Rig Security raised $12 million in seed funding to separate an AI agent's actions from those of the employee whose identity it borrows. The standard way to stop a misbehaving agent, disabling its account, locks out the person as well.
Reality
- Evidence40
- Adoption25
- Hype gap+30
- Incentives60
- Confidence45
Pillar Security CEO Ziv Karliner says OpenAI's sandbox escape shows AI agent limits must be enforced outside the model. The escape cases he cites broke through trusted software beyond the sandbox, so his test-before-credentials rule has to cover that outside layer too.
Publishers:scworld.com · token.security Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives72
- Confidence55
GitGuardian's 2026 State of Secrets Sprawl Report says commits identified as AI-assisted leak secrets at about twice the rate of human-written ones. Agent and MCP config files also keep plaintext keys on developer machines where commit scanning and code review never look.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence35
Enterprise Cloud owners can now pull owner, scope, expiry and last-use data for SSH keys, PATs and app tokens as a CSV. The export stops at credentials GitHub issued, so secrets pasted into repositories stay out of scope.
Reality
- Evidence58
- Adoption20
- Hype gap+5
- Incentives70
- Confidence62
Growth Equity at Goldman Sachs Alternatives has put $400m into Cyera at the valuation the company set in June, its third large round of 2026. What that cheque funds and what a security team can switch on next month are separate questions.
Reality
- Evidence45
- Adoption25
- Hype gap+30
- Incentives80
- Confidence55
A zero-click RCE hit four AI coding agents through 925 hijacked plugins. A dev.to post pins the reach of it on keys that never expire. Its replacement is a grant scoped to one run and one task.
Reality
- Evidence30
- Adoption12
- Hype gap+35
- Incentives40
- Confidence30
Hush Security searched public GitHub for the configuration filenames coding agents write, classified how each credential slot gets its value, and found a hardcoded literal in 12% of them, most of which match no vendor token format.
Reality
- Evidence45
- Adoption38
- Hype gap+12
- Incentives78
- Confidence58
Martin Kuppinger of KuppingerCole argues role-based access cannot hold an agent that makes probabilistic, multi-step decisions, and wants per-session credentials plus logs recording what the agent was told to do.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+30
- Incentives78
- Confidence52
Okta wants entitlements for AI agents and workloads evaluated continuously instead of recertified on a schedule, on the argument that approvals accumulate and access changes in the gaps between reviews.
Reality
- Evidence30
- Adoption14
- Hype gap+38
- Incentives76
- Confidence44
The token was unrelated to the task the agent was given, and its blanket GraphQL permissions covered the volume-level backups too. GitGuardian counts 24,008 secrets in public MCP config files, 2,117 of them still valid.
Reality
- Evidence34
- Adoption45
- Hype gap+32
- Incentives80
- Confidence55
The SANS 2026 survey puts 74 percent of businesses on standing credentials for autonomous AI, with no single control above 40 percent. The two MCP incidents most often cited as proof have different root causes.
Reality
- Evidence42
- Adoption38
- Hype gap+22
- Incentives58
- Confidence45
Ping Identity executives split enterprise AI agents into four classes at their Austin conference. The two that live on endpoints have no identity of their own, so their actions authenticate as the employee who lent them the credential.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+32
- Incentives84
- Confidence52
The new controls compare an agent's runtime behaviour against its authorized scope and can revoke the credentials underneath it. The 57% unmanaged-identity figure behind the pitch is Orchid's own, and neither publisher gives the method.
Reality
- Evidence28
- Adoption14
- Hype gap+38
- Incentives88
- Confidence62
Reco says four in five AI tools in its telemetry run outside IT oversight, averaging 414 per 1,000 staff at smaller companies, which turns the cleanup into a question of who now owns each agent's credentials.
Reality
- Evidence40
- Adoption58
- Hype gap+22
- Incentives78
- Confidence55
Pillar Security's Dor Sarig argues the non-human identity buildout answers who an agent is rather than what it does, and cites an internal agent any Slack message could trigger across a thousand private repositories.
Reality
- Evidence24
- Adoption18
- Hype gap+28
- Incentives86
- Confidence52
Mitiga field CISO Brian Contos argues most enterprises cannot say what a live agent did after the fact, and the people who feel that first are the auditors and responders who have to produce a sequence.
Reality
- Evidence18
- Adoption
- Insufficient
- Hype gap+32
- Incentives72
- Confidence58
A dev.to writeup traces about sixty commits that landed under a colleague's git identity, and the server-side rebuild that followed fixed dependency drift while leaving the question of who authored what exactly where it was.
Reality
- Evidence28
- Adoption14
- Hype gap+14
- Incentives32
- Confidence38
A dev.to guide defines the metric as confirmed invalidation minus validation, and names the four timestamps per incident that make it reportable. Cleanup does not stop the clock.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+18
- Incentives76
- Confidence52
The January 8 deal puts continuously granted and revoked access at the center of the Falcon roadmap. Anyone signing a PAM or IGA renewal this year now has a harder question to answer.
Reality
- Evidence32
- Adoption12
- Hype gap+46
- Incentives90
- Confidence42