Autonomous Agents, Fragmented Identities, and the New Crisis of Digital Trust

Gartner Fellow Lee McMullen talks cybersecurity teams.

As generative AI accelerates the creation of intelligent “agents” capable of making decisions and transacting autonomously, cybersecurity experts are warning that digital identity — already the soft underbelly of enterprise defense — is fast becoming unmanageable.

In a session at RSA Conference, Gartner Fellow Lee McMullen argued that cybersecurity teams are nowhere near ready for the rise of agent-based systems, autonomous software entities that act with human-like agency. “You do not hack agent-based systems because you don’t have to — you just confuse them,” he said. As machines begin to make and verify their own decisions, McMullen warned, identity will become the Achilles’ heel of every interaction. “By 2035, counterfeiting of digital capabilities will be widespread,” he predicted, noting that both human and machine “agents” can be impersonated, subverted, or socially engineered.

That warning comes as fresh data from Verizon’s 2025 Data Breach Investigations Report (DBIR) underscores how fragile identity already is. The report found that credentials remain the leading cause of breaches, accounting for more than a fifth of incidents analyzed. Info-stealer malware, often disguised as consumer software or browser add-ons, siphoned billions of passwords in 2024 alone, feeding thriving underground marketplaces. “We’re still seeing exposed RDP and reused passwords in 2025,” said Verizon’s lead data scientist Philip Langois. “Half of ransomware victims had credentials show up in infostealer logs before they were hit.”

Meanwhile, enterprise identity systems themselves are buckling under the strain. In an SC Media webcast titled “From Fragmented to Unified: Transforming IAM in the Age of Digital Complexity,” Saviynt Field CIO Simon Gooch and CyberRisk Collaborative’s Dustin Sachs described how hybrid cloud environments, mergers, and SaaS sprawl have splintered identity and access management (IAM) across organizations. “Identity is no longer just an entry point — it’s the fabric that binds everything,” Gooch said. “But legacy IAM frameworks weren’t designed for this level of interconnectedness. Fragmentation introduces risk because every inconsistency is an exploit waiting to happen.”

Taken together, the three conversations reveal a widening fault line: cybersecurity’s reliance on brittle identity systems just as the digital ecosystem is shifting toward machine autonomy. Credentials, identity stores, and even trust itself are being extended to — and in some cases delegated to — nonhuman actors.

To regain control, experts argue, CISOs must treat identity not as infrastructure, but as a living risk surface. That means re-leveling IAM foundations, enforcing zero trust and passwordless authentication, and protecting the prompts and APIs that power AI agents. It also means confronting a cultural problem decades in the making. “We’ve been training people to shut up and trust the system,” McMullen said. “Unfortunately, the system might not be trustworthy.”

The next phase of cybersecurity may depend not on faster automation or more AI, but on rebuilding a transparent, verifiable chain of digital trust — before the machines start believing each other more than they believe us.

Total
0
Shares
Next Article
cardboard robot under screen

When Machines Have Logins

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading