A new Human-in-the-Loop authorization framework combines IBM WatsonX orchestration, Auth0 CIBA identity flows, and Yubico YubiKey hardware attestation to create cryptographically verified human approval for high-stakes AI agent actions.
HashiCorp publishes an agentic runtime security blueprint for solving AI agent identity and access gaps, arguing that static IAM models fail when agents chain actions autonomously across dozens of systems.
Proofpoint unveils AI Security — an intent-based solution that verifies whether AI agent actions align with their stated purpose — backed by a five-phase Agent Integrity Framework built on the Acuvity acquisition.
RSAC 2026 Innovation Sandbox finalist Token Security introduces intent-based security for AI agents, arguing that static permissions fail when autonomous agents are non-deterministic and goal-oriented.
1Password partners with Anthropic, OpenAI, GitHub, Cursor, and Vercel to launch Unified Access — a platform that manages credentials for AI agents alongside humans, with least-privilege controls and full audit trails.
Microsoft's 2026 Secure Access report reveals that nearly every enterprise suffered identity or network access incidents, with 70% linked to AI-related activity. AI agent privilege escalation is now a real-world threat, not a theoretical risk.
Oasis Security's Series B brings total funding to $195M for its Agentic Access Management platform. With machine identities outnumbering humans 82 to 1, the company is building least-privilege governance for AI agents at enterprise scale.
ConductorOne launches AI Access Management — a unified control plane for AI tools, agents, and MCP connections with 3,000+ hosted MCP servers, credential vaulting, and fine-grained tool call authorization. The pitch: if getting approved AI access takes 60 seconds, nobody needs shadow AI.
Entro Security launches Agentic Governance & Administration (AGA) for shadow AI discovery and MCP enforcement. Apono launches Agent Privilege Guard with Intent-Based Access Controls and zero standing privileges. Together, they map the full agent governance stack — both headed to RSAC 2026.
Netwrix expands its 1Secure platform to show how AI agents inherit human identity permissions to access sensitive data — because the problem isn't AI bypassing security, it's AI using the access that already exists.
F5's bot defense meets Skyfire's Know Your Agent protocol — letting merchants distinguish revenue-generating AI agents from malicious bots, and opening the door to agentic commerce at scale.
Deutsche Telekom's 'AI Agent Ready' initiative aims to give every AI agent a digital identity, security clearance, and behavioral boundaries. With enterprises expecting tens of millions of agent identities, DT is betting that telcos — not cloud providers — should be the trust layer.
Okta unveiled its blueprint for the secure agentic enterprise: shadow agent detection, universal directory for non-human identities, an agent gateway for MCP servers, and a kill switch that can revoke all agent access instantly. Launches April 30, 2026.
SailPoint and AWS announced a strategic collaboration to build a unified identity governance layer for AI agents, integrating with Bedrock AgentCore and creating a single identity graph for human and non-human entities.