Summary
- Kocho’s Microsoft Identity Security Summit focused on AI-era identity, data protection, threat detection, and non-human identity governance.
- The supplied release says AI agents and automated services are increasing identities, permissions, and data access points inside organisations.
- Every agent, service account, connector, and automated workflow needs accountable ownership, access monitoring, and lifecycle control.
Kocho has warned that AI agents, automated services, and other non-human identities are expanding enterprise access faster than many organisations can govern, monitor, or hold accountable.
The warning follows Kocho’s Microsoft Identity Security Summit in London, where identity, security, and technology leaders discussed the controls needed as AI agents become embedded across business environments. Kocho’s summit agenda included sessions on AI-era security, agentic technology, modern identity threats, insider risk, and securing non-human identities for AI automation and IoT.
The supplied Kocho material says more than 150 identity, security, and technology leaders attended the event. It also cites figures indicating that non-human identities can outnumber human identities by as much as 144:1 in large organisations, while IDC forecasts suggest organisations could be using 1.3 billion AI agents by 2028.
AI agents and automated services need access to data, applications, workflows, and infrastructure in order to be useful. Once they can retrieve information, update records, trigger tasks, call APIs, or act on behalf of a user, access decisions become operational risk decisions. An unmanaged agent is no longer only a productivity concern; it is a route through which data can be exposed or actions can be taken without clear accountability.
Kocho’s public AI governance material argues that autonomous agents need owners, boundaries, and lifecycle control. Agent governance weakens when agents are created quickly but ownership, permissions, and lifecycle processes remain unclear. Joiner, mover, and leaver controls are often designed around employees rather than machine identities, agent accounts, service principals, connectors, and automated workflows.
Data exposure becomes harder to manage when AI can search, combine, and act on information across enterprise systems. If collaboration sites are overexposed, files are poorly classified, or sensitive information lacks retention and loss-prevention controls, an AI agent may produce outputs based on information the organisation should not use in that context.
Threat detection also needs to account for stronger identity-based attacks. Deepfakes, voice cloning, service desk compromise, and convincing social engineering can help attackers obtain credentials or authorise changes through processes designed around human trust. Once access is obtained, legitimate routes into systems and data may be used in ways that look normal unless behaviour is monitored.
The controls are familiar but need to be applied to a different population of identities. Organisations need to know which agents exist, who owns them, what systems they can reach, which data they can access, whether that access is still justified, and how activity is logged. Microsoft-centric organisations may already have parts of the control stack in Entra, Purview, and Defender, but those tools need to be configured around agents and non-human identities as well as employees.
Agentic AI adoption will be safer where every agent has a defined purpose, accountable owner, permission boundary, monitoring model, and end-of-life process. Pilots that begin in business units inherit enterprise risk once they touch proprietary data, privileged workflows, or live processes.




