[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpfgwdtRU_80a8NLGNB60KJgY3wozFwQCgsjrR_v7o4g":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"7e450cca-24cc-4249-b427-678b6eb9685e","Cybersecurity Awareness Month: AI agents are users too, and they need governing like it","cybersecurity-awareness-month-ai-agents-are-users-too-and-they-need-governing-li-58570a","For more than two decades, Cybersecurity Awareness Month has centered on people: the employee who might click a malicious link, reuse a password or approve a suspicious login. This October, as the campaign runs under the banner “Don’t Make It Easy for Them”, identity specialists say the conversation must widen to include a fast-growing population […] The post Cybersecurity Awareness Month: AI agents are users too, and they need governing like it appeared first on IT Security Guru.","This Cybersecurity Awareness Month, the focus is expanding beyond human users to include AI agents as a new class of digital users. Identity specialists emphasize that AI agents, which can authenticate, retrieve sensitive data, and execute workflows at machine speed, represent identities that create risk if their access is not properly governed. The scale at which these non-human identities can be deployed, often with broad permissions, significantly expands the attack surface, making robust Privileged Access Management (PAM) crucial.","AI agents are now considered users in Cybersecurity Awareness Month, requiring identity governance.","For more than two decades, Cybersecurity Awareness Month has centered on people: the employee who might click a malicious link, reuse a password or approve a suspicious login. This October, as the campaign runs under the banner “Don’t Make It Easy for Them”, identity specialists say the conversation must widen to include a fast-growing population of users that will never sit through a training module: AI agents. “Cybersecurity Awareness Month has traditionally focused on human behavior: recognizing phishing, protecting credentials and making better decisions about access to an organization’s network, data and accounts. That conversation now needs to expand,” says Darren Guccione, CEO and co-founder of Keeper Security. “As organizations rapidly deploy AI agents across their environments, they are creating an entirely new class of digital users, often without applying the same identity governance expected for employees, contractors or administrators.” Guccione is clear that this is no longer an experimental corner of the IT estate. “AI is transforming from intelligence to unremovable enterprise infrastructure. AI agents can now authenticate into systems, retrieve sensitive information, interact with applications, execute workflows and make critical decisions – all at machine speed. If an agent has credentials and permissions, it represents an identity, and every identity creates risk when its access is excessive, persistent or poorly monitored.” John Cannava, CIO at Ping Identity, agrees that the boundaries of what security teams must protect have shifted. “As technology evolves, so does the definition of who, or what, organizations need to secure,” he says. “AI agents are increasingly accessing applications, data, and critical business systems while taking actions at machine speed, creating a new layer of risk that businesses need to manage every day.” Scale is the real challenge What makes agentic AI different from previous waves of automation is the speed at which new identities can appear. “The biggest problem is scale,” Guccione warns. “Organizations can deploy hundreds or thousands of non-human identities far faster than they onboard human employees. If those agents receive standing credentials, broad permissions or long-lived secrets without appropriate governance, the attack surface expands just as quickly. A compromised AI agent with privileged access can give an attacker direct access into critical systems and data.” That concern resonates with Michael Marino, SVP of strategy, identity security at Keeper Security, who has watched the discipline of privileged access change dramatically. “Cybersecurity Awareness Month is an opportunity to reflect not only on how cyber threats have evolved, but on how our defenses have had to evolve alongside them,” he says. “Over my career in identity security, I’ve seen few areas change as significantly as Privileged Access Management (PAM).” “PAM was once primarily about putting administrator passwords into a secure vault,” Marino explains. “That made sense when infrastructure was largely on-premises, privileged users were relatively easy to identify and access occurred within clearly defined network boundaries. The objective was straightforward: protect powerful credentials and maintain an audit trail around their use.” That model has not survived the move to the cloud. “The days of contained network perimeter no longer exist,” he says. “Organizations now operate across cloud, hybrid and remote infrastructure, while employees, contractors, applications, service accounts and automated systems