As enterprises continue to rush to add AI agents to their workflows, they face an identity governance challenge they're not yet equipped to handle. Governance frameworks built for employees don't translate to machines, and most existing non-human identity systems, such as robotic process automation, don't address AI agents.
Yet, agents are inheriting human credentials, operating with highly automated agency, and accumulating access rights that are rarely fully understood. The exposure that follows doesn't show in conventional access reviews: a machine operating at speed, on borrowed trust, with no clear audit boundary between its activity and the employee whose credentials it's using.
Recently, the Linux Foundation took the helm at the Nvidia-initiated Open Secure AI Alliance, which brings together organizations to develop open tools, techniques, and standards for securing AI agents across enterprise environments. The membership reflects where much of the security industry sits: trying to build structural controls around a technology already being rapidly deployed and widely used.
Earlier this year, James Winebrenner, CEO of segmentation provider Elisity, held a customer CISO advisory board meeting, where CISOs said the convergence of authorized deployments and unsanctioned, employee-driven AI experimentation is creating an environment where the scope of agentic activity is poorly understood and poorly governed. Elisity joined the Open Secure AI Alliance this week.
Agentic AI deployments lack governance
Winebrenner sees a common theme playing out across enterprises: an AI agent running on a knowledge worker's behalf inherits that worker's credentials rather than operating under a properly scoped, agent-specific identity. Because the agent behaves non-deterministically and moves through rapid inference and highly automated actions, it carries access privileges the employee earned through years of tenure, human-level understanding, and organizational context the agent doesn't possess. Essentially, the agent can follow instructions but lacks the competence to make risk-based decisions. "And yet now they have wide-open access," Winebrenner said.
Winebrenner said Elisity is contributing to the alliance across three areas: establishing least-privilege access frameworks for sanctioned agents so that security controls can apply appropriate limits across platforms; building coordinated containment methods to limit blast radius when agentic activity goes wrong; and developing ways to identify and govern unsanctioned AI use: the shadow AI equivalent of the BYOD problem enterprises spent the previous decade managing. Elisity has been working with customers in early field trials for approximately two quarters, using network flow telemetry to detect agentic behavior and then quarantine it when it falls outside approved boundaries.
Whether standards can emerge fast enough may be harder than solving the technological hurdles. Winebrenner acknowledged that the development timeline for mature agentic identity frameworks risks paralleling the years it took previous identity protocols to achieve broad enterprise adoption: a runway the current pace of AI deployment doesn't have.
The organizations working on agentic AI security standards span government agencies, open-source foundations, and industry coalitions — with competing efforts backed by different subsets of the industry's largest players.
Government and Formal Standards Bodies
NIST launched its AI Agent Standards Initiative on February 17, 2026, alongside NCCoE work on agent identity and SP 800-53 control overlays for agentic systems, and is targeting ISO/IEC JTC 1 as the international venue for agent standards leadership.
The Five Eyes cybersecurity agencies, NSA, CISA, and their counterparts in the UK, Australia, New Zealand, and Canada issued joint guidance on agentic AI adoption in May 2026, and Canada and Singapore each published national agentic AI governance frameworks the same month.
Industry and Community Groups
The Open Secure AI Alliance was founded July 27, 2026 by NVIDIA with approximately 37 founding members, including Microsoft, IBM, CrowdStrike, Hugging Face, and Palantir, and joined the Linux Foundation as a directed fund project in September 2026. Notably absent: OpenAI, Anthropic, and Google.
While OpenAI, Anthropic, and Google are absent from the Open Secure AI Alliance, with each anchoring competing efforts, it illustrates the fragmentation challenges ahead, while also providing a counterweight to the frontier lab efforts.
The OWASP GenAI Security Project launched its Agentic Security Initiative in December 2024 and published its Agent Control Standard in September 2026.
The Cloud Security Alliance launched its CSAI Foundation in 2026 and administers the AI Controls Matrix, Agentic Trust Framework, and AARM specification.
CoSAI (Coalition for Secure AI) was announced in July 2024 at the Aspen Security Forum; founding sponsors include Google, IBM, Intel, Microsoft, NVIDIA, and PayPal, and the coalition is housed at OASIS Open.
The Agentic AI Foundation (AAIF) launched in December 2025 under the Linux Foundation, co-founded by Anthropic, Block, and OpenAI with support from Google, Microsoft, and AWS; it stewards open agent protocols including MCP.
The Blueprint Alliance was announced September 22, 2026 at Okta's Oktane conference; 12 founding vendors led by Okta including AWS, Google Cloud, CrowdStrike, Salesforce, ServiceNow, and Wiz are building an open multi-vendor reference architecture for agent security.
AIUC-1 launched in mid-2025 with more than 100 Fortune 500 CISOs as a certification standard for agent security, safety, and reliability, with quarterly updates built into its cadence.
The Confidential Computing Consortium, a Linux Foundation project, has formally engaged both NIST and UK government consultations on agent security.
Winebrenner believes appropriate enterprise procurement demands can drive acceleration. As large customers increasingly demand agentic identity and containment requirements in AI provider contracts, much as enterprises eventually forced accountability into cloud computing's shared responsibility model with AWS, Azure, and GCP. "It's going to take some big customers standing up and demanding better behavior from AI providers," he said.
For CISOs, many of the controls that matter most now,-network-level containment, least-privilege segmentation, telemetry-based visibility into what agents are doing,-don't require waiting for standards to solidify. They require treating agentic identity as a first-class governance problem, and plenty of work can be done before the frameworks are written.
