* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* Why Agentic AI Forces a Reckoning with Identity

# Why Agentic AI Forces a Reckoning with Identity

![Why Agentic AI Forces a Reckoning with Identity](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Agentic-AI-Forces-featured.jpg)  
**By [Carey Frey](https://www.paloaltonetworks.com/perspectives/author/carey-frey/ "Posts by Carey Frey")** | **6 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Why Agentic AI Forces a Reckoning with Identity\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fwhy-agentic-ai-forces-a-reckoning-with-identity%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/why-agentic-ai-forces-a-reckoning-with-identity/?pdf=download&lg=en&_wpnonce=8c35f4dfea "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/CareyFreyHeadshot2026.jpg)  
  Carey Frey is a Canadian technology executive working to advance the cybersecurity industry, driven by a passion for creating a more secure digital world for everyone. As Chief Security Officer for TELUS, a world leading communications technology company in Canada, he is responsible for delivering corporate programs securing the company's global assets and delivering managed cybersecurity services to TELUS customers. Prior to TELUS, Carey served in the Government of Canada at the Communications Security Establishment in a variety of technology, intelligence and cybersecurity leadership roles bringing security innovation to federal departments and building collaborative relationships with global information and communications technology companies. Carey is an active contributor to the broader cybersecurity ecosystem, having served as Chair of the Cambridge Forum on Canadian Cyber Security and the Industry Co-Chair of the Canadian Security Telecommunications Advisory Committee (CSTAC). In addition to his industry leadership roles, Carey is a 7 year member of the TELUS Ventures Investment Review Committee, served on the board of ZenEdge and is active in the Security Innovation Network (SINet) helping to select the annual innovator awards (SINET 16). A native of rural Saskatchewan, Carey holds a Master's Degree in Public Policy and Public Administration from Carleton University and a Bachelor of Science Degree in Computer Science from the University of Regina....

[Learn more](https://www.paloaltonetworks.com/perspectives/author/carey-frey/)

## IN THIS ARTICLE

For the better part of two decades, identity has been the third rail of cybersecurity. Addressing identity is the project that every CISO knows is necessary, but few want to touch. It is messy, political and fraught with the turf wars of legacy infrastructure. HR leaders claim they are the source of truth because they hire the talent, but finance leaders claim they are the source of truth because they cut the checks. The security leader, who's caught in the middle, often decides that fixing the firewalls or the SIEM is a safer bet than untangling the Gordian knot of user access.

The luxury of avoidance is gone. We are approaching a new era where artificial intelligence has evolved beyond a mere tool into an agent that acts on our behalf. With agentic AI, the fractured state of our identity infrastructure will become an existential vulnerability.

## The Great Pivot from Malware to Impersonation

To understand why identity is the new perimeter, we must look at how the adversary has evolved. Years ago, the primary threat was malicious software --- viruses and worms trying to breach our defenses. Today, the landscape has shifted entirely.

The modern adversary is a pragmatic business person. They have realized that reverse-engineering technology and hunting for zero-day vulnerabilities is expensive and time-consuming. It is far cheaper and infinitely more effective to simply steal a credential.

Current data suggests that over 80% of breaches now involve compromised identities.^[1](#foot-note)^ Attackers are living off the land, logging in with legitimate credentials and moving laterally through networks undetected. Simply put, they don't need to break down the door if they already have a key.

This reality was already a crisis before the arrival of generative AI. Now, as we build a new foundation of AI agents on top of this shaky ground, we are compounding the risk.

If we do not solve for identity first, the AI revolution will crumble.

## The Agentic Dilemma: The Source of Truth

The core challenge of agentic AI is agency itself. We are moving from chatbots that answer questions to autonomous agents that perform tasks such as buying software, updating code or transferring funds.

This challenge creates a profound problem of attribution. When an action happens within your network, who or what is responsible?

* **Scenario:** Imagine an AI agent, called Agent One, is assigned to an employee to manage their inbox. If Agent One deletes a critical, legal hold or authorizes a wire transfer, the audit trail becomes murky. Was it the human employee, the agent acting on a hallucination, or a threat actor who hijacked the agent?
* **Identity gap:** Most organizations today simply do not have the infrastructure to answer these questions. They lack a cryptographic root of trust for these nonhuman entities. If an agent is ephemeral, spun up for a task and then vanished, how do we maintain a history of its actions?

