惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
S
SegmentFault 最新的问题
Jina AI
Jina AI
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
B
Blog
博客园 - 【当耐特】
博客园 - Franky
M
MIT News - Artificial intelligence
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LangChain Blog
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 叶小钗
Last Week in AI
Last Week in AI
Engineering at Meta
Engineering at Meta

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
The AI Employee Without An Exit Interview
Ariel Zamir · 2026-06-26 · via Forbes - Innovation

Ariel Zamir is Co-Founder & CEO of Ray Security.

getty

​Organizations have spent decades refining how they onboard and offboard employees. When someone joins a company, IT provisions accounts, assigns permissions and grants access to the systems they need. When that person leaves, a formal process kicks in: Accounts are disabled, credentials are revoked and integrations are removed.

When an AI agent is abandoned, replaced or simply forgotten, none of that typically happens.

The Identity Life Cycle Gap In The Agentic Era

Enterprises are deploying AI agents at a pace that their security and governance functions were not built to absorb. These systems connect to email platforms, CRM tools, cloud storage, internal knowledge bases and collaboration environments. They automate repetitive work, accelerate analysis and handle operational tasks that used to require human involvement. The business case is easy to make. The governance case is far harder to execute.

According to Gartner, by 2026, 40% of enterprise applications will feature embedded AI agents, up from less than 5% in early 2025. That is not a gradual shift but a structural change in how enterprises operate, and most identity and access management frameworks were not designed for it.

The problem is not that AI agents are inherently dangerous. The more common risk is mundane:

• Legitimate access that persists long after its original purpose has ended​

• An AI assistant connected to a CRM during a pilot that was never formally concluded

• An orchestration tool with inherited permissions from the employee who configured it, who has since left the company

In many organizations, no one is actively monitoring whether that access still makes sense.

This is a version of a problem security teams already know well. Excessive identities and forgotten integrations create hidden security risks. AI agents introduce the same issue at a different scale and with a different character. Unlike a static application, an AI agent may interact across multiple systems dynamically, retrieve and process sensitive information and take actions without a human initiating each step. A forgotten integration is passive. A forgotten AI agent may not be.

The pace of experimentation makes this worse. Teams regularly spin up new tools, test vendors and build automations. Workflows evolve quickly. Projects are deprioritized or replaced. Access permissions, however, are rarely revisited at the same speed. Broad access gets granted because it is operationally easier than continuously scoping permissions as usage changes. The result is an expanding surface area of nonhuman identities whose actual activity no longer matches their granted privileges.

Traditional identity governance was built around human users and relatively stable enterprise applications. It assumed identities were persistent, visible and attached to people who could be held accountable. AI agents challenge each of those assumptions. They can be deployed in minutes, be modified continuously and operate across multiple environments simultaneously. They do not appear in org charts. They do not badge into buildings. And unlike employees, many of them will never receive an exit interview.

Getting this under control requires moving on three fronts:

1. Visibility

Organizations cannot govern what they cannot see. Security and IT teams need a current, accurate inventory of which AI agents exist, what systems they are connected to, what data they can access and whether that access was intentional or inherited. In most enterprises today, that inventory does not exist.

2. Life Cycle Discipline

AI agents should be subject to the same provisioning and deprovisioning logic applied to human identities. That means defining ownership at the point of deployment, building in periodic access reviews and establishing a clear process for retiring agents when the use case they were built for no longer applies. Access that is not actively maintained should not persist by default.

3. Moving Away From Static Permissions

The broader direction for identity governance needs to shift toward models that evaluate access based on actual behavior and usage, not on what was granted at the point of setup. An agent that has not accessed a system in 90 days probably should not retain full permissions to it. Continuous evaluation, rather than periodic audits, is where this needs to go.

Governing Agents Like Enterprise Identities

None of this requires treating AI agents as threats. Most of the risk in this space does not come from malicious systems. It comes from well-intentioned deployments that outlive their purpose and accumulate access that no one is actively reviewing.

The organizations that will manage this well are not necessarily the ones moving slowest on AI adoption. They are the ones that recognize a simple reality: As the number of nonhuman identities in the enterprise grows, the assumptions underlying identity security need to grow with it. The identity perimeter is no longer exclusively human.


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?