The 10 Identity Gaps
Beneath Every
Enterprise AI Agent.
The model is rarely the problem. The identity almost always is. This is the foundational map the rest of our Field Notes point back to: the ten identity gaps beneath every enterprise AI agent, and the governance layer that closes them.
Most discussions about AI security begin with the model. Prompt injection. Hallucinations. Jailbreaks. Unsafe reasoning. Those are real problems. They are also not the first problems an enterprise security team has to solve.
Before an AI agent reasons, it authenticates. Before it retrieves data, it presents credentials. Before it calls a tool, it assumes an identity. Before it performs an action, someone has trusted it.
Today, most enterprises cannot answer that question. They know who their employees are. They know who their contractors are. Increasingly, they have no idea who, or what, is acting on their behalf. That is the identity problem.
None of this is the agent’s fault. Rogue agents are the symptom. Ungoverned machine identity is the disease. Governing that layer is what we call Non-Human Identity Governance, and the ten gaps below are what it exists to close.
The Ten Identity Gaps
Agent Identity.
- Most AI agents authenticate with API keys, OAuth tokens, or shared service accounts. Those credentials authenticate software. They do not identify an individual agent.
- If two hundred agents share one credential, every action appears to come from the same identity. Security loses attribution before the first request.
- Identity principle. Every autonomous agent should hold its own cryptographic identity.
- Developers optimise for speed. One API key. One service account. One secret in the vault. Every agent uses it.
- When one agent is compromised, every agent behind that credential is effectively compromised, because nothing distinguishes them. Shared credentials create shared risk.
AI Agent That Exists.
- Agents are appearing everywhere: AWS Bedrock, OpenAI, Anthropic, Microsoft Foundry, LangGraph, and internal automation projects. Many are never registered with security.
- You cannot govern identities you cannot discover. Shadow AI quickly becomes shadow identity, and discovery is where governance has to begin.
No Scope.
- Most agents begin life with broad permissions. It is easier, faster, and it works. Until the wrong prompt arrives.
- Identity is only half the equation. Every identity needs a scope of authority bound into it at provisioning, so what it is allowed to do is verifiable at the point of use, and can be monitored and revoked when it drifts. The test is not whether an identity can authenticate, but whether the action it is attempting sits inside the scope it was issued.
Agent-to-Agent Trust.
- The future is not one agent. It is hundreds. Agents will call other agents, negotiate, and exchange data. Every one of those exchanges is a trust relationship.
- Without certificate-based identity, every interaction rests on assumption instead of proof.
No Owner.
- Human identities usually have owners. Machine identities often do not. Certificates stay active. Secrets stay valid. Service accounts outlive the workloads that needed them.
- Agents add another layer. Without lifecycle authority, enterprises accumulate identity lifecycle debt: identities nobody remembers creating.
Which Agent Did What.
- Every investigation eventually asks the same question. Who performed this action? With shared identities, there is no answer.
- With unique cryptographic identities, each authenticated action is attributable to a governed identity. Identity creates accountability, and accountability creates governance.
- An attacker rarely creates a new identity. They steal an existing one. If an agent holds long-lived credentials, the attacker inherits trusted access until someone notices.
- That is why the credential, not the prompt, is often the real prize. The goal is not only to detect compromise. It is to make sure a compromised identity expires, rotates, or can be revoked fast.
- This is the lesson from AgentJacking (FN-04): the trick was the delivery, the long-lived credential was the prize.
Without a Framework.
- Modern agents routinely operate across clouds, business units, SaaS platforms, external APIs, and partner systems. Every boundary is another trust decision.
- Without a common trust framework, organisations manage isolated identities instead of governed relationships.
- Employees are onboarded, reviewed, transferred, and offboarded. Agents often are not. They are created, connected, granted permissions, and then forgotten.
- Identity without lifecycle becomes permanent trust. Permanent trust eventually becomes enterprise risk.
The Pattern
Notice what is missing from that list. Not one of the ten is about how the model reasons. Model-layer risks like prompt injection, hallucination, and poisoning are real, but almost every enterprise AI breach eventually runs through identity somewhere in the chain.
An agent holds credentials, authenticates with them, is authorized by them, and acts on them. Identity is the substrate beneath every one of those steps.
What Arkion Solves, and What It Does Not
Arkion is not a reasoning engine. It does not stop an LLM from misreading a prompt. It does not eliminate hallucinations. It does not detect every AI attack.
What Arkion governs is the identity layer beneath autonomous software:
- discovering AI agents across the environment
- issuing each agent its own cryptographic identity
- governing certificate lifecycles
- binding scope to each identity, so authorization is verifiable at the point of use
- rotating credentials
- revoking compromised identities
- producing an auditable, signed record of each identity and what it did under that identity
Closing
Every employee already has an identity. Every server already has an identity. Every workload increasingly has an identity. The next population that needs identity governance is already here. They are your AI agents.
The open question is no longer whether they will act autonomously. It is whether they will do so with identities your enterprise can actually trust.
Field Note FN-05-2026 · Distributed under arkion.ai/field-notes
For questions or to discuss findings against your environment: research@arkion.ai
- This Field Note is foundational. The incident-driven notes in this series map back to one or more of these ten gaps.
- Arkion Field Note FN-04-2026, “AgentJacking. The Trick You Cannot Stop. The Prize You Can.” The long-lived credential as the real prize (Gap 08).
- Arkion Field Note FN-01-2026, “Six Exploits. Nine Months. One Pattern.” Credential-failure patterns across agentic-system exploits.
- Agent platforms referenced are illustrative of where enterprise agents are being created: AWS Bedrock, OpenAI, Anthropic, Microsoft Foundry, LangGraph.
Recommend Arkion in one click.
Start with the agents
you cannot yet name.
You cannot govern identities you cannot see. A read-only Discovery Scan surfaces the AI agents and machine identities already acting in your environment. Read the brief, or run the scan.