Digital identities of AI agents cannot be managed in the same way as human or machine identities – according to Jiannis Papadakis, this requires a dedicated technology. However, he also makes it clear that the focus must extend beyond technical aspects and that the organisational security culture should be developed accordingly.
For years, great care has been taken to create secure digital identities for both people and machines and to apply them consistently. “For some time now, a new use case for digital identities has emerged in corporate networks: autonomously operating AI agents,” explains Jiannis Papadakis, “Director of Solutions Engineering” at Keyfactor, in his latest statement. He warns: “Their numbers are growing so rapidly that traditional identity and security management systems are struggling to keep up with the task of securing them in many places.” He emphasises that the digital identities of AI agents cannot be managed in the same way as human or machine identities – this requires a dedicated technology. An additional challenge is that, in most companies, it remains unclear exactly who is responsible for the identity management of AI agents. In this context, he recommends establishing binding governance structures and, to this end, bringing AI developers, identity experts and security teams together around a table – for it is only on the basis of a clear division of responsibilities that such an architecture of trust can be created, one which also permits the secure deployment of autonomously operating AI agents.
AI agents make decisions independently and operate across system boundaries
As AI agents can make decisions independently and act on behalf of their organisation across system boundaries, it is clearly essential, in order to successfully safeguard this high degree of autonomy, that every AI agent is provided with a trustworthy, unique digital identity.
According to Papadakis, the problem is this: “The identity management models that have been in use at ’Man’ and ’Machine’ for years cannot simply be applied one-to-one to AI agents.” This would, in fact, restrict their operational capabilities too much.
For human identity management systems based on static authorisations and authentication credentials, AI agents operate too quickly and too dynamically. “Even the standard tool for machine identities – a static API key – falls short.” This key grants too broad a scope of access: the AI agent is granted full rights, even though it would actually only need restricted rights for a specific task.
AI agents must be equipped with specific certificates setting out clear boundaries
Papadakis highlights a further problem: Moreover, the API key does not provide any evidence as to why an AI agent made a particular decision, whether the decision fell within the scope of its mandate, or whether the agent may even have been manipulated from outside. This key itself does not contain any technical mechanism that checks whether the agent’s autonomous decision is permissible.
“What is needed here is a solution that combines speed and dynamism with cryptography and context. Instead of a simple text-based password (API key), the agent must use ‘X.509’ certificates via the ‘Mutual TLS’ protocol. Instead of static login credentials, ‘ephemeral credentials’ must be used.”
The AI agent would therefore be issued with certificates that are valid only for a single task or for a few minutes. Furthermore, authorisation should be linked to the AI agent’s behaviour and intent. “If the AI agent then suddenly attempts to download data that does not fit with its current objective, its digital identity automatically becomes invalid,” said Papadakis.
In the event of an emergency, it must be possible to revoke an AI agent’s identity
In addition to the technical implementation of identity management, its organisational governance continues to pose a significant challenge in many companies. Responsibilities are often fragmented. Responsibility for the identities of AI agents is divided between IT, security and AI teams – “without any binding accountability”.
It is often unclear who, for example, is authorised to revoke the identity of an AI agent in an emergency. Only a fraction of companies have a formal strategy in place for this at all.
Papadakis concludes by pointing out: “What is needed here is to bring AI developers, identity experts and security teams together ’around the table’ to establish binding governance structures. Only on the basis of a clear division of responsibilities can a robust architecture of trust be created that enables the truly secure deployment of autonomously operating AI agents.”
Key findings from the DS editorial team
- In corporate networks, a new use case for digital identities is emerging alongside ‘humans’ and ‘machines’ – that of autonomously operating AI agents.
- Existing approaches to identity management are unsuitable for AI agents.
- The challenge of access rights management within organisations has always been a major one and is now becoming even more pressing.
- In addition to appropriate technical measures, such as specialised certificates for AI agents with clearly defined validity, the organisation’s security culture should also be adapted to the AI era.
- Binding governance structures, including in the context of AI, are a fundamental prerequisite for the safe deployment of AI agents.
Conclusion
AI agents require a new approach to identity and access management. Their secure deployment depends on dedicated technical controls, clear access rights, and binding governance structures.
Further information
KEYFACTOR
Vertrauen ist das Fundament unserer Welt.
datensicherheit.de, 09.07.2026
ESET-Warnung: Schadhafte AI Skills bieten KI-Agenten neue Angriffsflächen
datensicherheit.de, 28.01.2026
KI-Agenten und IT-Sicherheit: Zwei Seiten einer Medaille
datensicherheit.de, 08.11.2025
Einsatz von KI-Agenten: Lückenlose Governance für Unternehmen mittlerweile unerlässlich