TL;DR: Agentic AI security requires identity intelligence, continuous threat detection, governance rooted in least privilege, and tested recovery. The Hugging Face breach shows what happens when an autonomous agent operates without any of it.
Recently, OpenAI disclosed what it called an unprecedented cyber incident. During a security test, models running with reduced guardrails broke out of an isolated sandbox, discovered a previously unknown vulnerability, and exploited it to access Hugging Face, one of the world’s largest repositories of AI models and datasets. OpenAI said the agent pursued a narrow testing goal so aggressively that it ended up executing state-of-the-art cyber capabilities against a real target it was never authorized to touch.
Hugging Face called the breach unlike anything it had handled before, driven end-to-end by an autonomous AI agent.
The agent found a path to credentials and infrastructure it shouldn’t have been able to reach, and nobody caught it while it was happening. AI agents inherit every identity weakness already present in an environment, and they exploit it faster than a human ever could.
Enterprises have spent decades addressing that kind of identity risk for human accounts and service accounts, and now they must do the same for agentic ones.
Here are four capabilities organizations need for agentic AI security, and how Quest Software can help:
1. Identity intelligence
Non-human identities already outnumber human users in most enterprises, and their numbers keep growing as organizations deploy more AI agents. The identities with the most access are often the ones nobody is watching: non-human and agentic identities hold standing privilege to critical systems and operate with no one reviewing what they touch, and up to 60% sit dormant while that access stays live. The Hugging Face incident involved a non-human identity operating with access nobody was actively watching. Most security teams still lack a clear, continuously updated view of what these identities are, what they can reach, and whether they should still exist.
The risk isn’t any single account; it’s what that account is connected to. A dormant service account inherits rights from a group that opens a system holding another account’s credentials, and that account holds full control of the directory. Every link is legitimate on its own. Together they form a live route into your most critical systems, and it already exists. Permission views and periodic scans show how access was configured, never how it’s actually used, so the route never appears in either one.
Quest’s acquisition of Anetac brought AI-powered identity discovery into the Quest Security Management Platform, extending visibility beyond traditional directories into access chains and privilege inheritance across human, non-human, and agentic AI identities. Instead of periodic audits or static inventories, organizations get continuous discovery and classification of every identity in the environment, including the ones nobody remembers creating.
Every other security capability depends on that visibility. Organizations cannot govern or monitor identities they do not know exist.
2. Continuous threat detection
The Hugging Face agent wasn’t flagged by a one-time access review or an annual credential audit. The compromise unfolded through behavior that evolved over time. Provisioning an identity correctly on day one says little about what that identity may do on day two, especially when the identity is an agent capable of adapting its approach.
Quest Identity Defense continuously monitors identity behavior across Active Directory and Entra ID, capturing the who, what, when, where, and originating workstation behind every change. For agentic AI identities, that context helps distinguish authorized automation from a hijacked or runaway agent, since the difference usually comes down to subtle behavioral drift.
When compromise is suspected, Identity Defense’s Shields Up capability freezes changes to critical identity assets, giving security teams total response control while an incident is still active. No endpoint tool, no backup tool, no SIEM, no other identity vendor can block a malicious directory change at the moment it happens. Only Quest can, because Quest operates in the control plane itself, blocking the change from being written, not just detecting it after the fact. That’s identity-layer protection that CrowdStrike, Microsoft Defender, and your SIEM can’t reach, working alongside them, not replacing them.
3. Governance and least privilege
OpenAI’s own account of the incident points to a governance gap. An agent running with reduced guardrails found ways to connect to the internet without human direction and reach systems well outside its intended scope. Whatever the intent behind the original test, the outcome was an over-privileged, under-governed identity doing exactly what over-privileged identities have always done when nobody enforces least privilege.
As enterprises hand more work to agents, agentic AI security demands the same lifecycle discipline as human accounts, with entitlements provisioned deliberately, reviewed regularly, and revoked the moment they’re no longer needed. The Quest Security Management Platform extends governance controls to non-human and agentic identities alongside human ones, helping organizations enforce least privilege, flag standing access that has outlived its purpose, and prevent entitlement sprawl from becoming an unmonitored attack path. Governance is what keeps a well-intentioned agent from ever having the reach it would need to “go rogue” in the first place.
4. Recovery and resilience
Everything the business runs on — databases, files, applications, endpoints, and now AI agents — authenticates back to Active Directory or Entra ID. They are the single point of truth for who and what is allowed to act, and in the AI era that point of truth has more dependents than ever, because every agent, every workload, and every automation also needs to authenticate. When AD or Entra goes down, nothing recovers cleanly until they do. During one of the worst publicly reported AD ransomware attacks, a Maersk IT staffer put it plainly: if they couldn’t recover their domain controllers, they couldn’t recover anything. That’s still true today, except now organizations are recovering for a world with orders of magnitude more non-human identities depending on it.
Even a well-governed, well-monitored environment can be compromised. Once identity systems are touched, restoring trust in Active Directory and Entra ID becomes the real test of agentic AI security resilience, and that recovery has to avoid reintroducing the same malicious changes it’s meant to undo.
Quest Identity Recovery delivers automated recovery of hybrid AD and Entra ID environments to a known-good, trusted state, without dragging compromised changes back in with the restore. From granular object-level recovery to full environment rebuilds, customers see up to 90% faster identity recovery and a 44% improvement in identity MTTR, backed by testing and validation. That validation is where most organizations fall short: more than 75% of organizations admit they lack a tested recovery plan, and Quest’s data shows only 24% test their identity disaster recovery every six months. If AD or Entra went down tomorrow, most teams could not say how long they’d be out or what the outage would cost. As agents make incidents unfold faster than teams can manually keep up with, recovery speed shapes the outcome for the business.
Building agentic AI security through identity
AI agents do not create entirely new identity risks. They accelerate risks that already exist. Unclear visibility, unmonitored behavior, excessive privilege, and untested recovery all become more dangerous the moment an autonomous agent is operating with them. Agentic AI security starts with applying identity security to every identity in the environment, human or not.
These four capabilities depend on each other, and the Hugging Face incident shows why. Visibility without detection leaves blind spots, since an identity nobody is tracking can drift into risky behavior long before anyone questions it. Detection without governance leaves risk in place, and governance without recovery still leaves an organization vulnerable when prevention fails.
Identity intelligence, threat detection, governance, and recovery reinforce each other only when they work as a single system, which is what matters most against agents fast enough to find whichever piece is missing. The Quest Security Management Platform brings all four together, helping organizations secure human, non-human, and agentic identities across the enterprise.
