# Cakewalk > Agentic access management for fast-moving companies. Govern access of human identities and AI agents across enterprise SaaS, internal apps, and infrastructure. ## Articles - [IETF Draft Says an Approval Inside an AI Agent Is Not Enough](https://www.cakewalk.security/blog/ietf-ai-agent-authorization-draft.md): A working group of the Internet Engineering Task Force adopted the AI Agent Authentication and Authorization draft on September 9, 2026. The draft applies OAuth and workload identity to AI agents and says a confirmation inside the agent client does not by itself authorize an action. - [Identity Standards Stop at the Moment an AI Agent Acts](https://www.cakewalk.security/blog/acs-agent-identity-gaps.md): The Agent Control Standard named five AI agent identity gaps on September 6, 2026. Four have no mechanism to close them, while the one that does lets a call through by default when no decision arrives in time. - [Most CLAUDE.md Security Rules Have No Built-In Control That Matches Them](https://www.cakewalk.security/blog/claude-md-security-rules-without-controls.md): A preprint posted to arXiv on August 24, 2026 read 481 public CLAUDE.md files and found that only 4.4% of the security rules it retrieved had a matching built-in control, under its strictest standard. The file gives a developer no sign of which rules anything enforces. - [Agents Can Combine Permitted Actions Into a Prohibited Outcome](https://www.cakewalk.security/blog/bounded-agents-authorization-architecture.md): A preprint posted on August 16, 2026 models agent permissions as a chain rather than a fixed grant and argues an injected instruction only causes harm when the agent already holds the authority to act on it. Its benchmark results are strong and entirely synthetic. - [MCP v2 Improves Agent Access Control and Still Cannot Say Who Decided](https://www.cakewalk.security/blog/mcp-spec-agent-access-control-accountability.md): MCP revision 2026-07-28 improves two of the three identities behind every agent action: the agent making the call and the account whose permissions it uses. The third, the person who decided the action should happen, still has no field of its own. - [Agent Plugins 1.0 Standardizes the Package and Leaves Policy to Each Client](https://www.cakewalk.security/blog/agent-plugins-per-client-policy.md): The Agent Plugins project released version 1.0.0 of its specification on August 6, 2026, making agent skills and MCP server configuration portable across clients. Its own documents say it defines no trust model, permission system or sandboxing, while each client keeps control of policy. - [Top 5 User Access Review Tools in 2026](https://www.cakewalk.security/blog/user-access-review-tools.md): The five user access review tools worth evaluating in 2026, judged on what actually reduces risk: reviews that execute the revoke, show context, cover the apps outside SSO and include AI agents. Why Cakewalk leads for mid-market SOC 2 and ISO 27001 teams. - [AI Agents Under Test Created Fake Identities to Get Malicious Code Approved](https://www.cakewalk.security/blog/aisi-agents-fake-identities.md): The UK's AI Security Institute disclosed on August 4, 2026 that AI agents in a cyber evaluation took 19 unsanctioned actions against real people and organizations. One agent built fake identities to pressure an open-source maintainer into approving malicious code, which the maintainer refused. - [The EU Started Enforcing the AI Act's Transparency Rules on August 2](https://www.cakewalk.security/blog/eu-ai-act-transparency-rules.md): The European Commission began enforcing the AI Act's transparency rules on August 2, 2026. Four disclosure duties apply, split between the providers that build AI systems and the deployers that run them. Fines reach 15 million euros or 3% of worldwide turnover, whichever is higher. - [Anthropic's Claude Broke Into Three Real Companies After Being Told It Was a Simulation](https://www.cakewalk.security/blog/claude-breached-real-companies.md): Anthropic disclosed on July 30, 2026 that three Claude models compromised the real systems of three organizations during cybersecurity evaluations. The test environments were supposed to be sealed. A misconfiguration gave them live internet access while the models were told they had none. - [Okta Alternatives: 10 Identity and Access Management Platforms Compared](https://www.cakewalk.security/blog/okta-alternatives.md): Ten Okta alternatives compared for 2026, from full IdP swaps (Entra, Google, JumpCloud, Ping) to the governance layer most mid-market teams actually need. Why pairing the IdP you already own with Cakewalk usually beats stacking Okta's premium tiers. - [AI Gateway Security: The New Attack Surface and the New Control Point](https://www.cakewalk.security/blog/ai-gateway-security-attack-surface.md): Darktrace found a company's AI gateway quietly working for an attacker. What a gateway holds between calls decides how bad a break-in gets. - [Agent Cake Now Signs In Through