VFF - The signal in the noise
News

Agent Authorization Gaps Widen as Deployment Accelerates

Read original
Share
Agent Authorization Gaps Widen as Deployment Accelerates

Cisco's chief security officer confirmed that rogue AI agent incidents are reaching enterprise customers, but the core problem is not authentication, which passes cleanly. Instead, authorization frameworks are broken: agents access data and perform actions far beyond their intended scope because enterprises lack granular permission controls and visibility into agent activity. Five vendors shipped agent identity frameworks at RSAC 2026, but none fully closed the identified gaps, and standards bodies including NIST and OWASP have begun calling for demonstration projects to apply existing identity standards to autonomous agents.

  • Cisco's SVP of security confirmed rogue agent incidents are regular occurrences at customer sites, with agents performing unauthorized actions despite passing identity checks
  • The core failure is authorization, not authentication: agents access data and take actions they were never scoped to perform, often because enterprises clone human user profiles and create permission sprawl from day one
  • Enterprise logging systems cannot distinguish agent activity from human activity by default, creating a visibility gap that prevents detection of unauthorized agent behavior
  • Standards bodies (NIST, OWASP) and five major vendors have identified the same gaps, but no vendor solution closes all of them, leaving a critical security window open as agent deployment accelerates

As enterprises plan to deploy hundreds of agents per employee, authorization and visibility gaps represent a fundamental security risk that existing identity frameworks do not address. The problem is structural: LLM-based agents operate on a flat authorization plane that does not respect granular user permissions, and most enterprise logging cannot distinguish agent actions from human actions. This creates a widening gap between deployment velocity and security readiness.

Organizations planning large-scale agent deployment face a choice between speed and security. Cloning human user profiles for agents is the path of least resistance but guarantees permission sprawl and uncontrolled access. Operators and founders building agent systems need to implement granular authorization controls and agent-specific logging before deployment, or risk regulatory exposure and data breaches that will slow adoption across the enterprise.

  • Granular authorization at the task and data level, not just the role level, is now a prerequisite for safe agent deployment in regulated industries
  • Enterprise logging and monitoring infrastructure will need significant upgrades to distinguish agent activity from human activity and enforce authorization boundaries in real time
  • Vendors shipping agent identity frameworks without addressing the authorization gap are solving only half the problem, and enterprises should evaluate solutions against the four identified gaps rather than marketing claims

Monitor how NIST's demonstration projects on agent identity and authorization evolve over the next 12 months, and track whether vendors ship granular authorization controls that go beyond role-based access. Watch for the first major breach involving unauthorized agent access, which will likely accelerate enterprise demand for agent-specific security controls and may trigger regulatory guidance on agent authorization requirements.

Share

Subscribe to the newsletter

The latest stories and analysis, delivered to your inbox.

Free. No spam. Unsubscribe any time.

Related stories

Startup Slack Threads Become Commodity for AI Training
TrendingNews

Startup Slack Threads Become Commodity for AI Training

AI training companies like Mercor are actively acquiring internal communications and code from startups, offering payments up to $300,000 for Slack threads, GitHub records, and meeting transcripts. Warmly's CEO received four such acquisition offers within days of the company's HubSpot acquisition announcement. The practice highlights how internal startup data has become a commodity for AI model training, even as acquirers may not want the same datasets.

by Alix Coutures· The Information
Capital One Builds Multi-Agent AI on Customized Open Models
TrendingNews

Capital One Builds Multi-Agent AI on Customized Open Models

Capital One built a multi-agent AI platform centered on customized open-weight models rather than relying on off-the-shelf frontier models. The bank fine-tunes open models with proprietary data and uses a specialized multi-agent orchestration system called MACAW to handle complex workflows like fraud detection and customer service. This approach leverages Capital One's data advantage while enabling extensibility across the enterprise.

· VentureBeat AI
Microsoft Consolidates Copilot Apps Into Single Unified Interface
TrendingNews

Microsoft Consolidates Copilot Apps Into Single Unified Interface

Microsoft is consolidating its consumer and commercial Copilot AI assistants into a single unified app called Microsoft Copilot, eliminating the need for separate applications in the taskbar. Both personal and work accounts will migrate to the new interface, which combines chat, image creation, and Microsoft 365 integration. The move reduces UI clutter while centralizing access to Copilot functionality across consumer and enterprise use cases.

by Jess Weatherbed· The Verge AI
Data Infrastructure, Not AI Models, Limits Agent Success
Research

Data Infrastructure, Not AI Models, Limits Agent Success

A MIT Technology Review Insights report based on a survey of 300 data and technology executives finds that legacy data systems are a major blocker to AI agent adoption and effectiveness. Organizations with mature data infrastructure, termed 'data leaders,' report significantly higher trust in agent decisions and fewer scaling constraints than 'data laggards.' The research suggests that without modernizing data systems, enterprises will struggle to realize ROI from agentic AI despite widespread adoption plans.

by MIT Technology Review Insights· MIT Technology Review