451 Research report: How agentic AI is redefining identity security

by 1Password
August 20, 2026 - 4 min

Related Categories
In the short time that AI agents have been a part of the enterprise, they have upended many of our bedrock assumptions about the nature of identity, access, development, and work itself. At 1Password, we’ve been in the trenches of the agentic revolution; we’ve seen its positive impact on productivity, and the serious concerns it raises about security. We’ve worked to build solutions that both harness AI’s potential and rein in its risks, and watched customers and colleagues grapple with the same issues.
In order to better understand how the industry at large is facing the agentic moment, 1Password commissioned a Vanguard Report from 451 Research, titled A new access model for the agentic enterprise. The report describes how agentic AI is redefining access and identity, and lays out what C-level leaders can do to ensure a smooth transition to this new paradigm. Its core recommendations include:
Start with discovery and visibility of AI agents and poorly governed non-human identities (NHIs).
Move to just-in-time credential delivery, rather than static credentials and standing privileges.
Implement guided remediation for developers so they can address NHI and agentic risk without interrupting their workflows.
Ensure full auditability and clear attribution that ties every action to a specific human or agent identity and authorization context.
Read on to explore the report’s findings, or download the full report here.
An expanding identity perimeter, with agents already inside
A new access model for the agentic enterprise begins by establishing that agentic AI is already deeply embedded in the enterprise. 69% of enterprises they surveyed have deployed AI agents, and 90% plan to do so within the next two years (these findings align with 1Password’s own research on agentic adoption).

But while agents became ubiquitous almost overnight, the tools and strategies to secure them have not kept pace. This on its own isn’t unusual; the report reminds readers that this “pattern has repeated with every new technology advance of the past two decades.” Yet AI agents are unique in some crucial ways that set them apart from earlier revolutions in SaaS, cloud computing, and automation.
“What makes agentic AI distinctly challenging to secure is not its scale but its unpredictability. Agents’ non-determinism breaks the core assumption of traditional access policy – that administrators can define in advance what a given identity should and should not do.”
Adding to the complexity are developer workflows, which rely on NHIs like service accounts and API keys. These credentials are often poorly secured – 71% of developers use unsecure methods for handling NHIs – and they exist outside the visibility of IT and Security teams. Vulnerable and compromised NHIs have been a source of risk and friction for years, and that risk is multiplying as AI agents use them to take actions on the backend of corporate systems.
How to redefine access for the agentic enterprise
The next generation of access control has to work for humans, machines, and agents, while accommodating the non-determinism that sets agents apart. As the report explains, traditional IAM and PAM solutions are “structurally inadequate” for this world, and adjusting to it requires nothing less than a paradigm shift.
“The organizations that successfully navigate this transition will treat it as an architectural reset – rethinking identity security from the ground up to govern people, machines, and agents in a unified way, with a single control plane that integrates governance, policy management, and auditing.”
The report lays out a list of “fundamentals” that every organization must get right to meet the challenge of this moment. Among the non-negotiables are:
Visibility into every agent and credential in use, including plaintext secrets embedded in config files and on local disks.
A single system of record for credentials, “spanning human users, service accounts, machine identities, and AI agents.”
Grounding identity security in runtime authority, which means continuously evaluating an identity’s behavior against expected parameters and dynamically enforcing access barriers. (This is particularly crucial for agents, in order to contain the risks of non-determinism.)
Advice for leaders on the agentic security transition
451’s report closes with C-level guidance for managing this transformation on an organization level. It recommends getting cross-functional buy-in from every technical team, since they’re both using agents and responsible for securing them. Likewise, it advises that leaders work to enable developers, and to design governance policies and workflow integrations that “make secure agent provisioning the default, not an additional burden on top of delivery pressure.” This advice is aligned with 1Password’s longstanding commitment to “make the secure path the easy path.” Even in a security landscape undergoing such a profound transformation, that philosophy still holds true.
Want to read the full report?
Want to learn how 1Password is building the future of identity security for humans, machines, and AI agents?

