# Cakewalk > Agentic access management for fast-moving companies. Govern access of human identities and AI agents across enterprise SaaS, internal apps, and infrastructure. ## Articles - [An AI Agent Ran a Ransomware Attack on Its Own](https://www.cakewalk.security/blog/jadepuffer-agentic-ransomware): JadePuffer is what the security firm Sysdig calls the first ransomware attack run start to finish by an AI agent, with no human directing it. The agent broke into a server, stole credentials, spread through the network and locked a company's database on its own. - [It Doesn't Take a Hacker to Leak Your Data: How to Secure AI Agent Access in the Enterprise [Webinar Recap]](https://www.cakewalk.security/blog/it-doesnt-take-a-hacker-to-leak-your-data-webinar-recap): It used to take a hacker to leak your data. That is no longer true. Barbara Teruggi (Allianz Technology) and Johannes Keienburg (Cakewalk) on zero trust for AI agents, default-deny access, and why no identity should complete a full process alone. - [Estonia Wants to Give Every AI Agent Its Own ID](https://www.cakewalk.security/blog/estonia-ai-agent-id): In June 2026 Estonia's prime minister proposed giving every AI agent a national ID code, tied to a responsible operator, with set permissions and an audit trail. It names the right principles. The open question is who checks each action against the limit at runtime. - [Even the NSA Is Warning About the Protocol Connecting AI Agents to Your Stack](https://www.cakewalk.security/blog/nsa-mcp-security-guidance): In May 2026 the NSA's AI Security Center published security guidance on the Model Context Protocol. It flags missing authentication, capability changes that need no approval and implicit trust between agents. - [Human → Agent → System: A Working Model for Governing Agent Access](https://www.cakewalk.security/blog/human-agent-system-working-model-governing-agent-access.md): How a line on our 2023 roadmap became security’s biggest unsolved problem and led to the access layer we are now building. - [AI Agent Access Control for Regulated Industries: What EU Auditors Are Already Asking [Webinar Recap]](https://www.cakewalk.security/blog/ai-agent-access-control-regulated-industries-eu-auditors-webinar): Your auditor is already getting ready to ask about AI agents. If your SOC 2, ISO 27001, or DORA audit lands in 2026, you can assume agent access will be in scope. Julie Gibelin (Talon.One) and Johannes Keienburg (Cakewalk) on what changes when agents enter the access picture. - [Runtime Governance: The Missing Layer for Agent Access](https://www.cakewalk.security/blog/governing-the-new-frontier-the-missing-layer-for-agent-access): Five industry responses are shaping agent identity and authentication. None governs what agents do at runtime. This article maps the gap and the four architectures that could fill it. - [Top 8 Identity and Access Management Tools for AI Agents in 2026](https://www.cakewalk.security/blog/best-identity-access-management-tools-ai-agents): Identity and access management was built for humans, then stretched to cover service accounts. Neither model holds up for AI agents. This guide compares the 8 platforms worth evaluating for AI agent IAM in 2026. - [Top 10 AI Agent Security Tools for Access Management in 2026](https://www.cakewalk.security/blog/top-10-ai-agent-security-tools-access-management-2026): Compare the 10 best AI agent access management tools for 2026. Cakewalk leads with purpose-built runtime governance and free early access, plus 9 alternatives evaluated honestly. - [Top 8 SOC 2 Compliance Tools for Access Management in 2026](https://www.cakewalk.security/blog/soc2-access-management-tools): Most SOC 2 audits get tripped up on access controls, not encryption. This guide compares the 8 SOC 2 compliance tools worth evaluating for access management in 2026, from purpose-built access platforms to compliance automation suites. - [AI Agents Have Too Much Access: Why Static Permissions Are a Security Risk [Webinar Summary]](https://www.cakewalk.security/blog/ai-agents-have-too-much-access-webinar-recording): ‍ - [The New Frontier in Identity Security: AI Agent Access](https://www.cakewalk.security/blog/the-new-frontier-in-identity-security-is-ai-agent-access): International Data Corporation (IDC) projects actively deployed AI agents will exceed one billion worldwide by 2029.[1] That is not a distant forecast. Machine identities already outnumber human identities 82 to 1 across organizations worldwide.[2] Microsoft Copilot Studio and SharePoint users - [OpenClaw & Moltbook: Why AI Agent Access Is The Next Identity Crisis [Webinar Summary]](https://www.cakewalk.security/blog/openclaw-moltbook-why-ai-agent-access-is-the-next-identity-crisis-webinar-summary): AI agents are spreading across company stacks faster than most security teams realize. - [How To Scale Securely In 2026 Without Growing Your IT Team with Peter Kovacs [Webinar Summary]](https://www.cakewalk.security/blog/how-to-scale-securely-in-2026-without-growing-your-it-team-with-peter-kovacs): ