Managing Agentic AI: Why the Control Plane Problem Is an AI Problem

BLOG

If we had $1 for everyone who said, “You can’t govern/manage/secure something you can’t see”, we could retire wealthy.

On one hand, it’s somewhat befuddling how often people may need that reminder. In reality, it is not that they don’t know that happy mantra, it’s that they struggle to gain the requisite visibility into … everything in their IT and OT environments.

Queue artificial intelligence and AI agents. Even if you thought you had full visibility into your environment, Surprise! Everything you knew just flew out the window.

TL;DR: Most organizations can’t count the number of agents they have in production. IDC research (sponsored by GuidePoint Security) found fewer than 1 in 5 organizations run continuous discovery on their agents.

  •  The biggest pain points start with AI: invisible agents running under user credentials, tooling built for humans not machines, privilege creep at machine speed, deepfakes breaking identity proofing and shadow AI shipping inside vendor platforms.
  • The fix? Identity is the foundational control plane. Every agent needs its own scoped identity, a human sponsor, short-lived credentials and a managed lifecycle.
  • Frameworks like OWASP NHI Top 10, NIST and the EU AI Act already expect this.
  • Three things every organization should do right now: run an agent inventory, assign a human sponsor to every agent and kill inherited credentials.  

Bring on the AI Agents

AI agents are in production at massive scale. They are executing tasks, accessing data, making decisions and chaining actions together at machine speed. They can even launch and orchestrate new AI agents without human intervention. 

At the same time, most organizations can’t confidently tell you how many agents they have. 

Why? Because they’re simply showing up. Everywhere. They’re being rolled out across every industry from manufacturing and supply chains to healthcare, financial services and even government services. And, let’s face it, Shadow AI thinks shadow IT is quaint.

Is AI an Identity or Operations Problem?

Make no mistake. Agentic AI is an operations problem and the question at the center of it returns to the deceptively simple (and utterly overused): how do you govern something you can’t see? ($1 please ;-))

Did you know fewer than 1 in 5 organizations run continuous discovery on their AI agents. Just over 1 in 4 have fully automated governance for them. Those data points are in IDC’s Worldwide IAM Security Survey (May 2026, n=860) and represent a snapshot of where we are today.

The Challenges Starts with Artificial Intelligence

IDC’s new qualitative research, which was sponsored by GuidePoint Security, (“Managing Agentic AI Through the Identity Control Plane: What Organizations Should Look For”) surfaced six new pain points that security and identity leaders described in their own words. Every one of them starts with AI:

  • Invisible agents. The hardest agents to find are the ones running under a user’s own credentials. These agents never entered an inventory because no one did it.
  • Tooling built for humans. The privileged-access stack assumes a person on the other end. An agent’s risk is defined by what it can do (non-human, remember?). That distinction breaks current models.
  • Privilege at machine speed. A support agent finishes an IT task and carries a leftover admin credential into a request that touches restricted HR data. Nothing was hacked. The agent just never let go. And so on… 
  • Synthetic trust. AI-generated voices and faces pass traditional identity proofing, making the human signal no longer reliable.
  • Governance lags adoption. Business pressure pushed agents into production faster than security could (re-)write policy.
  • Shadow and vendor-embedded AI. Do you know how your vendors (and their vendors) have embedded AI? This is a risk you didn’t build and don’t control. It’s simply shipping inside platforms your teams already use.

The Unexpected Consensus

Perhaps the most interesting detail in the report. No matter how mature the organization is in its AI adoption, every participant is heading to the same destination: a purpose-built, distinctly governed identity class for every agent.

Why is Identity the Foundational Control Plane?

As Laura Babbili said in her blog, “Agentic AI Security: Key Findings from New IDC Research on the Identity Control Plane”, it takes three control planes govern agentic AI: identity (who may act), data (what an agent may touch) and runtime (what it may do in the moment). Data and runtime controls both depend on knowing which agent is acting. But it’s impossible to enforce least privilege, audit actions or contain an incident for an agent that doesn’t have its own identity. Therefore, identity is the control plane upon which both data and runtime rely.

Understanding the AI Maturity Model?

Organizations in the IDC study modeled agents in different ways. Some treat agents as a distinct identity type. Others reuse service accounts or application identities, even if those models don’t exactly fit. And others skip the issue altogether and their agents run using the invoking user’s credentials. This variation doesn’t deviate from the above-stated consensus. Rather, the IDC report shows it as an indicator of how far along they are on the AI maturity curve. IDC defines a four-stage maturity model for agentic AI as:

  • Stage 1: Agents run under user or shared service accounts. No inventory. No distinct governance.
  • Stage 2: Some agents have their own identities, but governance is manual and inconsistent.
  • Stage 3: Agent identities are managed with automation, but coverage is incomplete.
  • Stage 4: Every agent has a scoped identity, a human sponsor, a managed life cycle and automated governance.

