ARKION
Field Notes/Field Note No. 05
Field Note · Architecture

The 10 Identity Gaps
Beneath Every
Enterprise AI Agent.

The model is rarely the problem. The identity almost always is. This is the foundational map the rest of our Field Notes point back to: the ten identity gaps beneath every enterprise AI agent, and the governance layer that closes them.

Published
July 07, 2026
Category
Architecture
Read Time
8 min
Reference
FN-05-2026

Most discussions about AI security begin with the model. Prompt injection. Hallucinations. Jailbreaks. Unsafe reasoning. Those are real problems. They are also not the first problems an enterprise security team has to solve.

Before an AI agent reasons, it authenticates. Before it retrieves data, it presents credentials. Before it calls a tool, it assumes an identity. Before it performs an action, someone has trusted it.

The first security question is not whether the agent can think safely. It is a simpler one. Who is this agent?
The question most enterprises cannot answer

Today, most enterprises cannot answer that question. They know who their employees are. They know who their contractors are. Increasingly, they have no idea who, or what, is acting on their behalf. That is the identity problem.

None of this is the agent’s fault. Rogue agents are the symptom. Ungoverned machine identity is the disease. Governing that layer is what we call Non-Human Identity Governance, and the ten gaps below are what it exists to close.

The Ten Identity Gaps

Gap 01
No Verifiable
Agent Identity.
  • Most AI agents authenticate with API keys, OAuth tokens, or shared service accounts. Those credentials authenticate software. They do not identify an individual agent.
  • If two hundred agents share one credential, every action appears to come from the same identity. Security loses attribution before the first request.
  • Identity principle. Every autonomous agent should hold its own cryptographic identity.
Gap 02
Shared Credentials, Lost Attribution.
  • Developers optimise for speed. One API key. One service account. One secret in the vault. Every agent uses it.
  • When one agent is compromised, every agent behind that credential is effectively compromised, because nothing distinguishes them. Shared credentials create shared risk.
Gap 03
Nobody Knows Every
AI Agent That Exists.
  • Agents are appearing everywhere: AWS Bedrock, OpenAI, Anthropic, Microsoft Foundry, LangGraph, and internal automation projects. Many are never registered with security.
  • You cannot govern identities you cannot discover. Shadow AI quickly becomes shadow identity, and discovery is where governance has to begin.
Gap 04
Standing Privilege,
No Scope.
  • Most agents begin life with broad permissions. It is easier, faster, and it works. Until the wrong prompt arrives.
  • Identity is only half the equation. Every identity needs a scope of authority bound into it at provisioning, so what it is allowed to do is verifiable at the point of use, and can be monitored and revoked when it drifts. The test is not whether an identity can authenticate, but whether the action it is attempting sits inside the scope it was issued.
Gap 05
No Basis for
Agent-to-Agent Trust.
  • The future is not one agent. It is hundreds. Agents will call other agents, negotiate, and exchange data. Every one of those exchanges is a trust relationship.
  • Without certificate-based identity, every interaction rests on assumption instead of proof.
Gap 06
Identity Lifecycle Debt,
No Owner.
  • Human identities usually have owners. Machine identities often do not. Certificates stay active. Secrets stay valid. Service accounts outlive the workloads that needed them.
  • Agents add another layer. Without lifecycle authority, enterprises accumulate identity lifecycle debt: identities nobody remembers creating.
Gap 07
Nobody Can Prove
Which Agent Did What.
  • Every investigation eventually asks the same question. Who performed this action? With shared identities, there is no answer.
  • With unique cryptographic identities, each authenticated action is attributable to a governed identity. Identity creates accountability, and accountability creates governance.
Gap 08
Compromised Identities Stay Trusted.
  • An attacker rarely creates a new identity. They steal an existing one. If an agent holds long-lived credentials, the attacker inherits trusted access until someone notices.
  • That is why the credential, not the prompt, is often the real prize. The goal is not only to detect compromise. It is to make sure a compromised identity expires, rotates, or can be revoked fast.
  • This is the lesson from AgentJacking (FN-04): the trick was the delivery, the long-lived credential was the prize.
Gap 09
Trust Boundaries Crossed
Without a Framework.
  • Modern agents routinely operate across clouds, business units, SaaS platforms, external APIs, and partner systems. Every boundary is another trust decision.
  • Without a common trust framework, organisations manage isolated identities instead of governed relationships.
Gap 10
Identity Without a Lifecycle.
  • Employees are onboarded, reviewed, transferred, and offboarded. Agents often are not. They are created, connected, granted permissions, and then forgotten.
  • Identity without lifecycle becomes permanent trust. Permanent trust eventually becomes enterprise risk.

The Pattern

Notice what is missing from that list. Not one of the ten is about how the model reasons. Model-layer risks like prompt injection, hallucination, and poisoning are real, but almost every enterprise AI breach eventually runs through identity somewhere in the chain.

An agent holds credentials, authenticates with them, is authorized by them, and acts on them. Identity is the substrate beneath every one of those steps.

What Arkion Solves, and What It Does Not

Arkion is not a reasoning engine. It does not stop an LLM from misreading a prompt. It does not eliminate hallucinations. It does not detect every AI attack.

What Arkion governs is the identity layer beneath autonomous software:

The distinction
That is the difference between securing the model and governing the identity. The first is a real and separate discipline. Arkion is built to do the second.

Closing

Every employee already has an identity. Every server already has an identity. Every workload increasingly has an identity. The next population that needs identity governance is already here. They are your AI agents.

The open question is no longer whether they will act autonomously. It is whether they will do so with identities your enterprise can actually trust.

Arkion Research Desk
Field Note FN-05-2026 · Distributed under arkion.ai/field-notes
For questions or to discuss findings against your environment: research@arkion.ai
Related
  • This Field Note is foundational. The incident-driven notes in this series map back to one or more of these ten gaps.
  • Arkion Field Note FN-04-2026, “AgentJacking. The Trick You Cannot Stop. The Prize You Can.” The long-lived credential as the real prize (Gap 08).
  • Arkion Field Note FN-01-2026, “Six Exploits. Nine Months. One Pattern.” Credential-failure patterns across agentic-system exploits.
  • Agent platforms referenced are illustrative of where enterprise agents are being created: AWS Bedrock, OpenAI, Anthropic, Microsoft Foundry, LangGraph.
Next Step

Start with the agents
you cannot yet name.

You cannot govern identities you cannot see. A read-only Discovery Scan surfaces the AI agents and machine identities already acting in your environment. Read the brief, or run the scan.