“AI transformation is exciting. Identity hygiene is not,” said Roy Katmor, co-founder and CEO of Orchid Security. “Boards are no longer asking whether AI will be adopted—they are asking why it is not moving faster, and security cannot answer with a blanket ‘no.’ Enterprises need to observe how agents act, understand when they drift, and govern them immediately, including terminating the authority through which they operate.”
The risk does not originate in how agents behave; it originates in what they inherit. Exceeding an intended scope requires no breach of controls, because the raw material is already sitting in the environment: embedded secrets, orphaned accounts, unmanaged authentication paths, and excessive permissions. Orchid’s Identity Gap 2026 research put a number on the exposure, finding that 57% of enterprise identity is unseen and unmanaged. An agent can convert that identity dark matter into a live route to elevated access in seconds to minutes — a pace that periodic governance reviews have no realistic chance of catching or containing.
That mismatch in tempo is the heart of the issue. Quarterly access certifications and yearly attestations were built around human workers who might change roles a handful of times across a career — not around non-human identities capable of moving through dozens of applications inside a single session. Accountability today hinges on whether an organization can answer questions about an agent’s authority within minutes, rather than waiting for the next review cycle to come around.