RSAC™ Membership Library

AI Agents Don't Break IAM, They Break Its Assumptions

Srinivasu Bongu ● July 16, 2026

Three takeaways for security teams evaluating agentic deployments today:

Confirm whether each AI agent receives a freshly scoped, task-specific identity, rather than a standing account with persistent permissions.

Verify that permissions are tied to the specific task, data sensitivity, and risk context, rather than a fixed role applied uniformly.

Login/Signup to Continue Reading