The AI Era Is Putting Enterprise Identity To The Test

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
AI-driven vulnerability discovery is changing enterprise identity security. Here's why identity resilience matters when remediation can't keep pace.

gettyA strange thing happens when software can be examined faster than people can fix it. AI causes vulnerability backlogs to pile up, while the path from discovery to a deployed fix remains stubbornly human.

Anthropic’s Project Glasswing granted limited access to Claude Mythos Preview after it showed unusual exploit abilities. By May, Anthropic noted that approximately 50 partners identified over 10,000 high- or critical-severity vulnerabilities, outrunning capacity to patch them.

​That should command the attention of every CIO and CISO, including leaders whose organizations will never use Mythos. AI is compressing the time available to understand exposure and contain it. The quality of an organization’s identity controls will shape how much damage a newly discovered weakness can cause.

As vulnerability discovery accelerates, organizations cannot assume every exposed weakness will be remediated immediately. The question becomes which weaknesses can reach privileged identities and trusted systems.

​In many enterprises, Active Directory and Microsoft Entra ID are where trust becomes operational. They determine whether a person can sign in and how much authority a workload carries. Enterprise AI agents need an identity or delegated identity through which they can access resources and act, often an account or service principal connected to the same systems the business already depends on.

​Identity resilience means preserving that trust under pressure and rebuilding it after compromise. That definition matters because AI operates inside the same complicated environment as every other workload. It inherits the privilege sprawl and hybrid complexity already present.

​This is ultimately a resilience problem. Organizations cannot assume every vulnerability will be found and fixed before exploitation. The ability to preserve trust during an incident and restore it afterward becomes just as important as prevention.​

​The urgency of a vulnerability depends heavily on the authority attached to the affected identity. A flaw in an isolated tool may have limited reach. A similar flaw inside an automated process that can modify directory policies could become an enterprise-wide event. Identity context tells the security team which finding can wait and which one can reach the systems that keep the business running.

​Without an updated map of privileges, teams receive volume without direction—a dangerous position when AI surfaces weaknesses rapidly.

​Privilege reduction must precede crises. Removing standing access reduces blast radius and buys time, while quick access withdrawal across hybrid environments blocks attacker pathways.

AI adoption is adding another layer of pressure inside the identity estate. Every autonomous agent needs an identity before it can act. Its permissions often expand as the business finds new uses for it. The original owner changes roles. The project ends. The access remains.

​We have lived with orphaned service accounts for years. AI can create the same debt on a much shorter clock.

​Each AI identity should enter the environment with a named human owner and a narrow business purpose. Its access should expire when that purpose ends. Accountability becomes far easier during an incident when the response team can trace an action back to the person who authorized the agent.

​Autonomy also changes the consequences of a bad decision. A person may stop when a system begins behaving strangely. An agent can continue acting across connected systems. A compromised credential may travel much further before anyone notices, especially when the agent has been given broad authority in the name of efficiency.

​Governance needs to reflect that speed. Logs can explain what happened after the fact. Clear ownership and tightly scoped authority help limit what can happen in the first place.

I have seen enough identity incidents to know that the most difficult moment often comes after the initial containment. The team still has to determine whether it can trust the directory guiding the recovery.

​Active Directory and Entra ID frequently authenticate the responders themselves. They also reconnect the applications needed to resume operations. When an attacker has altered those systems, the recovery effort may depend on a compromised source of truth.

​A backup can carry malicious changes forward. Bringing domain controllers online before validating their integrity can restore the attacker’s persistence along with them. Recovery must begin from a known-good state and end with evidence that unauthorized changes are gone. It should follow an isolated path that limits contact with the compromised environment.

​During a real incident, nobody on the bridge cares which model topped a benchmark. They need to know when employees can safely sign in again. They need confidence that restored accounts will not give the attacker a way back.

​A meaningful recovery objective measures the time required to return a trustworthy identity service to production. Server uptime alone says very little about whether trust has actually been restored. The recovery process should be rehearsed under realistic conditions so hidden dependencies emerge while there is still time to address them.

​That standard changes the board-level conversation. Recovery becomes a measurable operating capability rather than an assumption buried inside a security plan. Identity downtime is business downtime, and it can halt human work and automated processes at the same time.

The gap between vulnerability discovery and remediation is likely to widen as AI expands security testing. Resilience matters because AI dramatically accelerates the scale, speed and economics of exploiting weaknesses.​

​Identity resilience gives leaders a practical way to absorb both changes. It limits the authority available for an attacker to exploit and gives the business a credible path back when trust is broken.

​Organizations that build this foundation will be able to move faster with AI because they remain in control of who and what has authority. Every AI action begins with permission, and every permission rests on trust. The leadership task of the Mythos era is to make that trust durable enough for machine-speed change and recoverable when an attacker breaks it.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/29/the-ai-era-is-putting-enterprise-identity-to-the-test/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business