How AI Agents Are Reshaping Enterprise Security: The Identity Crisis Nobody Expected
AI agents are gaining access to enterprise data at a pace that far outstrips organizations' ability to secure them. According to new data from SailPoint's second quarter 2027 earnings report, 97% of AI agents now have access to sensitive enterprise data, while only 21% of organizations surveyed say they are highly confident in their ability to manage that risk. This widening gap between agent proliferation and security readiness is forcing enterprises to rethink how they govern autonomous software, and it's creating an entirely new category of business challenge.
Why Are AI Agents Becoming a Security Blind Spot?
The problem isn't that AI agents are inherently dangerous. Rather, traditional security models were built for humans and applications, not autonomous software that can independently decide which actions to take. As AI agents evolve from making recommendations to actually completing purchases and accessing data on behalf of users, the stakes have risen dramatically. By 2030, AI agents are projected to orchestrate between $3 trillion and $5 trillion of global consumer commerce, which means the security infrastructure supporting them needs to mature fast.
The challenge cuts across multiple layers. First, there's the question of identity: how do you verify that an AI agent is who it claims to be? Second, there's the question of intent: how do you confirm that an agent's actions reflect what a user actually wanted? Third, there's the question of accountability: if something goes wrong, who is responsible? Traditional cybersecurity controls what users and applications can access, but AI agents add a new dimension because software can independently decide which actions to take within those permissions.
SailPoint addressed this challenge by introducing two new product lines designed to manage both human and agentic identities under a unified control plane. The company launched SailPoint Agentic Fabric, a purpose-built product designed to discover, govern, and protect autonomous AI agents and nonhuman identities, alongside Human Fabric, the evolution of its Identity Security Cloud focusing on managing human workforce identities. The distinction matters because nonhuman identities, which include service accounts, bots, and autonomous AI agents, require different governance approaches than human users.
How Are Payment Networks Building Trust Into Agentic Commerce?
The payments industry is taking a different approach to the same problem. Ant International, Mastercard, and Visa have begun collaborating on a Know-Your-Agent (KYA) interoperability framework designed to help card networks, digital wallet ecosystems, agent platforms, and marketplaces streamline agent onboarding and identification across networks. The framework establishes shared principles while preserving each network's own verification and decisioning processes.
The KYA framework rests on three core pillars that address the identity and accountability challenge:
- Cross-Network Operator Traceability: Each agent is linked to a validated operator, cardholder, or business or organization, enabling clear attribution of agent activity across payment systems.
- Shared Certification Requirements: Each agent is assessed against security and behavioral requirements to ensure it operates as expected and meets baseline trust standards.
- Continuous Transaction Monitoring: Each agent is continuously monitored and evaluated using a combination of identity and transaction-related signals to support ongoing assessments and certification.
This approach recognizes that trust in agentic commerce cannot be a one-time event. As Rubail Birwadker, Global Head of Growth Products and Strategic Partnerships at Visa, stated, "As AI agents become a bigger part of how people discover and buy, trust must scale with them". The interoperable framework aims to reduce integration complexity and duplicative agent identity verification efforts while maintaining robust trust and risk controls, enabling faster time-to-market and lower integration costs for new agentic services.
Rubail Birwadker, Global Head of Growth Products and Strategic Partnerships at Visa
What Role Does AI Play in Contract Intelligence?
Beyond payments and identity governance, AI agents are also transforming how enterprises manage contracts. Docusign is moving beyond its traditional electronic-signature business toward intelligent agreement management, where AI can help organizations understand what their contracts contain and act on that information. This represents a fundamental shift from treating contracts as dormant documents to treating them as active sources of business intelligence.
The opportunity is significant because contracts contain some of the most commercially important information within a business. Pricing, commitments, renewal dates, service requirements, termination conditions, and liabilities are frequently contained within agreements that become difficult to analyze once they have been signed. Large organizations can hold thousands of supplier, customer, employment, financing, and property-related contracts while still depending on employees to manually open individual documents to determine what they contain.
An AI-based agreement platform could increasingly perform much of that preparatory work automatically. As a renewal approaches, it could identify the relevant contractual provisions, connect them with information about the commercial relationship, and prepare an assessment for the person responsible for renegotiating the agreement. The same approach can be applied before contracts are signed, allowing a company to understand how new clauses compare with previous contracts and whether particular provisions create additional risk.
How Can Organizations Implement Agentic Governance?
For enterprises looking to manage AI agents responsibly, several practical steps can help bridge the security gap. The key is recognizing that agentic AI introduces a new dimension to enterprise security that requires both technical controls and organizational discipline.
- Implement Permission-Based Autonomy: Restrict an AI agent's ability to access information and perform actions to what the relevant employee would ordinarily be permitted to do, limiting potential consequences if the agent makes an error or is manipulated.
- Establish Audit Trails and Verification: Require that AI agents produce citations and verification for their recommendations, allowing users to understand how the system reached its conclusions and which documents or provisions support the recommendation.
- Prioritize Human Oversight for High-Risk Actions: Deliberately constrain the authority available to AI agents during early development, requiring human involvement for higher-risk actions rather than allowing agents unrestricted authority over customer environments.
The financial impact of getting this right is substantial. SailPoint reported that AI-driven annual recurring revenue (ARR) exceeded $70 million in the second quarter of 2027, with AI net new ARR contribution representing more than 30% of net new ARR for the quarter, driven by demand for agentic governance solutions. Existing customers who adopted AI-driven solutions increased their annual spend by over 60%, suggesting that organizations recognize the business value of proper agentic governance.
Looking ahead, the stakes will only increase. SailPoint has set a fiscal year 2029 ARR target of at least $2.1 billion, with at least $800 million expected from AI-driven solutions. This suggests that agentic governance is transitioning from a niche concern to a core enterprise discipline. The EU AI Act, which includes human oversight requirements for AI agents scheduled for enforcement as early as 2027, will likely accelerate this trend.
The convergence of these trends points to a clear conclusion: as AI agents become more capable and more autonomous, the infrastructure for governing them becomes more critical. Organizations that invest in identity governance, permission-based autonomy, and audit trails now will be better positioned to scale agentic AI safely. Those that treat agentic governance as an afterthought risk the kind of security blind spot that the data suggests is already widespread.