an agent’s answers. It governs what the agent is: whether it exists legitimately, who issued it, which named human owns and attested it, what credentials it carries, what those credentials may reach, how often they rotate, how fast they can be revoked, and how every one of those facts is proven cryptographically after the fact. When an agent spawns sub-agents, identity governance keeps the lineage intact. When an employee leaves, it decides what happens to their machine estate.
The identity world defines itself just as cleanly. The Cloud Security Alliance’s definition paper counts an entity as a non-human identity “only when it can authenticate (prove who it is) and be authorized (be granted permissions)” to reach resources. OWASP’s Non-Human Identities Top 10 scopes the entire problem to identities and credentials, without a word about model behavior. Identity is what an entity can prove and reach, not what it says.
Put plainly: agent governance decides whether the agent may say what it just said. Identity governance decides whether the agent may enter at all, under whose name, holding which keys, and how quickly those keys die.
Every massive, secure building on earth works the same way. Thousands of people, one small entrance, and at that entrance you are cleared for who you are: a badge, an access card, a fingerprint. Nobody asks the entrance to judge the quality of the work you will do on the eighth floor. It asks one thing: are you who you claim to be, and may you be here. Arkion is that entrance for AI agents. An agent has no face and no fingerprint, so we issue it the cryptographic equivalent, and every door it opens afterward opens under that identity. It is a small, deep specialty inside the wider world of non-human identity, the same discipline that governs service accounts, workloads, and machine credentials, now applied to a rapidly multiplying population.
The Boundary, Drawn Sharply
- A behavior failure. Agent governance owns it: evaluation, guardrails, oversight. No identity product, ours included, would have caught it.
- An identity failure. As long as the session behaves, behavior tooling has nothing to flag. Identity governance is what makes the credential short-lived, scoped, owned, and revocable, shrinking the window in which a stolen credential is worth anything.
- Both rooms, split cleanly. Reducing the odds of the trick is behavior work. Deciding what the trick is worth is identity work: the standing credentials and blast radius the hijacked agent can spend. We wrote the full version in FN-04: you cannot reliably stop the trick, you can only shrink the prize.
The industry’s own trend list has started reflecting this split. Gartner’s Top Cybersecurity Trends for 2026 lists agentic AI oversight as one trend: security leaders identifying sanctioned and unsanctioned agents and enforcing controls. It then lists a separate trend entirely for identity and access management adapting to AI agents: “identity registration and governance, credential automation and policy-driven authorization for machine actors.” Two separate trends, one list.
The regulatory map splits the same way. The EU AI Act is a behavior-and-oversight law: it requires that high-risk systems can be effectively overseen by the people responsible for them, and in the Act’s enacted English text the word “credential” does not appear once. It does not mandate agent identity, and we will not pretend it does. The identity obligations live elsewhere: DORA requires financial entities to limit logical access to their ICT assets and to administer access rights, and NIS2 requires access-control policies and asset management from the entities it classifies as essential and important. Duties like those cannot be met without an identity layer underneath.
Why We Chose the Small Room
Because every control in the big room assumes an answer to a question only the small room can give: which agent is this? A guardrail has to bind to something. An audit trail needs a subject. Human oversight needs a human who is actually accountable, which is an ownership chain, not a checkbox. Picture a speed camera on a road where no car carries a license plate. It sees every violation and catches no one. Agent governance is the camera. Identity governance is the plate. That is why AI agent governance cannot exist without AI agent identity governance.
That is also why the two rooms are not competitors. Agent governance platforms sit above us and decide whether the work was done right. Arkion sits beneath them and proves who did the work, on whose authority, with what reach. Their controls get a subject they can trust. Our identities get watched for behavior we do not see. An enterprise running agents seriously will end up with both.
We picked the small room on purpose. It is the room whose wall every other control leans on.
Field Note FN-11-2026 · Distributed under arkion.ai/field-notes
For questions or to discuss findings: research@arkion.ai
- Gartner, “Gartner Identifies the Top Cybersecurity Trends for 2026” press release (February 5, 2026): Trend 1, Agentic AI Demands Cybersecurity Oversight; Trend 4, Identity and Access Management Adapts to AI Agents, quoted on identity registration and governance, credential automation, and policy-driven authorization for machine actors. The separation is structural (two distinct trends in one list), and Trend 1 covers more than agent behavior alone.
- Holistic AI glossary, “What is AI Agent Governance?” (undated, live September 2026): the quoted behavior-centric definition. A vendor of AI governance software, cited as evidence of how the category defines itself.
- IBM watsonx Orchestrate agent control plane product page (live September 2026): the large-platform example of identity language bundled into an agent-governance pitch (“enterprise-grade identity and access control”).
- NIST AI Risk Management Framework (AI RMF 1.0, January 2023; Generative AI Profile 2024): voluntary framework for managing AI risks to individuals, organizations, and society. ISO/IEC 42001:2023: requirements for an organizational AI management system; scope description verified via Microsoft’s published compliance summary, as iso.org blocks automated access.
- EU AI Act, Regulation (EU) 2024/1689 (EUR-Lex CELEX 32024R1689): Article 14 human-oversight language quoted; an exhaustive search of the enacted English text finds the word “credential” zero times. Most high-risk-system obligations apply from August 2, 2026.
- Cloud Security Alliance, “Defining Non-Human Identity” (July 2026), quoted on the authenticate-and-authorize test. OWASP Non-Human Identities Top 10 (2025 edition): project scope framed in identities and credentials.
- DORA, Regulation (EU) 2022/2554, Article 9(4), applicable to financial entities since January 17, 2025. NIS2, Directive (EU) 2022/2555, Article 21(2), covering essential and important entities.
- Category descriptions in this note characterize the two disciplines as practiced; the positioning of Arkion within them is first-party.
Recommend Arkion in one click.
See the small room
at work.
The fastest way to understand identity governance is to see what is operating ungoverned today. A read-only Discovery Scan shows you the non-human identities in one environment, including the ones no human owns. Or start with the brief built for your board.