Securing the Agentic Era: AI Agents as First-Class Security Principals

TL;DR AI
2 min readKey summary
Enterprises are running many unreviewed AI agents, with the author finding 47 agents and only six reviewed in one environment.
Vendors including GitHub, Microsoft, Cloudflare, and Scalekit released differing architectures to address agent identity and authorization.
Recommended practices include isolating agents with zero secrets, using per-action capability tokens, and treating injected data as potentially permanent.
