Zero Trust was built to evaluate access one request at a time. Autonomous agents chain those requests faster than static policies can process, and the gap is architectural, not a tuning problem.
That is the argument from Nik Kale, a CoSAI contributor on agentic identity, in a CSO Online feature by Evan Schuman published Sep. 3, 2026. His point: an agent can read a document, query a source, summarize it, write a file, and email it externally. Each step is individually authorized, adding up to an exfiltration nobody approved as a sequence.
Kale adds an identity-drift problem. Model updates, new tools, accumulated memory, and delegation can change an agent’s real capability without re-triggering approval. In his words, “you can have a materially different machine on Friday wearing the badge than what you approved on Monday.”
For security architects who already own NIST 800-207 deployments, the near-term move is not another control purchase. It is authorization scoped to the session and the sequence, not the single decision, plus continuous re-validation tied to an agent’s current capability state rather than its credential.
Treat delegation as unsolved. The piece asserts that subagents can inherit an originator’s privileges without a recognized identity and that no vendor has closed agent-to-agent visibility. That is a single-sourced, sweeping claim, so verify it before procurement, but plan as if subagent lineage and delegation scope are gaps your IAM and PAM tooling do not yet cover.
Source: CSO Online



Leave a Reply