As Cybersecurity Awareness Month begins, Keeper Security executives are urging organisations to extend identity governance to AI agents, which can now sign in to systems, retrieve data and run workflows at machine speed.
AI agents as privileged identities
Darren Guccione, Keeper’s chief executive and co-founder, said companies are deploying AI agents without applying the identity governance they expect for employees, contractors or administrators. Organisations can add hundreds or thousands of non-human identities far faster than they onboard staff, he said, and an agent with standing credentials or broad permissions widens the attack surface just as quickly. A compromised agent with privileged access could give an attacker direct entry to critical systems.
His answer is the same zero-trust approach used for people: verify every identity, enforce least privilege, remove unnecessary standing access, monitor privileged activity, and rotate credentials and secrets. “AI agents are users too,” Guccione said.
Privileged access management moves beyond the vault
Michael Marino, Keeper’s senior vice president of strategy for identity security, said privileged access management (PAM) once meant locking administrator passwords in a vault, when infrastructure was mostly on-premises. Keeper research from 2025 found 94% of organisations operate in hybrid or cloud-first environments.
Marino said modern PAM has to control when privileged access is granted, what can be reached and what happens during a session, using least privilege, just-in-time access and zero standing privilege. He said AI agents are creating privileged access faster than security teams can manage by hand, though AI can also help defenders spot suspicious activity.
Deepfakes and personal security
Anne Cutler, a cybersecurity expert at Keeper, said deepfakes are no longer just an internet novelty. Attackers can use AI to imitate a person’s voice, appearance or writing style, making requests for money or credentials more convincing.
Her advice is to verify unusual or urgent requests through another trusted channel, call back on a number you already have, never share passwords or multi-factor authentication codes in response to an unsolicited request, and use strong, unique credentials with MFA.



Share your thoughts