Non-human accounts unseen and unmanaged (all non-human accounts, not only AI agents): Two-thirds (Source: Unnamed research as summarized by Orchid Security in its IAM for AI agents guide (republished by The Hacker News, September 28, 2026))
Orchid Security argues that access rules show what an AI agent may do, not what it did. Its new guide says identity systems cannot close that gap on their own. The claim is worth testing against your own setup, because it changes what "under control" means for an agent.
Permission is not behavior
An old-style service account runs one hard-coded task. An AI agent is different. Orchid's guide says it takes a goal, reasons about it and picks actions at runtime, across tools, data and interfaces.
That breaks a common assumption. Identity systems record what an account is allowed to touch. They do not record what the account did inside each application. Orchid calls the space between the two the gap between intent and execution.
The guide offers an example. A support agent reads customer records, tickets, chat logs and a knowledge base. It may need only tickets, yet it holds broad knowledge-base access. If someone poisons that knowledge base, the agent acts on bad data while staying fully inside its permissions. A review of its settings alone would likely find nothing wrong.
The lesson here is that a permission list is a statement of trust, not evidence of conduct. Think of a contractor with a key card. The door log shows which doors opened. It does not show what the contractor did in the room.
What Orchid recommends
The guide does not propose a new standard. It says to extend the identity controls companies already run, drawing on NIST SP 800-53 families and threat lists from OWASP and MITRE ATLAS. Its core practices are plain:
Give every agent its own identity, never a shared or borrowed human login. Name a human owner for each one. Limit access to the tools and data the task needs, and prefer short-lived credentials over standing keys. Require a named person to approve high-impact actions, such as production changes, privilege grants and financial transactions above a threshold.
The guide also warns about chains. Agents can spawn short-lived sub-agents. Each one is a new access path, and its authority should not exceed that of the agent that created it.
Weak spots the guide says agents expose
The guide says agents expose identity weaknesses that existed before but were tolerable at lower scale. It lists ownerless accounts, broad permissions that never get trimmed, and shadow agents that teams deploy faster than security can inventory them.
On ownerless accounts, the guide points to research without naming it. Orchid relays a finding that about two-thirds of non-human accounts go unseen and unmanaged. That figure covers non-human accounts in general, not AI agents specifically. The guide gives no sample size or date for it.
Orchid also publishes figures from its own analysis of applications. These are not about AI agents. They describe the identity foundations agents would sit on.
The guide does not describe how many applications were analyzed or when. Treat the figures as Orchid's own findings, not a survey of all companies.
Read it with the seller in mind
Orchid sells a platform that finds identities inside applications. The guide's conclusion favors that approach, and it ends with an invitation to book a demo. Its build-versus-buy table shows vendor positioning, and the guide itself says capabilities vary and should be tested in your own environment.
That does not weaken the core point. It does mean leaders should judge the control model separately from the product.
Questions to put to your team
First: how many AI agents run in our systems today, and who owns each one? If the answer is an estimate, that is the first finding.
Second: can we see what an agent did inside an application, or only that it signed in? The guide says logs from the identity provider record logins, not in-application actions.
Third: which agent actions need a named human to approve them, and is that rule enforced or only written down?
Fourth: when an agent's task ends or its owner leaves, what revokes its access? The guide stresses removing the identity, its tokens and its tool connections, since partial retirement leaves usable remnants.
Orchid says many enterprises deploying agents sit at its early maturity levels while their risk argues for more. That is the vendor's view. The questions above let you test it yourself.
An agent's permissions tell you what you trusted it with. Only its activity record tells you what it did with that trust.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Orchid Security.





