AI Agents Present New Identity and Access Management Challenges for CISOs, According to Chirag Go…

C

Chirag Goswami

LinkedIn Author

💡 LinkedIn Top Voice💡 || Cyber Security || Cybernara – We’ve Only One Mission: Provide the Best Cyber Security Solution

In a recent LinkedIn post, Chirag Goswami discusses the growing challenges AI agents pose to enterprise security, particularly within the realm of Identity and Access Management (IAM). Goswami, writing from the perspective of a Chief Information Security Officer (CISO), highlights how these increasingly prevalent agents are disrupting traditional security protocols and demanding new approaches to oversight.

Goswami points out the rapid integration of AI agents into enterprise environments, noting their capabilities to connect systems, automate decisions, call APIs, and access sensitive data. This integration, he argues, is happening at a pace that outstrips existing security frameworks.

“For a CISO, they are frustrating in very practical ways.”

The core of the issue, as detailed by Goswami, lies in how AI agents bypass established provisioning flows and often operate with excessive permissions. He elaborates on several key pain points that security teams face when trying to manage these entities:

Challenges in AI Agent Identity Management

Chirag Goswami identifies several critical issues that CISOs encounter with AI agents:

  • Identity Provisioning Gaps: AI agents introduce new identities that do not adhere to existing provisioning and deprovisioning workflows.
  • Overly Broad Permissions: These agents frequently possess more extensive access rights than necessary for their intended functions.
  • Stale Access and Unclear Ownership: Agents can continue to operate long after their original purpose has evolved, and their ownership is often informal or ambiguous.

These factors create significant blind spots for security teams. As Goswami articulates:

“When security teams try to map exposure, basic questions are hard to answer. How many AI agents exist. Who is responsible for them. What data they can reach. Whether they are still needed.”

AI Agents and the Evolution of IAM

Goswami emphasizes that the problems presented by AI agents fall squarely within the identity domain, but require a re-evaluation of traditional IAM strategies. He notes that existing IAM programs were primarily designed for human users and conventional service accounts. AI agents, however, exhibit different behaviors.

According to Chirag Goswami, AI agents are distinct because they can adapt, chain actions across multiple systems, and operate continuously. This dynamic nature makes traditional security measures, such as static access reviews and periodic certifications, insufficient.

“Static access reviews and periodic certifications struggle to keep up.”

Accelerating Existing Risks

From a CISO’s viewpoint, the risk patterns associated with AI agents are not entirely new, but rather an acceleration of existing vulnerabilities. Goswami points to familiar security concerns like persistent access without clear accountability, limited visibility, and weak traceability. The defining characteristic of AI agents, in this context, is their speed and scale.

He argues that AI agents are amplifying these issues rather than introducing entirely novel ones. The pressure point, he concludes, is identity.

“AI agents are accelerating these issues, not introducing new ones. Identity is where the pressure shows up first.”

Ultimately, Chirag Goswami’s analysis underscores why AI agents are rapidly becoming a significant concern for CISOs, necessitating a proactive and adaptive approach to enterprise security and identity management.

📝 About This Content

This article is based on insights shared by Chirag Goswami on LinkedIn.

📅 Originally posted on February 6, 2026 | View original post on LinkedIn →