Akeyless published survey research this month covering 400 IT and security leaders globally on the state of AI agent identity security. The headline finding is worth sitting with: only 7% of organisations believe their existing controls could prevent a compromised AI agent from operating maliciously or outside its intended behaviour.¹
That is not a gap. It is near-total absence of control over a technology that 94% of those same organisations have already deployed, with more than 80% confirming their agents can access sensitive data.
The credential picture makes the exposure concrete. Every organisation surveyed uses persistent credentials for agent access: API keys, static secrets, OAuth tokens, service accounts. Only 45% use short-lived credentials at all. More than two thirds already suspect their agents have accessed data beyond their intended scope. When something does go wrong, the average detection time is 14 hours, followed by nearly a week to contain and remediate. Average annual cost of AI agent identity incidents: over $1 million.
The Akeyless report frames the solution around ephemeral credentials, continuous visibility, and runtime enforcement. These are necessary and legitimate controls. They address how agents authenticate and what they are technically permitted to access. A secrets management and identity platform reduces the blast radius when credentials are compromised and limits what an agent can reach in the first place.
What they do not address is what happens when an agent with valid credentials and correct permissions reaches a high-consequence action threshold. Ephemeral credentials do not stop a legitimately authenticated agent from initiating a wire transfer. Dynamic permissions do not prevent a correctly scoped agent from deleting a production database if deletion is within its permitted scope. Runtime enforcement at the identity layer tells you what the agent is allowed to touch. It does not require a named human to confirm that this specific action, against this specific payload, at this specific moment, should proceed.
This is the gap the 7% figure exposes. Organisations have some visibility into what agents are doing. They have almost no mechanism to stop a compromised or drifting agent from executing the action that causes the irreversible harm, because no such mechanism sits at the execution boundary.
GoFirm sits at exactly that boundary. When an agent reaches a configured consequential action threshold, GoFirm routes a confirmation request to the named human authority on their registered personal device through a channel architecturally separate from the agent environment. The authority confirms with their biometric. The agent receives a signed verdict. No confirmation means no execution. A compromised agent with valid credentials and correct permissions still cannot produce that biometric confirmation from the named authority's registered device. The action stops.
The Akeyless survey notes that organisations expect AI agent usage to increase another 44% over the next 12 months. The 7% figure is not going to improve by adding more identity infrastructure to the stack. It improves when the execution boundary has a control that does not exist yet in most organisations: a hard halt, a named human, a biometric confirmation, and an immutable record that proves it happened.
Identity governs access. GoFirm governs execution. Both layers are necessary. Right now only one of them exists at scale.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligations in seconds, not days.
References
1. Akeyless, New Research Shows AI Agents Are Outpacing Identity Security, May 2026, https://www.akeyless.io/blog/2026-ai-agent-identity-security-survey/
