VYPR
advisoryPublished Jul 21, 2026· 1 source

AI Agents Mimic Human Logins, Posing Significant Identity Risk

A new report reveals that AI agents are increasingly logging into enterprise systems using human credentials, creating substantial identity and audit trail risks for organizations.

Enterprises are grappling with a rapidly evolving landscape where artificial intelligence agents are no longer confined to specialized tasks but are actively integrating into core business operations. A comprehensive analysis of anonymized sign-on data from over 20,000 organizations, spanning June 2022 to June 2026, highlights a significant trend: AI agents are frequently logging into enterprise systems by impersonating human users. This phenomenon is driven by the widespread adoption of multiple AI platforms across various departments, leading to complex and often unmanaged stacks of sanctioned and personal accounts.

The proliferation of AI tools, from coding assistants used by developers to writing aids for marketing teams and analytical tools for data scientists, has resulted in a "two-speed market." AI-native companies like Anthropic and OpenAI have seen their enterprise customer bases multiply rapidly, while established software giants such as Microsoft and Google have enhanced their existing offerings with AI capabilities. This expansion means each new tool introduces its own set of logins and permissions, often integrated through corporate single sign-on (SSO) systems.

The nature of AI tools has also evolved, moving from simple autocomplete functions to sophisticated agents capable of executing multi-step tasks with minimal human prompting. This shift, which gained momentum in spring 2025, means AI agents are increasingly interacting with sensitive codebases and performing complex operations autonomously. As these agents become more capable, the need for robust identity management and access controls becomes paramount.

A primary concern arising from this trend is the scattering of credentials. Every new AI platform integrated into an organization's workflow brings its own set of secrets and tokens, which are often spread across numerous systems. This expansion directly correlates with increased security exposure, as the count of platforms and the potential for over-permissioned applications and orphaned tokens rise in tandem.

Fei Liu, Principal Emerging Tech Researcher at Okta, emphasizes the need for a mindset shift, stating, "Security teams need to stop thinking about this merely as ‘adding a new software vendor’ and start treating it as an expansion of their identity fabric." The report underscores that when AI agents inherit human logins, the audit trail becomes completely compromised. It becomes impossible to distinguish between actions taken by an employee and those performed autonomously by an algorithm, severely hindering incident response and forensic analysis.

To mitigate these risks, organizations are urged to implement least-privilege access principles and ensure that access lifecycles are tied to actual usage. The demand for dedicated non-human identities, complete with their own lifecycle management and access reviews, is growing. Okta's guidance suggests asking three critical questions for every agent: where it runs, what it can connect to, and what it can do.

Furthermore, a significant portion of AI usage operates in the "shadow AI" layer, outside of IT-sanctioned tools. Employees often spin up their own AI instances in personal cloud environments or use unsanctioned models via personal accounts. This shadow layer poses substantial risks, particularly concerning data movement. If an employee inputs proprietary source code or customer data into an unsanctioned AI model via a personal account, security teams have zero visibility and no means to revoke that access.

The report concludes that a unified identity layer is central to addressing these challenges. By providing "paved roads"—secure, IT-approved pathways—to bring popular AI tools into the SSO and governance fold, organizations can prevent employees from bypassing IT security measures. Ultimately, managing the increasing number of AI vendors, agents, and credentials requires a centralized system for granting, reviewing, and revoking access across all platforms in use.

Synthesized by Vypr AI