Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»The new identity challenge: securing AI agents through API governance (Page 16)
Cyber resilience

The new identity challenge: securing AI agents through API governance

There seems little doubt that AI agents will be transformational for organizational operations in 2026, but their trusted status requires strong API governance to ensure safe use.
January 13, 20266 Mins Read
Agentic AI Network workflow concept - Multi AI agents connected in a shape of a digital brain

By Glyn Morgan

Lately, there has been a growing conversation about how society assigns status and responsibility to non-human entities, particularly artificial intelligence agents. The notion of treating AI agents as if they were employees may sound abstract, but it cuts straight to the heart of an emerging security dilemma. From an API security perspective, the growing presence of AI agents across the enterprise makes it imperative to secure the API fabric, the action layer of AI where every workflow and decision occurs.

The next evolution of digital transformation is being driven by intelligent agents that will act autonomously on behalf of users, customers, and organizations. They will access systems, retrieve and process sensitive data, and perform operational tasks. Crucially, they will do all of this through APIs. In other words, these agents will be functioning as trusted insiders, equipped with credentials and permissions that allow them to interact with critical business infrastructure. The question therefore becomes: are we ready to manage and secure this new class of digital identities?

Why identity governance must evolve

At present, most identity and access management frameworks are built around human users. Systems and governance structures have evolved over decades to manage people: employees, contractors, and partners. They include role-based access controls, onboarding and offboarding procedures, behavioural monitoring, and audit trails. These mechanisms work precisely because they were designed to anticipate human behaviour, human error, and human risk.

AI agents, however, do not behave like humans. They are faster, more scalable, and can proliferate rapidly across systems. They can also be deployed by individuals or by other systems without central oversight. In effect, they represent a new insider population, effectively invisible to many of today’s monitoring and control frameworks. Without rigorous identity and API governance, the new control plane for these ‘machine insiders’ could easily become unmonitored conduits into an organization’s most sensitive environments.

It’s an issue that is no longer theoretical, either. APIs have already become one of the most targeted vectors for attackers. They serve as the connective tissue of digital business, enabling applications, services, and now AI models to exchange data and functionality. Yet, APIs are often inconsistently secured, documented, or monitored. Attackers understand that compromising an API key can yield the same access as compromising a human account, but without triggering the same alert mechanisms. The introduction of AI agents using APIs at scale understandably multiplies that risk.

Extending zero trust to non-human identities

In this context, the concept of zero trust takes on renewed importance. The principle of ‘never trust, always verify’ must now apply not only to users and devices, but also to machine identities. Every agent should be treated as potentially untrusted until proven otherwise, with authentication and authorisation verified continuously. Moreover, the principle of least privilege must be rigorously enforced. AI agents should only be granted the minimum permissions necessary to perform their assigned function; and those permissions should be reviewed or revoked as soon as they are no longer required.

Governance is another critical dimension. Organizations must establish clear policies for how AI agents are provisioned, managed, and audited. This includes assigning ownership and accountability: who is responsible for an agent’s actions, for maintaining its credentials, and for monitoring its behaviour. In many cases, the lifecycle of an agent may be far shorter than that of a human employee, but its ability to access and manipulate data is no less consequential. The same rigour applied to user identity management, e.g. privilege reviews and compliance audits must be extended to these digital counterparts.

Resilience through control and visibility

A further consideration is resilience. Even with strong controls, incidents will happen. AI agents could be compromised, misconfigured, or manipulated through adversarial inputs. The objective, therefore, is not only to prevent breaches, but to ensure that when one occurs, it can be detected quickly and contained effectively. Continuous monitoring, anomaly detection, and API threat protection are all essential to this resilience model. Visibility into how and when agents are interacting with systems provides the forensic insight needed to maintain trust in automated environments.

Building a secure digital workforce

There is also a cultural aspect to this shift. As organizations begin to integrate AI agents into their operations, they must move beyond seeing them as experimental tools and start treating them as full participants in the digital workforce. This involves extending corporate policies, ethical frameworks, and even security awareness to encompass non-human entities. The language of ‘employment’ may feel metaphorical, but it captures the responsibility inherent in granting autonomy to a machine. Every credential issued to an agent is a delegation of trust and that trust must be governed as carefully as any other.

The security industry has long grappled with the insider threat. Traditionally, this has meant guarding against disgruntled employees, negligent contractors, or compromised user accounts. The rise of machine insiders demands a parallel mindset that recognises the potential for harm through automation and scale. A misconfigured AI agent could exfiltrate data in seconds or overwhelm systems with unintended requests. The impact of such errors will be amplified by the sheer speed and scope of machine capability.

For organizations preparing to embrace this next wave of AI integration, the path forward lies in convergence. Identity, API, and AI governance cannot remain separate disciplines. Security teams must develop unified frameworks that cover both human and non-human identities, enforcing consistent standards for access, authentication, and monitoring. APIs should be treated as critical infrastructure, not as ancillary code, and should therefore be subject to continuous testing, discovery, and protection.

In essence, resilience in the age of machine insiders will depend on how effectively we extend human-centred security doctrines to non-human actors. Zero trust, least privilege, and continuous governance are not abstract principles – they represent the mechanisms through which we can enable innovation, and do so safely. As AI agents become integral to how organizations function, the challenge is not merely whether to trust them, but how to structure that trust intelligently, transparently, and securely. The future of cybersecurity will hinge on this balance between empowerment and control. Just as we once learned to manage the risks of human insiders through culture, technology, and policy, we must now apply the same diligence to the digital workforce we are creating. The difference is that this time, the workforce operates at the speed of code.

The author

Glyn Morgan is UK&I country manager, Salt Security.

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleThe Internet of Stranger Things: managing IoT risks
Next Article Zero trust and the trouble with trusted vendors

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Digital Europe map with stars, symbolizing EU cybersecurity and technology.

ENISA releases guidance to help organizations develop successful cyber security exercises

February 19, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?