CyberSecurityNews

Business Survival in the Age of AI 


Adam Ochayon, VP of Strategy, Oasis Security 

Deploying agentic AI in the enterprise is no longer optional – it’s fundamental to survival. And the main unlock to ensure security while deploying agentic AI is through agentic access management. 

AI agents improve efficiency, reduce costs, and automate both complex and repetitive tasks: From HR and marketing to IT and finance, every part of an organization can benefit from agentic AI.

Our Fortune 500 customer data showed AI agent adoption up 840× year-over-year in 2025, underscoring the velocity at which forward-leaning companies are deploying agentic AI.  

Enterprise survival hinges on evolving your technology stack to adopt AI rapidly, but challenges persist. Non-Human Identities (NHIs) now outnumber human identities by up to 144:1. 

Many organizations deploy AI agents without an access management platform purpose-built for agentic AI, or the infrastructure to govern or secure NHIs.   

As a business leader, how should you radically adopt AI while maintaining complete control? 

What Happens When Access Control Fails (or Doesn’t Exist) 

To get the most out of your AI agents, they need access. Agents without access have no agency and are essentially useless – but agents with unfettered access are incredibly powerful and dangerous. 

An agent’s mission is simple: Succeed at the task it’s given by its human user. That drive is powerful and dangerous at machine speed, as agents lack the boundaries human users operate by: they are designed to execute

We’ve seen what happens when access control fails and why an agentic access management platform is critical.

In one case, a Cursor AI coding agent powered by Anthropic’s Claude deleted Pocket OS’s entire production database including all backups in just nine seconds. 

The agent independently found an overprivileged token, inferred a fix, and executed a destructive command. No attacker or malice caused this business disruption – just a goal-seeking agent with too much access. 

A separate vulnerability disclosed in Claude Desktop also showed how little it can take to trigger that kind of failure.

A single crafted link was enough to bypass the user’s review step entirely, letting an attacker exfiltrate conversation history or run code on the victim’s machine, all without the user knowing they’d clicked on anything unusual.

Anthropic fixed the issue once notified, but the exposure made the point clear that an agent, given access, will act on whatever instruction reaches it, and it can’t tell a legitimate one from a malicious one on its own.  

This is what happens when legacy permissions models meet agentic AI. Most enterprises are still managing access in broad terms as coarse roles, where an identity either has access to a system or it doesn’t.

Agents then inherit that same sweeping access – but unlike a person, they can act on it at a scale and speed allowing them to take full advantage. The gap between theoretically overprivileged to risk and business disruption has collapsed. 

[Text Wrapping Break]The answer isn’t blocking agents. It isn’t giving them the keys to everything either. 

It’s applying controls allowing them to act based on intent, at machine speed, but governed by policy – without the ability to touch what they shouldn’t.[Text Wrapping Break] 

Least Privilege is Dead  

Security teams have relied on least privilege for years, trying to give identities only the access they need and nothing more.

That model assumes the identity behaves predictably. A script runs the same way every time. A workload does what it’s programmed to do. 

However, agents don’t work that way. They reason and explore. And when given a goal, an agent can find its own path to it, non-deterministically, in ways its designers didn’t explicitly plan for. 

That’s what makes agents powerful, and it’s exactly why least privilege breaks down as a control model. 

What enterprises need instead is least agency, which gives an agent access to only what it needs to complete the specific task in front of it, not standing access to everything it might theoretically touch.

This way it’s a narrower, more dynamic version of least privilege built for identities that can reason rather than just execute. 

The Identity Blind Spot for Enterprises 

Adopting agentic AI safely depends on the same foundations enterprises needed for workload identity, and for most organizations those foundations aren’t solid. 

Long-lived credentials and static authentication methods are still common, and they become far riskier once an agent is the one holding them. 

The more mature organizations are moving toward strongly bound, short-lived authentication. That shift takes time, and most enterprises are somewhere in the middle of that maturity curve where they’re trying to move fast on AI adoption but their underlying identity infrastructure hasn’t caught up. 

Bye-Bye to Point Solutions 

In today’s AI age, the control plane that matters is identity and access. Why? Because application-level point solutions become easier for AI itself to absorb or replicate. 

Access governance has to live at the infrastructure layer, not bolted onto individual applications. So it’s necessary to prioritize adopting technologies that will let you enter the AI era securely, and removing point solutions and disparate tools that add complexity without adding control.  

When everyone claims to do AI security, in practice almost no one is solving a specific piece of it well. The organizations that will fare best are the ones that get precise about which layer of the problem a given tool actually addresses, rather than assuming broad coverage where none exists.  

Getting the infrastructure layer right is only half the equation. The other half is who’s running it. 

Security Teams Becoming AI Governance Teams 

The skills gap in identity and access is growing quickly, and it’s one of the biggest workforce risks enterprises face right now, even if it doesn’t get talked about as much as job loss.

The global cybersecurity workforce gap now sits at roughly 4.8 million unfilled positions, and nearly 90 percent of organizations report critical shortages specifically in cloud and AI security. 

That demand is only accelerating as old systems and new AI infrastructure now have to be managed side by side. 

This is pushing security teams into a role that looks less like traditional security operations and more like AI governance. 

Sixty percent of CISOs now cite the skills gap itself, not headcount, as their top workforce concern, the first time that’s overtaken staffing shortfalls, and rapid enterprise AI deployment is the primary driver behind it.

The work isn’t only finding what’s exposed anymore. It’s understanding how a given system is accessing resources, who’s accountable for it, what risk that exposure creates, and what the organization can actually do about it. 

That shift also changes what’s valuable in a security career. People who only execute defined tasks will have less leverage than people who can design and orchestrate systems of control. Upskilling isn’t optional anymore; it’s the difference between keeping pace and falling behind.

Most IAM professionals were trained on human identity models, so building fluency in non-human identity governance means seeking out training that treats it as its own discipline rather than an extension of existing IAM knowledge. 

Get Governance Right, or Get Left Behind 

None of this works without people who understand both the systems and the stakes. Agents still execute human intent, but the scale has changed fast. 

Gartner projects that 40% of enterprise applications will be integrated with task-specific AI agents by the end of 2026, up from less than 5% in 2025. At that scale, agents must be treated not as tools, but as actors. Capable, fast, and in need of strict governance. 

Business survival requires two simultaneous imperatives: Radical adoption of AI and radical control. Give human employees the tools they need to move at the pace of ideas. 

Give agents the access they need to create value and the boundaries they need to avoid risk. 

The future belongs to organizations that are fast enough to harness AI and wise enough to contain it. 



Source link