Skip to main content.

Who's the User Now?

Agentic AI isn't a new attacker. It's a new kind of user your identity model never named. It lives in the seams, the way bedbugs do.

The 2026 takeaway. Agentic AI, autonomous systems that act, not just recommend, has moved to the top of the CISO threat list: in one industry poll, 48% of security pros named it the #1 attack vector heading into 2026, ahead of deepfakes and passwordless adoption. The practical problem isn’t “do we use AI agents.” It’s “who or what holds the permission to act in our systems, and who answers for it when it does?” That’s an identity problem wearing an AI costume.

I inherited a ticket once that had been sitting for eight months. Multiple comments, each one angrier than the last, ending with the immortal line: “On hold until we hire a SME to figure this stupid shit out.” The engineers had poked at it, shrug-shouldered it as outside their expertise, and left it to fester like mystery meat in the office fridge.

The fix was a one-liner. An .htaccess change. But that’s not the interesting part. The interesting part is that for eight months, that ticket lived in the space between teams. It wasn’t ours. It wasn’t theirs. It was the thing in the gap that nobody claimed. Nobody looked at it and said, “This is mine. I own this. I’ll fix it or I’ll die trying.” Maybe not that dramatic, but you get it.

I’ve been thinking about that a lot lately. Because the tickets I keep getting walked into now look exactly like that eight-month pile. Except the “user” on the other side isn’t a user. It’s a bedbug. And it didn’t check in at the front desk, and I can’t exactly open the couch and shake it out.

It’s complicated, so bear with me.

The user used to be a user#

Let’s take a breath. For a long time, “the user” was a person. A human. With a name, an ID, a badge, a password they forgot on a Tuesday and reset at 8:03 am, and an MFA prompt at 8:08 am. Identity meant a human. The perimeter was fuzzy, yeah, but the actor was usually a meat popsicle with a username, and if it did something silly we could, at least, find the person and laugh with them.

That assumption, that the thing on the other side of the API call is a person, is now a lie in a lot of organizations.

Enter the thing that’s not a person#

Agentic AI is the name on the tin, but “agent” is doing a lot of soft-pedalling, the way “Casual Friday” does a lot of soft-pedalling for “you’ll be wearing a blazer and sweating at 25°C.” An agent doesn’t advise. It acts. It executes, pulls data, moves files, talks to other systems, opens a ticket, drafts the reply, maybe submits the invoice. All with permissions that would make a senior engineer’s jaw drop, and often with less oversight than a fresh hire gets in week two.

When you built the IAM model, you had one question at the center of it: who is this request from? You built the whole edifice, MFA, RBAC, service accounts, conditional access, around that question. The system answers it by looking at an identity. A credential. A user.

So the agent comes knocking. It presents its credentials. It’s not a user. It’s not a service account, either. It’s a new category of user we’ve decided to file under “service account” because that was the closest shelf we had. Your system is going to treat it like one, because that’s the only category you ever made. Convenience won.

The numbers back up the mess. Roughly 90% of the AI incidents I see already involve an agent or a GenAI workflow. Meanwhile, only about one in ten organizations has an actual strategy for non-human identities. You’re running a population of agents your IAM team can barely name, on top of a security model that was primarily built for people.

The bedbugs in the seams#

The bedbugs get into the couch. They tuck into the stitching, the folds, the crack where the baseboard meets the floor. They don’t camp out in the open where you can see them. They live in the seams. In the little dark gaps between one piece of furniture and the next.

That’s exactly where these agents live. In the space between the team that builds the identity, the team that consumes the identity, and the team that pays for the identity. The seams.

It’s not just your agents. Bedbugs travel. Someone lugged a box into the room, or a vendor left through the back, and now there are agents other teams spun up because the business wants the AI to do things now, and identity wasn’t a checkbox on their launch plan. Shadow agents. Agents with more permission than the manager who requested them. And as it turns out, agents that remember. Persistent memory is its own whole threat, because once you can poison the memory, you don’t need to break in.

You just wait for it to feed again.

Here’s the thing about bedbugs. You can spray them. I’m sure your facilities team will bring a can to the next steering committee. And it’ll work, for the ones you can see. But the rest are in the stitching, breeding in the dark, feeding when you’re asleep. The spray doesn’t reach what you can’t see.

You can’t see them until someone owns the mess. Until someone looks at the four teams in the loop and says “this thing is mine, I own its lifecycle, I own its permission, I own its audit trail.”

The fix for most of the problems I see in the wild is not a new can of spray. It’s a one-person decision that nobody made: this is my bug, this is my couch, this is my problem to own. And you can’t make that decision if the four teams in the loop are still waiting for someone else to call the meeting.

The seams where this breaks are predictable:

  • Security assumes an agent is a known identity.
  • Platform/Eng assumes the agent’s permission was set at creation and stays set. (The way a wrinkly shirt was supposed to stay “a minor faux pas” and not “a major faux pas.”)
  • Data assumes the agent reads what it’s allowed to read, and never writes.
  • Finance assumes an agent that submits a transaction is somebody. (It’s not. It’s a something.)

Nobody in that loop owns the agent, as a first-class identity, with its own lifecycle, its own least-privilege, and its own audit trail. Which is to say: the eight-month ticket, again. Different config file. Same “not my problem.”

What “the user is a person” actually costs you#

The eight-month ticket didn’t end because someone found a clever fix. It ended because someone stopped waiting for the other team to exist. The “user” in that ticket wasn’t a person, either. It was a symptom: the thing that happens when nobody owns the seam. And that’s exactly where the agent lives. It’s not a new attacker. It’s the newest, most capable symptom you’ve got, and your identity model still can’t name it.

So this week, ask your team one question, and don’t let the answer be “we’re looking into it”:

If an agent in our environment could do X, who owns that agent’s identity, its permission, and its audit trail, and can they show me in under ten minutes?

If the answer is three departments and a spreadsheet with a broken link, the bug is still in the stitching. You just haven’t named it yet.

Saying “this couch is mine, and the bug in it is mine to deal with.” is the actual job. It’s not a new tool. It’s a decision nobody decided to own. Give it a name, then flip the couch over.


Further reading, if you want the receipts: