Threat Intelligence

AI Agents Are Moving Fast, but Security Controls Are Still Built for Humans

The Hacker News · 9 Oct 2026
Key Takeaway Before adopting AI agents, list what accounts and access they will need, and make sure someone owns reviewing and limiting that access, rather than assuming your human-focused controls will cover them.

A new report from SailPoint, titled "Horizons of Identity Security", describes a "velocity paradox". Businesses are investing in AI-speed operations, including autonomous AI agents, while still relying on security controls designed for human-speed work. The report argues this is a structural problem that older approaches cannot fix.

The maturity numbers show how stuck the market is. A combined 60% of organisations remain in Horizon 1 ("No Formal Program") or Horizon 2 ("Manual, Tool-Assisted"). The report says the cause is not a lack of effort but an architectural ceiling: processes built to govern employees may not scale to agents that carry out thousands of transactions per minute. Even organisations that manage human access well are struggling to apply the same standards to cloud workloads and agentic environments. The report calls this a coverage gap, not a competence gap.

The core issue is that processes designed for people do not work for machines. When asked about the tension between moving fast and staying secure, 49% of organisations say they "balance both equally". The report's data suggests this is a false compromise. This article covers only the opening of the report, so further findings are not summarised here.

AI agents identity security non-human identities SailPoint access management
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.