Without a robust identity framework, we cannot implement a true zero trust model for AI. We need agents to prove who they are, just as we require of our employees.

## The Solution: AI-Native Identity Fabric

We cannot rip and replace the legacy identity systems of the past 30 years. The investment in Active Directory, HRIS systems and mainframes is too deep. Instead, we must abstract above them. We need to move from a fragmented, east-west view of identity silos to a unified, north-south control plane.

This concept is what an **AI-Native Identity Fabric**represents.

* **Data plane:** We ingest identity data from every source --- HR Workday systems, contractor databases, IT directories and cloud IDPs --- into a single, normalized layer.
* **Intelligence layer:** On top of this data, we apply AI to act as the observer. The scale of machine-to-machine interaction is too fast for humans, so we need AI to monitor AI.
* **Automated governance:** This fabric enables us to spot anomalies at machine speed. If an employee leaves the company, the system shouldn't wait for a weekly batch process to revoke access. The AI, seeing the signal from HR, should instantaneously cut off the agentic access associated with that identity.

## Defining Good in an Era of Chaos

For leaders staring down this transition, the path forward can feel paralyzing. The technology is moving faster than the standards bodies can keep up. However, paralysis is not a strategy.

We recently collaborated with a network of CISOs to develop a maturity model for this exact problem. The findings were stark, indicating [95% of organizations](https://www.csoonline.com/article/4109999/agentic-ai-already-hinting-at-cybersecuritys-pending-identity-crisis.html) have not yet seriously considered how to map identity to AI agents.^[2](#foot-note)^

To avoid being part of that statistic, security leaders must take three immediate precautions:

* **Inventory the invisible:** You cannot protect what you cannot see. Do you know how many AI agents are currently operating in your environment?
* **Establish delegated authority:** You need to design fine-grained permissions for agents. Just because an agent manages your calendar does not mean it should have the authority to email the CEO. You need human-in-the-loop thresholds. For example, an agent might pay an $89 invoice automatically, but a $250 or $500 invoice requires human approval.
* **Assess maturity:** Use available guidance to baseline your current identity hygiene. If you are struggling to manage human access today, you are not ready to manage machine access tomorrow.

## The Optimism of Necessity

There is a silver lining to this urgency. Because the risk is so high, the third rail is finally being touched. Boardrooms and investors now understand that identity is one of the foundational elements of trust in the AI economy.

We have a brief window to lay the groundwork. We won't perfect it immediately, but we can avoid the worst-case scenarios. By treating identity as a data problem and leveraging AI to solve it, we can build an architecture that both withstands the future and empowers it.

To hear more from Carey Frey, tune into ["The Kill Switch for AI Agents" episode](https://www.paloaltonetworks.com/resources/podcasts/threat-vector-the-kill-switch-for-ai-agents) of the Threat Vector podcast.

*** ** * ** ***

^1^"[Stop Identity-Based Threats Today](https://www.crowdstrike.com/en-us/resources/infographics/identity-security-risk-review/)," CrowdStrike, April 8, 2024.  
^2^Evan Schuman, "[Agentic AI already hinting at cybersecurity's pending identity crisis](https://www.csoonline.com/article/4109999/agentic-ai-already-hinting-at-cybersecuritys-pending-identity-crisis.html)," CSO, December 23, 2025.

* [AI](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=ai)
* [Identity](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=identity)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://www.paloaltonetworks.com/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://www.paloaltonetworks.com/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://www.paloaltonetworks.com/perspectives/weaponized-intelligence/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/RFP-Bottleneck-featured.jpg) BLOG

### AI

**From Weeks to Minutes: How We Applied an AI-First Transformation to the RFP Bottleneck**

Understanding why manual efforts burn hundreds of hours and are bottlenecki...

[Sandeep Uttamchandani](https://www.paloaltonetworks.com/perspectives/author/sandeep-uttamchandani/ "Posts by Sandeep Uttamchandani")
[](https://www.paloaltonetworks.com/perspectives/from-weeks-to-minutes-how-we-applied-an-ai-first-transformation-to-the-rfp-bottleneck/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
