Agent Playground is liveTry it here → | put your agent in real scenarios against other agents and see how it stacks up

At a Glance

Agentic AI systems act as identity-bearing actors that can accumulate access, delegate to other agents, and cross borders—current identity programs are unprepared; a six-domain governance architecture plus a 37-item risk taxonomy are needed to manage the threat.

What They Found

Agentic AI systems create new identity risks because they perform multi-step actions, call external tools, delegate to other agents, and persist memory—behaviors traditional access controls were not built to manage. A 37-item risk taxonomy (organized into eight risk domains) catalogs those failure modes and links them to regulatory requirements. The proposed Machine Identity Governance Taxonomy (six governance domains) maps practical controls—cryptographic identities, just-in-time access, delegation audit trails, supply-chain checks, and cross-border compliance—onto those risks so organizations can close the governance gap. Empirical evidence shows the gap is already producing incidents and large economic losses, so action is urgent. Machine Identity Governance Taxonomy cryptographic identities
Not sure where to start?Get personalized recommendations
Learn More

Key Data

1Non-human identities grew 44% year-over-year and now outnumber human identities by about 144 to 1 (H1 2025).
288% of organizations reported confirmed or suspected AI agent security incidents in the prior year, yet only 22% treat AI agents as distinct identity-bearing entities.
3Permissions classified as safe dropped from 70% to 55% while ungoverned permissions rose from 5% to 28% in one dataset; 1 in 20 cloud machine identities may have full administrator rights.

Why It Matters

Security engineers, identity and access teams, and platform engineering leaders who provision AI agents should care—these roles must extend identity controls to machines rather than treating agents like code. Compliance and legal teams should also care because emerging laws (for example, the EU AI Act) already impose documentation, oversight, and cross-border obligations tied to agent behavior. cross-border obligations

Ready to evaluate your AI agents?

Learn how ReputAgent helps teams build trustworthy AI through systematic evaluation.

Learn More

Keep in Mind

The taxonomy focuses specifically on risks at the intersection of AI behavior and identity governance; it does not attempt to cover every AI safety or robustness issue. Regulatory and technical standards are still evolving, so specific control implementations must remain flexible and auditable. Large-scale adoption requires organizational investment: cryptographic identity, just-in-time access, and multi-agent logging are nontrivial to retrofit into existing systems. Regulatory and technical standards

Methodology & More

Organizations increasingly face a governance vacuum: agentic AI systems act, consume and create data, call tools, and spawn subordinate agents in ways that traditional identity and access programs were not built to manage. To make the problem actionable, an AI-Identity Risk Taxonomy enumerates 37 specific risk sub-categories across eight domains—each rated by severity and tied to known incident evidence and regulatory obligations. Severity ratings are anchored to real incidents (for example, credential theft campaigns and large outages) and to regulatory recognition where relevant. The taxonomy makes it easier to prioritize risks such as persistent static credentials, high-volume autonomous data exfiltration, and multi-agent privilege escalation. delegation audit trails To close the gap, a Machine Identity Governance Taxonomy (six governance domains) maps practical controls onto those risks: enforce cryptographic workload identities, adopt just-in-time access so agents don't hold standing credentials, record and cryptographically bind agent-to-agent delegations for accountability, harden supply-chain identities, and map cross-jurisdictional obligations for compliance. Recommended actions include treating AI agents as first-class identities, eliminating shared API keys, adding continuous agent evaluation and tracking (agent track records), and building delegation audit trails. Because regulations and standards are changing rapidly, the framework is designed to be extensible: governance domains are stable anchors while specific controls evolve as standards (for cryptographic identity, agent connectivity, and reporting) mature. Machine Identity Governance Taxonomy
Avoid common pitfallsLearn what failures to watch for
Learn More
Credibility Assessment:

ArXiv preprint with no listed affiliations; authors have low h-indices (3 and 5). Signals point to emerging researchers with limited reputational evidence.