TL;DR: AI agents are rapidly expanding the population of non-human identities with access to critical systems, data, and workflows, creating new risks that organizations must address now. Rather than waiting for theoretical safeguards like an AI “kill switch,” security leaders require visibility, governance, and control over every identity across their environments. As the digital workforce grows, organizations that can continuously understand, govern, contain, and recover compromised identities will be better positioned to embrace AI without sacrificing security or resilience.

Recent events have pushed AI risk beyond security teams and into boardrooms, government hearings, and dinner-table conversations. Investigations involving OpenAI on platforms like Hugging Face and now the Australian government, have raised concerns about how autonomous systems can access, share, and manipulate resources in ways their creators did not intend. At the same time, lawmakers are debating how organizations might stop a rogue AI agent if one threatens critical operations or national security.

That conversation often centers on the idea of an AI “kill switch.” While the concept has attracted broad interest, it remains largely theoretical. Organizations still don’t know what such a mechanism would require, who would control it, or how it would function across different AI systems and environments.

Meanwhile, AI agents are already operating inside organizations today, gaining access to systems, data, applications, and workflows. Rather than waiting for future safeguards, security teams need visibility, AI identity governance, and control over the identities these systems use right now. Identity is where much of the immediate risk comes into focus.

In the 1996 film Multiplicity, starring Michael Keaton, an overwhelmed employee creates clones of himself to improve productivity. At first the solution works. But managing the clones becomes more difficult as each develops its own behaviors, creating new challenges around visibility, accountability, and control.

Organizations are beginning to encounter a similar problem with AI agents experiencing something similar. They are rapidly deploying AI agents, a new class of non-human identity now joining the service accounts, and APIs organizations have long managed. These agentic identities promise significant gains in productivity and automation along with the responsibility of managing a rapidly expanding workforce of trusted digital identities.

The AI hiring boom no one is tracking

Imagine your organization could instantly add 100 employees for every person already on staff. They operate around the clock, work at machine speed, and interact with dozens of systems simultaneously.

AI agents and automation are creating a new version of that scenario inside organizations. Every new agent requires some level of access, yet AI identity governance often lags behind growth. The business sees efficiency gains; security teams see an expanding trust model that must be governed. This extends beyond AI agents. Organizations have spent years accumulating service accounts, automated workflows, machine identities, certificates, and APIs. AI is accelerating that existing trend, with non-human identities growing faster than the human workforce they support.

Attackers have noticed the shift

Attackers have shifted their focus on targeting credentials, tokens, hashes, certificates, and machine accounts because trusted identities provide legitimate pathways into critical systems. A compromised identity can continue operation with authorized access, making malicious activity much harder to detect.

Autonomous interaction among AI-driven systems creates another layer of complexity. Security teams may struggle to distinguish machine-to-machine activity from malicious behavior hidden within normal business operations.

You can’t govern what you can’t see

Many security teams struggle to answer basic questions about their growing population of non-human identities:

  • Which identities exist?
  • Who owns them?
  • What access do they have?
  • How are they connected to critical systems and workflows?
  • What happens if one is compromised?

Answering those questions becomes more difficult as the identity environment changes. Most AI identity governance models were designed around periodic reviews and static inventories. But non-human identities are dynamic. They appear, disappear, inherit permissions, and interact with systems continuously. By the time an organization conducts its next review, the environment may already be very different.

From visibility to governance

Organizations need visibility into every human and non-human identity across their environments, clear ownership, and continuous monitoring for dormant accounts, unusual behavior, privilege changes, and excessive access. However, that’s just the beginning. Security teams also need identity intelligence, which includes the ability to understand how identities relate to one another, how access changes over time, and where emerging risks are developing. Applying least-privilege principles, lifecycle management, behavioral analytics, and continuous monitoring to AI agents and other non-human identities helps ensure innovation does not outpace AI identity governance.

Organizations must also prepare for the reality that some attacks will succeed. Security leaders need the ability to contain compromised identities, limit the spread of unauthorized access, and recover critical systems quickly when incidents occur.

The Multiplicity problem

In Multiplicity, creating the clones was only the beginning. Managing each clone created difficulties. Organizations face a similar reality today: AI agents and other non-human identities can deliver tremendous productivity gains but only if organizations maintain control as their digital workforce grows.

The growing debate around rogue AI agents and kill switches reflects a broader recognition that AI security is no longer solely a technical issue. It has become a business resilience, governance, and a board-level issue. A workable kill switch may eventually become part of the conversation. but organizations cannot wait for it while AI-driven identities are multiplying today.

AI identity governance will matter as much as deploying these identities. Organizations need to know what their digital workforce can access, who or what is accountable for its actions, and how quickly access can be contained when something goes wrong.

Bastiaan Verdonk has over 30 years' experience in the IT industry, with a special focus on Identity Threat Detection and Response, Active Directory and the evolving state of cyber security. During his 20 years at Quest Software, he has supported various customers around the globe to implement Quest products in a wide variety of environments and dealing with several challenges. Most recently, Bastiaan became a trusted subject matter expert on cyber security and resilience where he is involved in some speaking opportunities where he shares his experiences and knowledge with many audiences. He hast spoken at the Gartner IAM conference in 2025 and is part of the Technical Expert Conference which is hosted by Quest both in the US and in EMEA.