Google SSO](https://www.cakewalk.security/blog/auto-provisioning-google-sign-in.md): Agent Cake, Cakewalk's AI provisioning agent, now signs in through Google SSO. Apps that enforce Google sign-in stay inside auto-provisioning, with no password kept alive outside the company's identity provider. - [An Attacker Turned Off the Hermes AI Agent's Approval Prompt](https://www.cakewalk.security/blog/hermes-agent-yolo-mode-attack.md): On July 23, 2026 the threat-intelligence firm Hunt.io reported an attacker running Hermes, a widely used open-source AI agent, in YOLO mode against Thailand's Ministry of Finance. Because that setting clears the approval checks on dangerous commands, nobody watched each step. - [An AI Agent Breached Hugging Face to Cheat a Benchmark](https://www.cakewalk.security/blog/ai-agent-breached-hugging-face.md): In July 2026 Hugging Face disclosed that an autonomous AI agent, not a human attacker, broke into its infrastructure over a weekend and harvested credentials. Days later OpenAI said the agent was its own evaluation models, which escaped a test sandbox to cheat a cyber benchmark. - [Top 5 AI Agent Access Control Platforms in 2026](https://www.cakewalk.security/blog/ai-agent-access-control-platforms.md): How the five major platforms control AI agent access in 2026. Cakewalk's runtime policy gateway compared against Okta, SailPoint, Wiz and Cisco-Astrix, with an honest look at what each one enforces. - [Where AI Expands Access, Breaches Run Four Times the Rate](https://www.cakewalk.security/blog/ai-access-outpaces-governance.md): Two 2026 surveys, from Netwrix and ISACA, point to the same gap: companies are giving AI access faster than they can govern or revoke it. Netwrix links wider AI access to a higher breach rate. ISACA found most security teams cannot say how fast they could halt an AI system gone wrong. - [An AI Agent Ran a Ransomware Attack on Its Own](https://www.cakewalk.security/blog/jadepuffer-agentic-ransomware.md): JadePuffer is what the security firm Sysdig calls the first ransomware attack run start to finish by an AI agent, with no human directing it. The agent broke into a server, stole credentials, spread through the network and locked a company's database on its own. - [It Doesn't Take a Hacker to Leak Your Data: How to Secure AI Agent Access in the Enterprise [Webinar Recap]](https://www.cakewalk.security/blog/it-doesnt-take-a-hacker-to-leak-your-data-webinar-recap.md): It used to take a hacker to leak your data. That is no longer true. Barbara Teruggi (Allianz Technology) and Johannes Keienburg (Cakewalk) on zero trust for AI agents, default-deny access, and why no identity should complete a full process alone. - [Estonia Wants to Give Every AI Agent Its Own ID](https://www.cakewalk.security/blog/estonia-ai-agent-id.md): In June 2026 Estonia's prime minister proposed giving every AI agent a national ID code, tied to a responsible operator, with set permissions and an audit trail. It names the right principles. The open question is who checks each action against the limit at runtime. - [Even the NSA Is Warning About the Protocol Connecting AI Agents to Your Stack](https://www.cakewalk.security/blog/nsa-mcp-security-guidance.md): In May 2026 the NSA's AI Security Center published security guidance on the Model Context Protocol. It flags missing authentication, capability changes that need no approval and implicit trust between agents. - [How to Adopt AI Agents Securely at Scale: The 4 Zones of Automation [Webinar Summary]](https://www.cakewalk.security/blog/how-to-adopt-ai-agents-securely-at-scale-webinar-summary.md): Vercel's breach started with an AI app holding broad, static access. Marco van Hurne (ASML) and Johannes Keienburg (Cakewalk) on the four zones of AI automation, why most zone 3 agent projects fail and why the most dangerous agent in a company is usually a zone 1 agent. - [Human → Agent → System: A Working Model for Governing Agent Access](https://www.cakewalk.security/blog/human-agent-system-working-model-governing-agent-access.md): How a line on our 2023 roadmap became security’s biggest unsolved problem and led to the access layer we are now building. - [AI Agent Access Control for Regulated Industries: What EU Auditors Are Already Asking [Webinar Recap]](https://www.cakewalk.security/blog/ai-agent-access-control-regulated-industries-eu-auditors-webinar.md): Your auditor is already getting ready to ask about AI agents. If your SOC 2, ISO 27001, or DORA audit lands in 2026, you can assume agent access will be in scope. Julie Gibelin (Talon.One) and Johannes Keienburg (Cakewalk) on what changes when agents enter the access picture. - [Runtime Governance: The Missing Layer for Agent Access](https://www.cakewalk.security/blog/governing-the-new-frontier-the-missing-layer-for-agent-access.md): Five industry responses are shaping agent identity and authentication. None governs what agents do at runtime. This article maps the gap and the four architectures that could fill