Akeyless Security CEO Warns AI Agents Undermine Identity Security
Oded Hareven warns that autonomous AI agents introduce non-deterministic behaviors that traditional identity and access management systems cannot effectively control or evaluate.
Oded Hareven, CEO of Akeyless Security, warns that autonomous AI agents are undermining traditional identity security models by introducing non-deterministic behavior. He argues that standard identity and access management systems, which rely on predictable tasks and static credentials, are unable to determine if a fully authenticated agent's action aligns with organizational intent.
Hareven points to the PocketOS incident as evidence that authentication alone is insufficient, noting that an authenticated agent deleted a database in seconds. This vulnerability is further highlighted by research from Akeyless Security, which found that 83% of organizations believe a single compromised AI agent credential could affect multiple major systems.
In response to these shifting risks, OWASP has introduced its Top 10 Risks for Agentic AI for 2026. The new framework specifically highlights the dangers of excessive agency and unintended actions resulting from the deployment of agentic AI.