Posted 13 days ago

Machine Identity Vendors - AI Agent Delegation Solutions

Two days at Cybersec Netherlands in Utrecht, and one question followed me across the entire floor. Who owns the identity that is not a person? Some context: Cybersec Netherlands is the largest B2B security event in the Benelux, two days at Jaarbeurs Utrecht, roughly 10,000 visitors. The floor covered almost every domain in the field: OT and ICS security, threat intelligence, data protection, supply chain and resilience, compliance automation, digital sovereignty, and IAM. The theme that kept coming back was AI sitting on both sides of the table. Defenders using it for detection and triage, attackers using it to move faster than a SOC can respond. Mandy Andress of Elastic made the point in her keynote that compliance-driven security models are hitting their limit. That is exactly where non-human identity comes in. Service accounts, API keys, workload identities and now AI agents already outnumber human users in most enterprises. The market is clearly moving on it. Three examples from the floor: Elimity is mapping who can access what across both human and non-human identities, AI agents included, and turning that into access reviews an auditor will accept. Evertrust is doing certificate lifecycle management and sovereign PKI, which is machine identity at its most literal, while preparing customers for shorter TLS lifespans and post-quantum crypto. Kiteworks came at it from the data side. Their own research says most organisations already run AI agents in production, and a majority cannot enforce limits on what those agents do with regulated data, or stop one that misbehaves. Real progress. But look at what all three are solving: visibility, lifecycle, containment. The harder question sits one step further out. An AI agent receives delegated authority from a human and then acts on it. Who approved that scope? Who revokes it when the human leaves? Which control, in which framework, actually covers it? My MSc thesis is a gap analysis of that question across ISO/IEC 27001:2022, NIST CSF 2.0, SOC 2, the DORA RTS and NIST SP 800-53 Rev. 5. Three findings I keep coming back to: Not one of the five mandates a rotation cadence for machine secrets. All five are silent on agentic delegated authority. IA-9 in SP 800-53 is the only NHI-native control in any of them, and it is classified P0 and assigned to no baseline. So the tooling runs ahead while the frameworks still work from a registration-era model, where an identity is created once by a human and reviewed quarterly. Machine-speed sprawl walks straight past that. That gap is what I work on. Thesis goes in this month, and I am speaking on NHI governance at Identity Fabric Impact Day 2026. KuppingerCole Analysts If you were at Cybersec and saw a vendor with a real answer for agent delegation, I want to hear about it. Cybersec Netherlands #CybersecNetherlands #NonHumanIdentity #IAM #AISecurity #GRC #Cybersecurity
KuppingerCole Analysts logoKuppingerCole Analysts
Sourcee Logo

Brought to you by Sourcee

We find journo requests from across the web and deliver them directly to your inbox.

We Monitor the Web for Journo Requests