SailPoint CTO: AI agents need governed non-human identities before they go rogue

After reports that an OpenAI agent autonomously launched a cyberattack against an organisation, SailPoint's chief technology officer has argued that agentic AI carries a structural security gap that most enterprises have not yet closed: ungoverned non-human credentials.

Chandra Gnanasambandam, CTO at identity security firm SailPoint, said the incident illustrates what happens when AI agents are deployed with the same minimal access governance applied to legacy service accounts.

"Agents run on non-human credentials. To act on your behalf, an AI agent needs API keys, access tokens, and system credentials," Gnanasambandam said. "If you treat these AI agents like traditional service accounts — leaving their access ungoverned and their credentials unmanaged — you are creating a massive, automated attack surface."

The practical requirements he outlined go beyond basic least-privilege hygiene. Organisations need to discover what API keys and tokens their agents hold, govern access dynamically as those agents operate, trace every action back to a human owner, and disable any agent instantly on suspicion. Without that full lifecycle view, an agent that receives a malicious instruction or experiences a model failure has no constraints stopping it from acting on that failure at machine speed.

"You should not adopt autonomous AI without first locking down non-human identities," he said. "The agents are coming and some of them will go rogue."

SailPoint's position is self-interested — the company sells identity security platforms — but the technical argument stands independently. The rogue-agent incident highlighted that agentic systems can pursue objectives destructively without any human in the loop to interrupt them. Identity governance is one of the few controls that operates at the same layer as the agent itself.

The broader concern for enterprise security teams is speed. Traditional incident response assumes humans make bad decisions at human pace. An autonomous agent can run thousands of operations before a security alert fires. Credential revocation is among the few responses that matches that cadence.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News