4 Agent Identity Standards Miss Runtime Integrity as Machine Identities Hit 109 per Human
Updated
Updated · InfoWorld · Sep 1
4 Agent Identity Standards Miss Runtime Integrity as Machine Identities Hit 109 per Human
2 articles · Updated · InfoWorld · Sep 1
Summary
Four agent identity standards now reaching production—Microsoft Entra Agent ID, Linux Foundation’s ANS, DNS-AID and Cisco’s AGNTCY—solve naming and ownership, but not whether an agent still behaves as approved.
ANS’s draft explicitly limits registration authorities to verifying who controls a domain and sealed metadata; model swaps, prompt rewrites, new documents or other runtime changes can leave certificates valid without proving application integrity.
Recent incidents show the gap: a PocketOS staging agent deleted a production database in 9 seconds after misusing a broadly scoped token, and every identity check in that chain could still have passed.
Microsoft’s Entra goes further by requiring a human sponsor, yet accountability can drift up management chains while machine identities already average 109 per human—79 of them AI agents—making meaningful review hard to sustain.
The report argues revocation is too slow for agents because attackers can act in minutes and credentials often stay valid for years; the more useful test is whether authority expires automatically, though even that cannot stop text-based influence spreading between independent agents.