For years, CISOs have focused on securing human identities and, more recently, machine identities. But a new, invisible threat is expanding the attack surface at an unprecedented rate: the autonomous AI agent.
These digital colleagues, now embedded in customer service, finance, and operations, are creating what industry experts call "identity dark matter"—real, powerful identities operating completely outside the traditional governance fabric.
The scale of the problem is staggering. A 2025 SailPoint study revealed that 82% of organisations already use AI agents, yet only 44% have policies in place to secure them. This governance gap is not a future risk; it is a present one.
Alarmingly, 23% of organisations report their AI agents have been tricked into revealing access credentials, and 80% of companies say their AI agents have taken unintended actions, including accessing unauthorised systems or resources (39%) and accessing or sharing sensitive data (31-33%).
The core problem is architectural. Legacy Identity and Access Management (IAM) was built for predictable human workflows, not for autonomous agents that plan and execute multi-step tasks at machine speed.
As IBM notes, "AI agents reason, act, and accumulate access independently. Legacy IAM wasn't built for that". These agents don't join through HR, request access, or retire accounts. Instead, they operate on standing credentials, accumulate privileges over time, and chain actions across multiple systems, making their activities nearly impossible for security teams to interpret in real-time.

John Morgan, senior vice president and general manager of Security at Splunk, warns that the inventory problem is more severe than most leaders realise. "One of the biggest issues we're seeing today is that organisations have countless agents in their environment they didn't even know about," he states. "You can't protect something if you don't know it exists."
This situation is exacerbated by the rapid adoption of autonomous agents across cloud environments. In Hong Kong, the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) has identified "AI-driven attacks and agentic AI risks" as one of the top five cybersecurity risks for 2026.
HKCERT warns that agentic AI systems—which possess autonomous learning and execution capabilities—"can make judgments and act on their own without human intervention. Once hacked, they will carry out potentially malicious commands automatically." This makes such attacks "harder to predict and defend against."
For Southeast Asian enterprises, the risks are amplified by the region's complex IT environments and digital adoption rates. In Singapore, Mimecast's State of Human Risk 2026 found that 61% of IT and security decision-makers said an AI-enabled attack on their organisation is inevitable within the next 12 months, yet 69% said their organisations are not fully prepared to handle AI-driven threats that exploit human vulnerabilities.

Patrick Dannacher, CEO of ITSEC Asia, reinforces this regional concern. He warns that the threat landscape has undergone a fundamental shift: "It's quite frequent that we see AI-enabled attacks which are very persistent, very targeted, and round the clock. A human needs a little bit of sleep... The machines only need electricity."
He also highlights how AI lowers the barrier to entry for malicious actors: "With a little bit of prompt engineering, you will be surprised at how you can easily motivate certain AI models to support cyber-attacks".
The solution, experts argue, is to reclassify AI agents as high-risk non-human identities fundamentally.
The solution, experts argue, is to fundamentally reclassify AI agents as high-risk non-human identities. Morgan advises CISOs to treat agentic AI like a new, highly privileged employee: "Assign identity and governance—authentication, authorisation, and access control.
"You need to break up what one human used to do into several agents doing one job. That's called separation of duty, and it's really important from a security perspective." John Morgan

Tim Freestone, chief strategy officer at Kiteworks, emphasises that the governance gap requires an architectural response: "Organisations have deployed AI far faster than they've built the governance infrastructure to manage it. The incidents have already happened, and the compliance consequences are already being felt.
The path forward is architectural. It requires a data policy engine that enforces controls at the data layer for every person and every agent alike, not behavioural policy people can route around." Tim Freestone
IBM's approach echoes this need for a new security paradigm. As agentic AI adoption accelerates, the company states that "organisations face unmanaged AI agents, shadow access risks and an entirely new attack surface".
To address this, IBM has developed solutions to help organisations "secure agentic AI while maintaining speed, innovation and trust" by moving from standing credentials to just-in-time, short-lived credentials scoped to each specific task.
The Kiteworks survey identified seven priorities for closing the governance gap, including classifying and enforcing sensitive data, deploying AI-specific data loss prevention through a centralised policy engine, implementing and testing an AI kill switch, building audit trails that meet regulatory production timelines, and assigning dedicated AI data governance ownership.
The message is clear for CISOs in Singapore, Hong Kong, and across the region: the window to get visibility and control over agentic AI identities is closing.
Morgan cautions: "The real power of AI is in changing AI-native workflows—not as bolted-on supplements, which is how it started. As enterprises embed AI into revenue or business-critical workflows, it introduces new attack surfaces and unpredictable model behaviours."