all require different levels of access.” Marino points to Keeper’s 2025 report, Securing Privileged Access: The Key to Modern Enterprise Defense, which “found that 94% of organizations operate in hybrid or cloud-first environments. As access has become more distributed, the traditional concept of privilege has expanded with it.” As a result, he argues, the scope of PAM has had to grow. “Modern PAM, therefore, has to be about much more than protecting passwords. It must control when privileged access is granted, what someone or something can access and what happens during that session. Principles such as least privilege, just-in-time access and zero standing privilege help organizations replace persistent administrative rights with access that is intentional, temporary and auditable.” AI is now driving the next phase of that evolution, both as a source of risk and as a defensive tool. “The next stage of this evolution will be driven by automation and AI,” Marino says. “Non-human identities and AI agents are creating privileged access at a scale that security teams cannot manage manually. At the same time, AI can help defenders analyze privileged activity and identify suspicious behavior much faster.” Familiar principles, new identities Encouragingly, none of the experts believe organizations need to tear up the rulebook. “The security principles needed to secure these identities are not new,” says Guccione. “Organizations should apply the same zero-trust discipline to AI agents that they apply to people: verify every identity, enforce the principle of least privilege, eliminate unnecessary standing access, continuously monitor privileged activity, and protect and rotate credentials and secrets. Access should be granted only to the resources required for a specific task and only for as long as that access is necessary.” Cannava makes the same case, stressing that accountability ultimately sits with people. “The same security principles we’ve long applied to human access now need to extend to AI. At the end of the day, the nonhuman identity problem is still a human problem,” he says. “Organizations need to know who authorized an agent, what authority it has, and what it should be allowed to do. That means giving AI agents verifiable identities, clear ownership, and least-privilege access, with continuous authorization and accountability for their actions.” The key, he adds, is enforcement rather than intent. “Businesses should extend proven identity principles to machines acting on behalf of people and build those principles into controls that can actually be enforced.” For Marino, that continuity is the real lesson of the month. “The lesson for Cybersecurity Awareness Month is that cybersecurity fundamentals don’t disappear as technology changes – they evolve to meet the occasion. Privileged access will always represent concentrated risk. Effective PAM is about continually adapting how that risk is controlled as the identities, infrastructure and technologies around it change.” Awareness beyond October Guccione believes awareness itself has to evolve to keep up. “Cybersecurity awareness must evolve alongside technology. We have spent years teaching organizations that every employee identity requires governance. Now we need to extend that understanding to machines.” “The next frontier of cybersecurity awareness is recognizing that AI agents are users too,” he concludes. “Organizations that govern them accordingly will be far better positioned to capture the benefits of agentic AI without creating an unmanaged layer of privileged access.” Cannava, meanwhile, warns against treating the month as a one-off. “Cybersecurity Awareness Month is an important reminder to make security a priority, but it shouldn’t begin and end in October,” he says. “Looking ahead to secure the next 250 years, security cannot be in the spotlight for only one month. Leaders must build a culture of security and maintain visibility and control over every kind of identity year-round.”","https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F10\u002F02\u002Fcybersecurity-awareness-month-ai-agents-are-users-too-and-they-need-governing-like-it\u002F?utm_source=rss&utm_medium=rss&utm_campaign=cybersecurity-awareness-month-ai-agents-are-users-too-and-they-need-governing-like-it","https:\u002F\u002Fwww.itsecurityguru.org\u002Fwp-content\u002Fuploads\u002F2026\u002F10\u002FAI-Agents-in-a-Secure-Digital-Workspace.png","2026-10-02T12:53:56+00:00","2026-10-02T14:00:17.311956+00:00",7,[18,21,24,27],{"name":19,"type":20},"Keeper Security","product",{"name":22,"type":23},"Ping Identity","vendor",{"name":25,"type":26},"Privileged Access Management","technology",{"name":28,"type":26},"AI agents","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":29,"icon":31,"name":32,"slug":33},null,"AI Security","ai-security",[35,40,42,47],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":41},{"id":29,"icon":31,"name":32,"slug":33},{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":48},{"id":49,"icon":31,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]