Leadership1 distinct publisher3 min readUpdated
A vendor-authored account of a real agent-driven exfiltration lands in the same month the AI Act's high-risk rules move out 16 months. Only one of those two dates is under your control.
The Board Room · Leadership desk
Compiled by The Board RoomSomething wrong?How this is made
Attackers used compromised AI agents to extract 150 gigabytes of data from nine Mexican federal agencies between December 2025 and February 2026, including the federal tax authority and the electoral institute, according to Israel Duanis, chief executive of the identity governance vendor Linx Security, writing for the Forbes Tech Council [2] [1]. That matters less as breach trivia than as a timing problem: the EU AI Act's high-risk compliance obligations, originally set to apply on August 2, 2026, will now take effect in December 2027 [4], roughly 16 months later than planned [13].
The second incident Duanis cites is a June 2025 zero-click prompt injection in Microsoft 365 Copilot that let a single attacker exfiltrate data from OneDrive and Teams [3]. Both are asserted in a sentence each, with no actor named and no account of how the agents were compromised [2] [3]. Read them as claims from an executive selling into the category [1]. The operational argument does not actually rest on them.
That argument is that most enterprises now run three identity layers and govern them as separate programmes [11]. Human identity carries the familiar debt: dormant accounts, permissions from five jobs ago, privileged access nobody cleaned up [14]. Non-human identities, meaning service accounts, API credentials and container identities, run into the tens of thousands and were mostly never formally provisioned [8]. Agents are the third layer, and per Duanis they operate around the clock, spawn sub-agents dynamically, request permissions thousands of times a day, and chain actions across dozens of systems in minutes [9]. Only 21% of organisations report a matured programme for governing agents [7], which leaves 79% without one [15].
The most useful passage is not the breach count. Duanis describes a financial services firm where an agent deployed to research vendor risk accumulated access to procurement systems, vendor databases and internal communications within months; much of that access was never formally provisioned but emerged as the agent embedded itself in daily workflows, and by the time leaders saw the scope, revoking it without breaking operations had become difficult [10]. That is not an attack. That is entitlement creep at machine speed, and it happens inside a compliant, audited estate.
The questions Duanis says CISOs cannot answer with current tooling are worth putting to your own team this quarter: which agents hold access to production data, what the blast radius is if one is compromised, whether an agent's access actually expired when its project ended, and whether it can be revoked instantly if behaviour changes [16]. His prescription is a separate governance framework for agents rather than forcing them into human-centric workflows, unified visibility across all three identity types in one view, and automated revocation on detection [12]. Note that this is also a description of his product [1]. The first two items are cheap to attempt and will tell you how bad the inventory problem is before anyone buys anything.
Watch three things. Whether December 2027 holds as the AI Act date, or moves again [4]. What NIST publishes as standards for autonomous agents, since that is likely to shape procurement language before any statute bites [6]. And what the SEC does as it tightens rules around AI-driven decision-making [5], which reaches the disclosure side of the house, not just security.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Duanis recommends building separate governance frameworks for agents rather than forcing them into human-centric workflows, implementing unified visibility across all three identity types in a single view, and automating remediation so access is revoked instantly when excessive access, policy violations or suspicious behaviour is detected.
Israel Duanis is CEO of Linx Security, an identity governance platform for human, non-human, and agent identities across the enterprise. The piece appeared in the Forbes Tech Council section of forbes.com.
Duanis lists questions CISOs are asking that their tools cannot answer: which AI agents have access to production data, what the blast radius is if an agent is compromised, whether an agent's access actually expired when its project ended, and whether an agent's access can be revoked instantly if it starts behaving strangely.
The EU AI Act's high-risk compliance obligations, originally set to apply on August 2, 2026, will take effect in December 2027.
Only 21% of organizations report having a matured program in place to govern agents.
Most CISOs are managing three overlapping identity problems simultaneously: human identity debt, governance for non-human service accounts and APIs, and AI agents deployed into production with no unified framework to control them.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-authored source, load-bearing facts uncited
Every claim traces to one contributed column by a vendor CEO. The two incidents that carry the argument have no advisory, victim statement, CVE or actor attribution; the 21% maturity figure names no survey; the non-human identity scale is an estimate; the illustrative case is an unnamed first-person anecdote; and the regulatory date change cites no legislative instrument while the body is truncated where it returns to that deadline. Only the attribution-level claims — who the author is, what he recommends, what questions he poses — are directly and fully evidenced.
Agents reportedly in production, governance rarely matured
Adoption of agents into privileged positions is indicated by two reported incidents and one customer-side anecdote, while governance adoption is put at 21% of organizations reporting a matured program. All three data points come from the same uncited vendor-authored source, so the reading is that deployment is running ahead of controls but the magnitude is unverified rather than established.
Crisis framing outruns cited evidence, and contradicts its own deadline
The piece frames an immediate operational crisis and a shortening compliance clock, yet the regulatory fact it supplies moves the hardest deadline out roughly sixteen months, and the empirical support for the urgency — the exfiltration, the Copilot injection, the maturity statistic, the identity population estimate — is uncited throughout. Positive gap reflects assertion volume exceeding verifiable support; it is not a judgment that agent identity risk is unreal, since the mechanism described is coherent and self-checkable by any operator.
Vendor CEO prescribing his own product category
The author is CEO of an identity governance platform that, per his own bio, covers human, non-human and agent identities — the same three-layer unified view, automated instant revocation and continuous verification the article tells CISOs to buy or build. The venue is a contributor council channel rather than independent reporting, and the disclosure appears once in the bio without being revisited at the point of recommendation.
One publisher, one contributed item, truncated text
Confidence is constrained by a single-source, single-publisher cluster with a strong disclosed commercial interest, no corroboration for any empirical claim, and a body that ends mid-sentence in the section discussing the compliance deadline. The assessment is reliable about what the article argues and who is arguing it, and unreliable about whether its incidents, statistics and regulatory dates hold.
leadership
Data residency is not model isolation, and your contract probably only covers the first1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
invest
SEC's $74m pre-IPO case turns on the markup, not the access1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026