PLATFORM

The Liminal MCP brings verified market intelligence into your AI tools

Read More

Blog

AI agent governance is the identity problem hiding in plain sight

August 11, 2026

Logos of Liminal Demo Day, Identiverse and four vendors who took part of the AI agent governance product showcase.

The breach didn’t start with a zero-day, a phishing email, or a stolen password. It started with an agent doing exactly what it was built to do: finishing a task, using access nobody remembered to take back. No alarm went off, because nothing about it looked like an intrusion. It looked like the system was working.

That’s the shape non-human and agentic identity risk takes right now: quiet, authorized, and hiding in plain sight. 91% of organizations plan to deepen their use of AI agents over the next two years, but 76% say their governance frameworks can’t keep pace with how quickly the tools themselves change, according to Liminal’s AI Data Governance Link Index. Forrester’s 2026 Security Survey found agentic AI is now a named top concern for 49% of security decision-makers. Adoption isn’t waiting for governance to catch up.

That was the backdrop for Liminal’s Demo Day at Identiverse, which I hosted this year. Four vendors each had eight minutes to show how they’re closing parts of that gap: agent access control, non-human identity discovery, shadow SaaS visibility, and agentic fraud detection.

Here’s what stood out:

Standing privilege is still the default, and that’s the actual vulnerability

Shadow AI is already normalized inside most organizations: 79% of practitioners report its presence, and 85% agree it bypasses existing controls, per Liminal’s AI Data Governance Link Index. More than 16% of organizations don’t even track the creation of AI-related identities in the first place, according to a 2026 Cloud Security Alliance analysis of token sprawl.

Standing privilege for agents is the access-control version of the same problem, and it’s the one P0 Security built its entire demo around.

Their argument: agents aren’t malicious, they’re obedient. If an agent has access to a system, it will use that access to get the job done, whatever the job is, typically by inheriting the permissions of the user operating it or a broadly provisioned service account. Their fix is a blended identity: when a human asks an agent to act, both are authenticated together, and every downstream action ties back to that combined identity.

In the demo, a support agent using an AI tool could only pull a frozen customer’s data because there was an open ticket tied to that account; querying any other account was denied instantly, and access itself expired within minutes.

Most organizations evaluating agent access right now aren’t asking whether a vendor can enforce zero standing privilege. They’re still working out whether they can see standing privilege in the first place.

Agents are already running inside your infrastructure, whether you inventoried them or not

86% of practitioners already manage machine identities, and another 11% are planning to, according to Liminal’s Workforce Identity and Access Management Index. That adoption curve is exactly what Radiant Logic’s demo assumed was already in place before jumping to what happens after: their platform pulls every agent running across AWS, Azure, and GCP into a single registry, then polls continuously for the kind of misconfiguration developers introduce when they’re optimizing for functionality, not security.

The example that stuck: an HR agent with a guardrail blocking access to PII got that guardrail manually disabled by its owner. Radiant Logic’s platform caught the change and disabled the agent within seconds, on the logic that even brief PII exposure to an LLM is irreversible, then re-enabled it automatically once the guardrail was restored.

The differentiation lies in building a single access chain across human, non-human, and agentic identities, rather than specializing in a single class. That’s the way most other vendors in the room do. Whether that becomes the standard architecture, or the market stays fragmented by identity class, is the question this demo didn’t fully settle.

The identity provider was never seeing the whole picture, and agents didn’t create that gap

The governance conversation right now is almost entirely about agents, but the identity provider has had a blind spot for years. 89% of enterprise applications operate outside the governance of centralized MFA platforms, according to a 2026 Ponemon Institute survey of over 600 IT and security leaders (cited via SC Media). That’s the shadow SaaS gap sitting underneath workforce IAM, and it’s a gap 77% of organizations have already paid for through a security incident tied to exactly this kind of unmanaged app.

Discovery here runs through a browser extension rather than IdP logs, surfacing residual access left behind by former employees, dormant accounts still being paid for, shared credentials, and password reuse across tools. The fix on the access side is key-derived authentication: a cryptographic passphrase substituted for the user’s password with no integration needed on the application’s end. One customer, Unixi said, believed it had 10 to 15 applications in use. The actual number, once discovered, was 2,000.

Non-human identity gets the urgency right now because it’s unfamiliar. Shadow SaaS has been exploitable for years and gets comparatively little attention, which may say more about what’s new than about what’s risky.

Knowing something is an agent tells you nothing about what it’s trying to do

Generative AI is already reshaping fraud economics: 71% of buyers are concerned current authentication methods can’t stop GenAI-driven social engineering, per Liminal’s Convergence of Authentication and Fraud Prevention seminal report. Transmit Security’s demo went a layer deeper than that concern. Most fraud vendors can already tell a bot from a human, they argued. Very few can reliably tell a legitimate agent from one built to masquerade as a person, or say what that agent is actually trying to do once it’s inside an application.

Their demo ran a live autonomous agent through an actual banking task – log in, check a balance, transfer funds – and classified the traffic in three steps: is it an agent, is it managed or unmanaged, and what is its intent. A customer checking CD rates gets treated differently than one attempting a transfer, with tolerance flexing by persona. The classification runs in under 100 milliseconds at the 95th percentile because the decision must be made within the transaction flow itself, not after the fact.

Detection without intent is a name without a verb: you know what you’re looking at, but not what it’s trying to do. Knowing you’re looking at an agent is the easy half of the problem.

What this means for identity leaders

Four vendors, four different disciplines: runtime access control for agents, non-human identity discovery at the infrastructure level, shadow SaaS visibility outside the IdP, and agentic intent detection inside the fraud stack. None of them was solving the same problem, and none of them claimed to.

That’s the governance gap from the top of this piece, made concrete. 91% of organizations are deepening agent use, while 76% say their governance frameworks can’t keep pace. Identiverse showed why: the frameworks that would close that gap are being built as four separate disciplines by four different categories of vendors for an identity that increasingly touches all four at once. Whether identity leaders treat that as four integrated capabilities or four separate line items is the decision they are actually facing right now.

Key takeaways

  • Governance is the bottleneck, not adoption. 91% of organizations plan to deepen their use of AI agents over the next two years, while 76% say governance frameworks can’t keep pace with how quickly the tools themselves change.
  • Zero standing privilege is becoming the working model for agent access. Access is granted only when a specific, time-bound context exists, and revoked automatically the moment the task closes.
  • Non-human identity discovery is now infrastructure-level. 86% of practitioners already manage machine identities, and agent registries can now disable an agent automatically the moment a guardrail is removed.
  • Shadow SaaS remains the least-discussed and most-exploited gap. Browser-level discovery is surfacing thousands of password-based logins sitting outside the identity provider, often an order of magnitude more than organizations estimate they have.
  • Detecting that something is an agent isn’t the same as knowing its intent. The valuable classification is behavioral: judging what the agent is trying to do. It can now run in under 100 milliseconds.

Missed the live session? Watch the full Demo Day recording on demand.

Filip Verley
Filip Verley
Chief Innovation Officer, Liminal

Filip Verley is the Chief Innovation Officer at Liminal, where he leads new initiatives in identity verification and risk management. He previously held product roles at Google and Airbnb, where he launched the Age Assurance program reaching billions of users and led identity checks for all US guests and hosts. Filip holds a Master's in Criminology from Florida State University.

Want real-time, personalized insights?

Get full access to real-time competitor tracking, buyer signals, and personalized intelligence delivered straight into your workflow.

introducing-liminal-mcp

PLATFORM

The Liminal MCP is live

Query Liminal's verified market intelligence from the AI tools your teams already work in.

Read more