Today, most organizations are sitting somewhere around stages 1 or 2. But their destination is codified in the security frameworks they’re measured against: Every agent needs a named human sponsor and managed lifecycle. 

What the Security Frameworks Already Expect

Update Vendor Expectations

This is also where you’ll see frameworks such as OWASP NHI Top 10 and Agentic Applications Top 10 converge. 

  • OWASP NHI Top 10: Know every non-human identity you own. Retire each one cleanly. Keep privileges trimmed to the task. Rotate credentials before they age into liabilities. It flags improper offboarding is the number one risk. (Related: you can’t offboard an identity that never entered an inventory.)
  • OWASP Top 10 for Agentic Applications: Every agent gets its own scoped identity. No borrowed sessions, no cached tokens, no inherited credentials. (Inherited credentials and identity abuse are the most common shortcut in agent deployments.)

Note that both start with the same prerequisite: an agent that has its own scoped identity. Now, the expectation is threefold:

  • Every agent acts under its own scoped identity with least privilege at the task level.
  • Credentials are short-lived. They are neither inherited nor cached.
  • Runtime traceability records every action under the agent’s own name.

There are other relevant frameworks in play with AI.

  • NIST AI Risk Management Framework: Maintain an inventory of AI systems as a basic governance practice. Govern, Map, Measure and Manage functions extend to agents.
  • NIST SP 800-53 (2026 overlays): Agents are treated as distinct non-human identities with formal identification, managed life cycles and audited authorization.
  • CSA AI Controls Matrix: Identity, logging and data-protection control domains apply to agents.
  • EU AI Act, Article 12: High-risk AI systems must support automatic event logging across their lifetime. General obligations are in effect now; high-risk compliance is required by December 2, 2027. (If you can’t find it, you can’t log it. $1 please.)

Don’t believe me? Abused non-human identities are now effectively tied with phishing as the leading entry point in confirmed identity incidents. AI agents are the least covered identity type in NHI management programs. It is time for that to change.

Given this data, there are at least four critical capability areas to address with your supply chain. These are the questions to put in front of your vendors as part of your standard decision-making process:

  1. Automated discovery and an authoritative agent inventory. Continuous, automated discovery that finds agents regardless of how they were deployed.
  2. An agent-first identity and privilege model. Clearly defined, scoped, short-lived, task-level credentials. An agent’s privilege should match its task, expire when the task ends and never carry over to the next workflow.
  3. An integrated governance framework. Ownership, policy, life-cycle management and audit should live in a single framework.
  4. Deepfake-resistant, adaptive verification. Verification workflows need to account for synthetic trust because many AI-generated voices, faces and behaviors pass traditional identity proofing.

And one filter that cuts across all four: provable, no-lock-in solutions that meet you where you are on the maturity curve.

Don’t Know Where to Start?

When they say AI is operating at machine speed, it’s no joke. Which means, you can’t solve everything at once, but you absolutely need to get started. One step at a time. Here are a few immediate actions we recommend.

  1. Run an agent inventory. Include agents running under user credentials and via Shadow AI/vendor-embedded AI. These are most often the agents missing.
  2. Assign a human sponsor to every agent in production. This was the single strongest consensus point in the research.
  3. Kill inherited credentials. Every agent gets its own scoped identity. Short-lived. Task-level. Auditable.
  4. Decommission/containment plan. A way to identify and cut rogue agent access, isolate it from the network and shut it down before it can do further damage.

The maturity curve is a roadmap, not a finish line. Start where you are. The organizations that are furthest along didn’t wait for perfection. Afterall, you eat the [proverbial] elephant one bite at a time. 

Start with visibility and ownership, then build governance around what you find.

For more details, we invite you to read the full IDC whitepaper: “Managing Agentic AI Through the Identity Control Plane: What Organizations Should Look For” (September 2026, #US54897326), sponsored by GuidePoint Security.

Director, Offer Marketing
GuidePoint Security

Ingrid helps bring cybersecurity services and products to market in a way that is meaningful to customers. Ingrid is a strategic product and go-to-market leader who helps create market momentum and stimulate revenue growth for enterprise and emerging technology companies. She brings decades of experience in cybersecurity, high technology platforms, marketing, messaging, content creation and positioning. Prior to joining GuidePoint Security, Ingrid held consulting, corporate, solution and product marketing roles at industry leaders including Sun, NetApp, Qualcomm, Cisco, McAfee, Fidelis Cybersecurity and Kambe Consulting. She has a Bachelor of Science in Commerce (BSC) in Marketing from Santa Clara University.