“AI transformation is exciting. Identity hygiene is not,” said Roy Katmor, co-founder and CEO of Orchid Security. “Boards are no longer asking whether AI will be adopted—they are asking why it is not moving faster, and security cannot answer with a blanket ‘no.’ Enterprises need to observe how agents act, understand when they drift, and govern them immediately, including terminating the authority through which they operate.”
The problem was never how agents behave. It is what they inherit. Exceeding an intended scope requires no circumvention of controls — agents simply locate the identity debt that has piled up over years: embedded credentials, abandoned accounts, unmanaged authentication routes, and over-broad entitlements. Orchid’s Identity Gap 2026 research put 57% of enterprise identity in the unseen and unmanaged category. That identity dark matter can be turned by an agent into a live route to elevated access within seconds or minutes — a pace that periodic governance reviews cannot match, let alone contain.
Governance has consequently moved from stated intent to operational proof. Approving agentic AI in a board resolution tells a CISO nothing about which applications an agent may safely touch, which service accounts carry standing privilege, or which delegation chains would hold up under regulatory scrutiny. Converting mandate into measurable control is exactly the point at which most AI programs stall.


