The auditors are already writing the questions.
None of these regimes were written with AI agents in mind, and all of them now reach agents anyway. Access control and record-keeping requirements don't stop at the edge of a human workforce.
Article 12 — record-keeping
Operational risk controls
CC6 — logical access
A.5.15 — access control
Govern & Measure
Restrict privileges
Least privilege for agents is the same argument that built a twenty-billion-dollar identity industry for people.
Adoption is outrunning governance.
Agent rollouts are accelerating inside every function.
The control gap widens every quarter you wait.
The model vendors can't referee themselves.
Most enterprises already run agents from several vendors at once.
None of them can credibly police the others — a neutral layer can.
Human identity tools weren't built for this.
Agents need per-task credentials and intent-aware policy.
Legacy IAM has neither, and no replayable record of what ran.