"The IAM problem with agents is not that we lack the right credentials standard. It is that we built access control around principals that have accountability, and agents have none. Every control we designed assumes a principal with something to lose. Agents operate outside that contract entirely. The organizations getting ahead of this are mapping what they actually have, categorizing it honestly, and governing proportionally to what each category can do and what it can cost when it goes wrong.”

Fernando Montenegro

Vice President & Practice Lead, Cybersecurity & Resilience

Agentic AI Identity Sprawl will Break Traditional IAM, Requiring Dedicated Authorization Governance to Prevent Unmonitored Agent Activity

As 2026 ends, enterprises will realize their Identity and Access Management systems are failing because they were built for humans, not goal-directed AI agents. Standard workload identity models designed for service accounts simply do not work for these new entities.

Meanwhile, agent identity sprawl will continue to accelerate due to unmonitored procurement, unmanaged open-source deployments, and agents embedded within SaaS platforms. Organizations will need to urgently build agent authorization governance fit for purpose. Without it, the costly gap between an agent’s authorized capabilities and its actual actions will become a severe liability.

  • Agent Taxonomy Is Exposing Governance Blind Spots: Not all agents are the same problem. End-user-facing agents, such as copilots and assistants operating on behalf of individuals, carry different risk profiles than application-layer agents orchestrating workflows across systems, which differ again from agents embedded inside third-party SaaS platforms that security teams never directly reviewed. Each category has distinct identity models, oversight frequencies, and blast radii. Organizations that govern agents as a single, uniform category systematically under-engineer controls for autonomous, goal-directed agents while over-engineering them for bounded, deterministic ones.
  • Credentials Solve Authentication, Not Authorization: Workload identity standards give agents a verifiable identity. They do not solve the runtime authorization gap, specifically, whether a specific action combining steps across multiple systems falls within what was actually intended when a human granted a goal. Goal-directed agents infer permission from objectives; they do not seek explicit authorization for discrete actions. When an agent causes harm, “Who authorized this?” has no clean answer. Logging and PAM provide detective value but cannot substitute for a prospective authorization layer that does not yet exist at enterprise scale.
  • Third-Party Agents Are an Information Asymmetry Problem: Agent sprawl is arriving faster than shadow IT ever did, partly because it travels through legitimate procurement channels. A vendor platform approved by a marketing team may contain embedded agents with broad data access that nobody in security has evaluated. There is no established SBOM equivalent for agents, meaning there is no standard disclosure mechanism specifying which agents a product contains, what permissions they require, and which systems they touch. Buyers cannot assess what they are deploying, and vendors have no market incentive to disclose more than necessary.
  • Agent Taxonomy as a Governance Starting Point: Security teams are mapping agent environments by category, covering end-user agents, application orchestrators, and embedded third-party agents, and applying governance proportional to autonomy and blast radius. This bottom-up approach, starting with the specific runtimes already running in the organization, surfaces the embedded third-party agent population that would otherwise be invisible and yields more actionable results than waiting for a top-down framework.
  • Extending PAM and Requiring Agent Capability Disclosure: For high-value, known target systems, extending PAM to cover agent identities is the right near-term control, with honest acknowledgment of where it breaks for agents that discover APIs at runtime. For third-party agents, organizations are beginning to require capability disclosure in vendor contracts as a procurement forcing function, establishing what an agent can access before deployment rather than after an incident.
  • Token Spend as a Trust and Governance Signal: Runaway agent spend is becoming a governance concern in its own right. An agent with broad authorization and unconstrained tool access can consume compute and API budget well beyond what was anticipated at deployment. Organizations experiencing unexpected cost spikes are often those with the weakest authorization controls. Security and finance teams are beginning to treat the token budget as an authorization dimension: an agent that cannot account for its spend cannot be trusted with broad permissions.

Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice’s growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.

Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.

Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

Recent Insights, News & Research

Microsoft's Project Perception Bets on Agents That Act, Not Just Alert
July 28, 2026

Microsoft’s Project Perception Bets on Agents That Act, Not Just Alert

Fernando Montenegro, VP at Futurum, analyzes Microsoft's Project Perception and MAI-Cyber-1-Flash, and why the company's enterprise entrenchment, not its agents, is the real differentiator in agentic security....
So This Is How AIs Attack- Observations From the OpenAI & Hugging Face Incident
July 24, 2026

So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident

Fernando Montenegro and Mitch Ashley, VPs at Futurum, read the OpenAI and Hugging Face agentic incident as a live test of enterprise readiness to detect and contain AI agents that...
Fortinet's AI Controls Join the Field. Can Integration Set Them Apart?
July 21, 2026

Fortinet’s AI Controls Join the Field. Can Integration Set Them Apart?

Fernando Montenegro, VP at Futurum, examines why FortiEndpoint's consolidated AI controls are a real buyer win, while platform and SASE integration, not the individual features, will decide whether Fortinet stands...
ServiceNow and Accenture Bet on Migration to Win Enterprise Risk
July 7, 2026

ServiceNow and Accenture Bet on Migration to Win Enterprise Risk

Fernando Montenegro, VP at The Futurum Group, examines the ServiceNow and Accenture cybersecurity offering, and why its AI-powered migration and the Armis acquisition point to a bid to become the...
The Hard(er) Challenge in Agent Governance Is Authorization
June 26, 2026

The Hard(er) Challenge in Agent Governance Is Authorization

Fernando Montenegro, VP at Futurum, argues that the launch of the Agent Control Standard does not close the agent governance gap, and that "shrinkage," not universal coverage, is the correct...
The Hard(er) Challenge in Agent Governance Is Authorization
June 25, 2026

The Hard(er) Challenge in Agent Governance Is Authorization

Fernando Montenegro, VP at Futurum Group, argues that the launch of the Agent Control Standard does not close the agent governance gap, and that "shrinkage," not universal coverage, is the...

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.