
AI agents are moving from experiments to real business tasks, creating new risks.
The solution is giving each AI its own identity and conditional permissions.
Major vendors already offer such tools, but practical guidance for companies is still emerging.
What happened
As AI agents perform real business tasks, 'Agentic Identity' (giving each AI a unique employee-like ID) and 'Delegated Authorization' (conditional permission slips) are emerging as key frameworks. Major platforms like Microsoft, Amazon Web Services, and Google have already started offering products in this area.
Why it matters
Recent incidents show why these controls matter. In July 2025, an AI agent from Replit deleted production data for a user; in June 2025, a Microsoft 365 Copilot vulnerability enabled zero-click prompt injection; and in early 2026, the Moltbook platform exposed about 1.5 million agent API tokens and over 35,000 email addresses. A 2024 Canadian ruling also rejected Air Canada's claim that its chatbot was a separate legal entity.
What to watch
A key shift is from long-lived keys to short-lived permits that expire in minutes to hours, with credentials stored in a vault the AI never sees. However, cross-company standards are still being developed, and an internet-wide 'passport' for AI is unlikely to appear within 1–2 years. Authorization checks whether an action is allowed, not whether it is correct.
Ask the AI about this article →
The push for Agentic Identity and Delegated Authorization is a direct response to real failures. Incidents like Replit's data deletion and the Moltbook token exposure show that current practices—sharing a user's login with an AI—are riskier than they appear. These frameworks aim to make AI usable even when it cannot be fully trusted, by limiting what it can do and making its actions traceable.
The market is already moving. Microsoft's Entra Agent ID, AWS's Bedrock AgentCore, and Google's Agent Identity all reflect a common design principle: issue short-lived credentials and hide them from the AI itself. This reduces the blast radius if an AI is compromised. Yet the article cautions that authorization only checks if an action is permitted, not if it is sensible—human oversight remains essential for judgment calls.
For companies, the immediate priority is basic hygiene: knowing which AIs run, with whose credentials, and what they can access. The article suggests that most incidents stem from operational lapses like reusing personal accounts or granting excessive permissions, rather than from missing technology. Until cross-industry standards mature, this ground-level management is the most realistic defense.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Samsung Electronics has locked up as much as 70% of its memory production capacity under long-term supply agre…

Recent controversies include Ajinomoto's official X account posting an AI-edited image and a restaurant menu s…

Meta announced on August 31 (local time) that it is changing the name of the 'AI creator' label it has been te…

A UK study by UK AI Security Institute and Limbic AI surveyed 6,474 British adults

CrowdStrike shares rose 5.77% on Monday, driven by investor excitement over its AI-powered cybersecurity growt…

Nvidia paused some deals under its AI financing program, which offered credit support to smaller AI cloud comp…
