A survey of 508 IT and security leaders employed by U.S. organizations with more than 1,000 employees published this week finds nearly all (95%) are relying on artificial intelligence (AI) agents to perform at least one IT or security task autonomously.

Conducted by ConductorOne, a provider of an identity management platform, the survey also finds that 96% of respondents said they planned to operationalize AI agents.

Additionally, 91% of respondents report that increased reliance on AI has led to increasing investments in identity access management (IAM) platforms, with 87% of respondents rating non-human identity risk as being either moderately to extremely urgent.

In total, 45% of respondents said they already use IAM tools to govern non-human identities, with another 45% planning to follow suit within the coming year. Just under half (47%) also report they are already managing more non-human identities than human users, but only 22% claim to have full visibility into those identities.

ConductorOne CISO Kevin Paige said the survey makes it clear that the rise of AI is likely to further exacerbate existing identity management issues that have long persisted in many organizations.

In fact, the survey finds 80% of respondents experienced at least one identity-related breach in the past year, with phishing and social engineering (52%) and malware or ransomware (46%) being the leading attack vectors. Top challenges include lack of visibility (47%), excessive privileges (40%), limited auditability (37%), long-lived credentials (33%) and tools that are not designed for agents (27%).

It’s not clear how proactively cybersecurity teams are going to be able to secure AI agents as the pace of adoption continues to accelerate. Many end users, for example, are downloading AI agents such as OpenClaw with little to no regard for the cybersecurity implications. The one thing that is certain is that adversaries will double down on stealing credentials that provide them access to AI agents that can then be used to not just exfiltrate data but also compromise entire workflows.

Regardless of those risks, most organizations are committed to adopting AI agents come hell or high water, noted Paige. Cybersecurity and IT teams, at the very least, should make sure that fundamental best cybersecurity practices are followed, including making sure that humans remain in the loop of any workflow, to minimize risk as much as possible, he added. Otherwise, it’s only a matter of time before a catastrophic incident reminds everyone why cybersecurity is still crucial in the age of AI, said Paige.

In the meantime, it’s important for IT and cybersecurity to have hands-on experience with AI agents, he added. It’s simply not going to be possible to secure them without knowing how AI agents access data to automate tasks, noted Paige. Cybersecurity teams will need to understand the architecture used to construct them, noted Paige.

Hopefully there will come a time soon when AI agents are simply just another type of identity that IT and cybersecurity teams have learned how to govern and secure. Until then, however, those same teams would be well advised to prepare for the worst while continuing to hope for the best outcomes possible.