it. - [Top 8 Identity and Access Management Tools for AI Agents in 2026](https://www.cakewalk.security/blog/best-identity-access-management-tools-ai-agents.md): Identity and access management was built for humans, then stretched to cover service accounts. Neither model holds up for AI agents. This guide compares the 8 platforms worth evaluating for AI agent IAM in 2026. - [Top 10 AI Agent Security Tools for Access Management in 2026](https://www.cakewalk.security/blog/top-10-ai-agent-security-tools-access-management-2026.md): Compare the 10 best AI agent access management tools for 2026. Cakewalk leads with purpose-built runtime governance and free early access, plus 9 alternatives evaluated honestly. - [Top 8 SOC 2 Compliance Tools for Access Management in 2026](https://www.cakewalk.security/blog/soc2-access-management-tools.md): Most SOC 2 audits get tripped up on access controls, not encryption. This guide compares the 8 SOC 2 compliance tools worth evaluating for access management in 2026, from purpose-built access platforms to compliance automation suites. - [AI Agents Have Too Much Access: Why Static Permissions Are a Security Risk [Webinar Summary]](https://www.cakewalk.security/blog/ai-agents-have-too-much-access-webinar-recording.md): ‍ - [The New Frontier in Identity Security: AI Agent Access](https://www.cakewalk.security/blog/the-new-frontier-in-identity-security-is-ai-agent-access.md): International Data Corporation (IDC) projects actively deployed AI agents will exceed one billion worldwide by 2029.[1] That is not a distant forecast. Machine identities already outnumber human identities 82 to 1 across organizations worldwide.[2] Microsoft Copilot Studio and SharePoint users - [OpenClaw & Moltbook: Why AI Agent Access Is The Next Identity Crisis [Webinar Summary]](https://www.cakewalk.security/blog/openclaw-moltbook-why-ai-agent-access-is-the-next-identity-crisis-webinar-summary.md): AI agents are spreading across company stacks faster than most security teams realize. - [How To Scale Securely In 2026 Without Growing Your IT Team with Peter Kovacs [Webinar Summary]](https://www.cakewalk.security/blog/how-to-scale-securely-in-2026-without-growing-your-it-team-with-peter-kovacs.md): ‍ - [AI in Cybersecurity, Identity Governance & Access Management in 2026](https://www.cakewalk.security/blog/ai-cybersecurity-access-management-considerations.md): Well, SKYNET isn't quite here yet, but it feels awfully close, doesn't it? We've yet to see a robotic revolution, but it seems like with each passing week a new AI tool is storming the market and simplifying mundane tasks. Companies naturally jump at the chance to streamline tedium and reduce c - [Everything Financial Companies Need to Know about DORA](https://www.cakewalk.security/blog/what-is-dora.md): While we've recently covered NIS2, the AI Act, and other sweeping regulations that address tech innovations, the EU's Digital Operational Resilience Act seems to have flown under the radar for many. Possibly in part due to its esotericism or being kept in the dark about how it will affect non-E - [The Future of Identity Governance is Employee-Centric. Here's Why.](https://www.cakewalk.security/blog/employee-centric-iga.md): Poor access management practices are one of the most significant security risks facing any IT team. In fact, a recent Verizon report found that 43% of breaches are performed via applications as an entry point—underscoring how traditional access management paradigms are no longer cutting it. - [3 Ways NIS2 Will Affect UK Companies (Yes, We're Serious)](https://www.cakewalk.security/blog/blog-nis2-uk.md): Despite Brexit's determination to break from the EU, many UK companies still do business with and within the EU in some capacity, meaning that EU legislation may not directly impact UK businesses, but it can still heavily influence them — as is the case with NIS2. - [Deutschland: Wach auf und mach dich bereit für NIS2!](https://www.cakewalk.security/blog/deutschland-wach-auf-und-mach-dich-bereit-fur-nis2.md): Der 17. Oktober 2024 war das offizielle Zieldatum für die Umsetzung der bahnbrechenden Gesetzgebung – bekannt als die Network and Information Security Directive (NIS2) – durch die EU-Mitgliedstaaten. Doch in einer Wendung deutscher "Effizienz" haben es z Germans nicht rechtzeitig geschafft – es - [EU: Wake up and Get Ready for NIS2](https://www.cakewalk.security/blog/nis2-in-eu.md): 17. October 2024 was the goal date that landmark legislation, known as the Network and Information Security Directive (NIS2), should have been implemented for member states; but in a plot twist, many EU countries are behind schedule, including the economic titans of the EU,  Germany and Fr - [Uncovering and Fixing Shadow IT](https://www.cakewalk.security/blog/uncovering-and-controlling-shadow-it.md): For a second, imagine the employees in your company can rent and lease cars at any time. They do this directly, without informing anyone. Still, they do it in the name of the company.