AI Agent Identity Crisis: Companies Struggle with Accountability
As companies increasingly rely on AI agents for production tasks, they're struggling to determine who's accountable when an agent goes wrong. IBM says securing the agentic enterprise starts with identity management. In a typical enterprise, machine and agent identities already outnumber human ones by over 100 to 1, and this ratio is growing as more agents are deployed.
IBM recommends that every agent should have its own verifiable identity, and every action taken by an agent should be traceable back to the human responsible. Access to sensitive data or systems should also be continuously checked, not granted once and forgotten.
Vault 2.1 is IBM's solution for managing identities in agentic environments. It extends the agent registry and identity-based policy controls into a fuller runtime enforcement model, ensuring that agents can't access more than they're authorized to.