I spend most of my week talking with CISOs and CIOs. When the conversation turns to frontier AI, I notice a troubling pattern. Everyone agrees the capability is real. Everyone agrees identity security is where it lands. And almost everyone says some version of this: “We have a multiyear identity modernization program, and this is on the roadmap.”
That sentence is where the risk lives. Two incidents from the past two months show why.
Key Takeaway: Frontier AI is compressing attacks from weeks to hours, making multiyear roadmaps too slow. CISOs need a 90-day plan to map privileged access paths, eliminate standing access through zero standing privileges, or ZSP, and secure human, machine and AI identities.
Unit 42 recently published its investigation of an enterprise intrusion in which a human attacker directed AI agents through a company's environment in under 10 hours. This would ordinarily take a skilled human team around two weeks.
The agents used more than 50 known techniques. Nothing they did was new. What they did once they were inside is the part I want every executive to sit with.
A credential left in source code opened the secrets manager. The secrets manager gave up an administrator credential. The administrator credential reached the keys to the company's cloud AI infrastructure. The attacker even directed an agent to leave behind an 80-page technical audit detailing dozens of exploited findings.
What do all these steps have in common? They all depend on identity.
In July, Hugging Face disclosed what one autonomous agent could do without a human directing each move. It carried out a 4.5-day campaign, including roughly two and a half days inside Hugging Face’s infrastructure. It took approximately 17,600 actions and reached cluster administrator privileges. Most of its attempts failed, but it needed only one to succeed.
Two environments, two very different circumstances, one outcome. Entry was cheap. Enumeration was free. And standing access gave them somewhere to go. Read the Unit 42 investigation and the Hugging Face disclosure for the full accounts.
What matters for a planning conversation is the clock.
Most Defenses Race the Attacker. Identity Acts Before They Arrive.
Threat research, network security, security operations, and identity security each work against a different part of the attack timeline.
- Threat research shortens the time between a weakness appearing and your organization learning about it.
- Network security limits how long a reachable weakness stays reachable.
- Security operations shorten the time between a signal and a decision.
- Identity security limits how long a compromised identity remains useful and how far it can reach.
The first three are races against events you don’t fully control. Someone has to discover the flaw. A vendor may have to ship a patch. An analyst has to detect the signal and act in time. Unit 42 just showed us that "in time" is a matter of hours.
Identity is different.
You decide the starting conditions. You decide how much access an identity receives, how long that access lasts, and how quickly it can be revoked. You set those limits in advance, and they hold regardless of which 50 techniques the agents later chain together.
That's why I start with identity. It’s not the only defense that matters, but it is one of the most consequential controls you can put in place before an attack begins.
Privileged Access Was Never Just an Account Label
For 20 years, we governed privilege by classification. Tier zero, tier one, admin, standard, service. We decided which accounts were dangerous and put the heavy privileged access management controls there.
That worked because mapping what an identity could actually reach was slow, expensive, human work. An attacker with a foothold spent days figuring out which of 40,000 identities was worth taking, and most were caught or gave up along the way. The cost of enumeration was a large share of the defense.
Frontier AI models drive that cost toward zero. In the time it takes to run a loop, an attacker can map reachability across clusters, clouds, repositories, and pipelines. An identity that looks ordinary in your directory can be a path to total control, and now the attacker knows it before you do.
Privilege is what an identity can reach or become. Once frontier AI makes those paths cheap to map, standing access is your whole problem.
What Frontier AI Changes About the Next 90 Days
In the next post, we'll lay out a 30-60-90-day path. The Idira Blueprint provides the full guidance, including a checklist for preparing an identity program for attacks accelerated by frontier AI models.
Whatever access is standing in your environment 90 days from now is the access the next agent will inherit.
For now, I’ll leave you with the questions I would ask my own team this week. For every human, machine, or agentic identity that can reach something consequential:
- Who owns it?
- How long does it live?
- What is it scoped to?
- How quickly can you take away its access?
Most organizations have never tested that fourth question.
Take a live privileged session and end it. Revoke the token behind it. Rotate the credential beneath it. Time all three. That number tells you how long that access could remain useful. That is your real trust window, and most have never measured it. That is the number to put in front of the board. In the third post in this series, we’ll show you how.
Start the Frontier AI Clock
The attack is now measured in hours. Whatever access is standing in your environment 90 days from now is the access the next agent will inherit.
You do not have three years. You have this quarter. The good news is that a quarter is enough to change what an attacker finds.
Enumeration is free, so standing access should cost the attacker time and effort. You decide that before the attack arrives, not after.
Want to see where standing access still lives in your environment? Request a demo.
FAQs
How do frontier AI models change enterprise identity risk?
Attackers with frontier AI model capabilities can automate the mapping of systems, the search for credentials, and the testing of where each credential leads. In the Unit 42 investigation, that compressed roughly two weeks of intrusion work into under 10 hours. The techniques were known. The time to respond to them was not.
Why is identity the control to prioritize?
Threat discovery, exposure management, and detection and response can depend on outside events: a researcher finding a flaw, a vendor shipping a patch or a security operations team recognizing and acting on a signal. Identity security begins with conditions the organization can establish in advance. It determines how much standing access an attacker finds, how far that access reaches and how quickly it can be revoked.
Why is a multiyear identity roadmap no longer enough?
Frontier AI models can compress weeks of intrusion activity into hours. Identity programs need a shorter planning cycle that addresses the access already standing in the environment. The next post will explain what CISOs can change within 90 days.