- Forbes Technology Council
- Posts
- AI’s Identity Crisis
AI’s Identity Crisis
Explore why AI leaders are getting breached more, why secure API gateways matter more than bigger models, and how agentic AI is pushing cybersecurity into an AI vs. AI era.
In today’s Tech Pulse, gain insight into how:
Early AI adopters are seeing a 43% breach rate as agentic identities explode faster than identity governance can keep up.
Enterprise AI agents stall in production when teams skip a secure API gateway control plane for policy, routing, and auditability, not when the model is too small.
Agentic AI is shifting cyber risk to “AI vs. AI”, making autonomous defense and board-level governance essential as attackers move at machine speed.
Each of these articles is penned by members of Forbes Technology Council, key luminaries shaping the future of technology leadership.
Grab your coffee, and let's dive in!
AI’s Identity Explosion Is Fueling Breaches
Early AI adopters are doing many “right” security fundamentals, yet they are still getting breached at dramatically higher rates. The key driver is not maturity. It is the sudden growth in machine and agent identities that legacy identity programs were never built to govern at deployment speed.
Here’s what stands out:
🤖 Breach Gap: Organizations where AI significantly increased identities reported a 43% breach rate vs 11% where it did not.
🔎 Not a Fundamentals Issue: Aggressive adopters reported better inventories, nonhuman identity governance, and shadow AI visibility, yet breaches remained higher.
🪪 New Identity Load: AI agents and integrations create fast, persistent identities that can inherit access immediately and linger long after the task ends.
⚡ Attack Speed Mismatch: Adversaries move in minutes, but only 23.5% can respond in real time; 62.9% still need 1 to 3 days.
🏢 Mid-market Squeeze: Companies with 500 to 999 employees saw a 40% breach rate, often constrained by budget and skills.

Still Interested in Forbes Technology Council?
As a member, you'll receive:
- Publishing Opportunities: to share your expert insights on Forbes.com through Expert Panels and bylined articles.
- Executive Profile: a professional, SEO-friendly profile on Forbes.com.
- Networking Benefits: access to a member portal to connect with other world-class technology leaders.
- And Much More: from premium travel and lifestyle benefits to exclusive virtual knowledge sharing events, members join to learn and grow with their peers.
Click the button below to continue your application today.

Before You Buy a Bigger Model, Lock Down the Front Door
Many enterprise AI pilots stall in production not because the model is weak, but because the system lacks a secure control plane. When leaders cannot answer which model call accessed which sensitive record, under what policy, with what audit trail, the rollout stops fast, especially in regulated environments.
Here’s the architecture shift to prioritize:
🚪 Secure Gateway First: Treat the API gateway as the “front door” with rate limits, schema validation, OAuth scopes, mutual TLS, and centralized logging.
🧱 One Model is a Master Key: A single LLM doing everything creates “ambient access” and removes natural choke points for authorization and auditing.
🧩 Use Specialized Models By Task: Small models for routing and classification, vision-language for document extraction, general LLMs for coordination, reasoning models for high-stakes exceptions.
🧾 Governed Tool Execution: Action steps should emit structured, authorized service requests, not free-form text that might become an API call.
🔐 Gateway Responsibilities: Policy-driven routing, least-privilege scopes, secrets hygiene, fail-closed fallbacks, and SOC-ready security-event logs.
Agentic AI Turns Cybersecurity Into AI vs. AI
Agentic AI boosts productivity, but it also expands the attack surface by enabling autonomous actions at machine speed. The same shift is forcing security teams to move from human-paced response to adaptive, AI-driven defense, with governance and accountability rising to the board level.
Key takeaways to know:
📊 Early Warning Data: IBM reports 13% of organizations have already had a breach involving AI models or applications, and 97% of those impacted lacked adequate AI access controls.
📜 Governance Gap: 63% still lack formal AI governance policies.
⚔️ Autonomous Threats Scale Fast: Agents can automate recon, vulnerability discovery, phishing customization, lateral movement, and iterative learning with minimal human involvement.
⏱️ Traditional SOC Models Fall Behind: Manual investigation and reactive response cannot keep up when exploitation timelines compress.
🛡️ Autonomous Defense Is Emerging: AI can detect anomalies, correlate signals, predict patterns, prioritize threats, and execute containment without waiting for approval.
Wrapping Up
If these articles sparked your interest, we have a network that you will absolutely love: Forbes Technology Council.
This exclusive, vetted community brings together the brightest minds in technology — founders, CEOs, CIOs, CTOs, CISOs, and other leaders of technology-focused teams.
Put yourself at the forefront of innovation with access to publishing opportunities on Forbes.com, a personalized, SEO-friendly Executive Profile, and the chance to network with other respected leaders in the field.
Join Forbes Technology Council today, and become part of a group driving transformation in technology.