TechForge

January 27, 2026

  • Existing Identity Access Management systems unsuitable for agentic AI rollouts.
  • “A recipe for secrets and data leakage.”
  • Security certs and least-privilege models should apply to agent instances.

Controlling identity – people, machines, networks – is a central component in zero-trust environments, and controlling who and what can access specific resources is the key to maintaining the best possible cybersecurity posture.

Teleport‘s identity stack is one of many products that follows a zero-trust, cryptographic system of identity control that’s positioned to replace older identity management infrastructure. Its addition of particular controls governing the use and development of AI agents means companies can prepare for their AI future more safely in security terms.

Most organisations will have some form of identity and authentication provision, be it Okta, Entra ID, or similar SSO that gives them role-based access tied to identity. Teleport claims its next-generation IAM will integrate with most existing solutions, and also cover a cybersecurity team for policy formulation, log auditing, monitoring, and response.

The company claims its machine and workload identity solution brings its security methods to AI agents, so treating each instance of autonomous agent like any other user or device. This allows cryptographic authentication methods (such as dynamic certificate issuance/revocation) to determine agents’ privileges and boundaries instead of static, un-managed API keys or secrets. The company states that traditional identity systems “break” when applied in the context of agentic AI. It says legacy IAM isn’t up to standard for dynamic, autonomous workloads.

The principles of zero trust (least-privilege access, the granting of only short-lived privileges) are applied to individual agents in the same way as users, machines, subnets, etc., and each agentic AI similarly creates an audit trail detailing its activities in production environments.

Teleport frames static credentials and ‘traditional’ IAM as an “unmanaged attack surface” that can easily increase risk to the organisation without specific controls applied to agents.

By providing audit logs, session recordings, identity, and behavioural telemetry, the company’s platform takes away some of the risk inherent in deploying agentic AI in the enterprise. In short, agents will not be allowed to access un-proscribed materials, and act within predefined boundaries at all times – in much the same way that human users are given only access to the parts of the organisation’s digital real estate they’re permitted to.

This prevents companies from having to reconfigure their existing identity management systems to allow for agentic AIs’ workflows. It also provides a governed MCP and LLM control plane which effectively limits AI’s scope of access. Organisations with several different AI projects happening concurrently (run by different departments, for example) will be bound by an overarching set of security guardrails. Individual stakeholders and automation project leads can therefore proceed with their rollouts, as free of security concerns as possible.

The company’s survey of 200+ infrastructure leaders revealed that 69% of those queried said AI adoption would require significant changes to their existing identity management systems, with only 2% saying their existing IAM was suitable. This suggests that although many companies are moving their AI prototypes out into production, the accompanying security framework is not providing adequate cover.

There have been several instances that have revealed some truly bad habits, such as committing hard-coded API keys and credentials in plain text to repositories. Although such cases may be outliers, they emphasise the speed (and therefore, potentially, the ensuing lack of care) of AI-related development. An IAM capable of governing all use of agents in an enterprise could therefore help bring risk levels down. Ev Kontsevoy, Teleport’s co-founder said, “Deploying AI on top of fragmented credentials and identity silos is a recipe for secrets and data leakage.”

(Image source: “Masqued Ball” by SoulStealer.co.uk is licensed under CC BY 2.0.)

 

Want to experience the full spectrum of enterprise technology innovation? Join TechEx in Amsterdam, California, and London. Covering AI, Big Data, Cyber Security, IoT, Digital Transformation, Intelligent Automation, Edge Computing, and Data Centres, TechEx brings together global leaders to share real-world use cases and in-depth insights. Click here for more information.

TechHQ is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

Author

  • Joe Green

    Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.

    View all posts

About the Author

Joe Green

Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.

Related

August 11, 2026

August 10, 2026

August 5, 2026

July 30, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12345 view(s)
11326 view(s)
7643 view(s)
6152 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)