AI is becoming a true workforce of autonomous agents. To avoid security breaches, businesses must manage their identities and access as rigorously as real employees.
AI is no longer an experiment; it is now an expected standard. Furthermore, in many companies, it is already anchored in daily tasks, integrated into employee tools and, increasingly, incorporated into systems that operate discreetly in the background. What distinguishes this stage from previous ones is not only the speed with which AI is deployed, but the depth with which it is now at the very heart of work processes.
The “Trend of AI” study conducted by KPMG revealed that, among the 60% of organizations that have already integrated AI into their activities, an average productivity increase of 33% was observed following the integration of AI agents into daily tasks. Teams are discovering new levers to gain agility, automate repetitive tasks and extract analyzes that previously would have required much more time. However, as AI becomes more firmly established within companies, they must be more rigorous in their management, particularly in terms of identity and security.
From AI tools to a digital workforce
So far, most of the debate has focused on the use of AI by humans. Assistants and other “co-pilots” who support employees have been in the news, and for good reason: they are radically transforming the way we write content, develop code, analyze data, and communicate with each other.
However, a more discreet transition is underway: AI is almost becoming a full-fledged collaborator. Indeed, we are only at the beginning of autonomous AI agents capable of performing tasks independently, accessing applications, extracting data and making decisions with little to no human intervention. While it’s tempting to see this as just the simple evolution of assistants, in reality they are fundamentally different. These agents behave as true independent actors within the system and must have their own identifiers and authorizations. This development is crucial, as the majority of companies continue to treat these agents as simple software.
The critical delay of identity systems
For decades, identity and access management (IAM) has been based on a simple principle: the user is generally a human being. Even when companies extended IAM to service accounts and machine identities, these remained tied to predictable systems, confined to specific, repetitive tasks.
Autonomous agents are disrupting this model. They are adaptive, perform their tasks flexibly and heterogeneously, operate at machine speed, and can interact with many more systems than an employee ever could. Yet many organizations are still trying to force them into frameworks that were never designed for independent, decision-making digital workers. A growing gap between the behavior of these agents and the governance of their identities results, thus creating gray areas that hackers are already ready to exploit.
Recruiting AI without a human resources system
This gap manifests itself from the moment an organization attempts to integrate an autonomous agent. When a new employee joins the company, HR systems automatically trigger the creation of their identity: roles are assigned to them, their access is configured and their responsibilities are clearly defined. There is an official record of the identity of this person, their missions and their hierarchical superior.
Autonomous agents arrive without any of these structures. They are created by developers, integrated into workflows, or introduced through new platforms, most often without central visibility or consistent process. There is no HR system for AI, no designated manager by default, and no guarantee that anyone will be held accountable for this agent’s access or actions.
This is precisely where identity governance must evolve. Organizations must be able to detect these agents, register them and assign them their own identities, linked to a clearly identified business manager. Each autonomous agent should have a referent capable of explaining its reason for existence, its missions and the systems with which it is authorized to interact. Without this fundamental foundation, it becomes difficult to answer the most basic questions: how many agents are active? Who is responsible for this? Are their accesses always justified? etc.
Governing digital workers at machine speed
Once deployed in the system, the real difficulty consists of supervising their actions and their scope of intervention. It’s easy to focus on securing models or code, but governance is ultimately about managing identities and privileges in alignment with business objectives.
If an agent is capable of acting on behalf of the company, their identity must be administered even more rigorously than that of an employee. Indeed, AI agents operate autonomously, continuously, and cross trust perimeters at a speed and scale specific to machines. This makes any granting of excessive privileges particularly dangerous.
AI has profoundly transformed the identity security paradigm. High-privilege actions are proliferating across hybrid ecosystems, from on-premises to cloud, database and SaaS, and organizations have lost the central point of control they once relied on. Companies must evolve towards dynamic and ephemeral models. The use of time-limited credentials, just-in-time access, tightly bounded permissions, and continuous monitoring helps ensure that agents complete their tasks at the right time, without holding more authority than necessary. This approach promotes innovation while limiting the area of impact in the event of an incident.
Offboarding: the risk of the forgotten digital workforce
Just as crucial as onboarding and governance, the exit process is a key step. When an employee leaves the company, their access is revoked and their accounts closed. On the other hand, an agent can be quietly decommissioned, replaced by a new tool or simply forgotten. Without adequate monitoring, this identity can persist, retaining access that it no longer needs. An unmanaged agent, whose privileges persist, then becomes an easy target and an invisible entry point to critical systems. It is therefore essential to extend detection and lifecycle management processes to identify inactive or “orphan” agents, in order to remove them without delay.
With 73% of French leaders with a keen interest in AI agents, the companies that succeed will be those that move from treating autonomous agents as mere background software to truly treating them as digital employees. They will set up integration processes in close collaboration with HR departments, deploy governance models capable of keeping up with the frenetic pace of automated activities, and apply exit procedures that leave no door open.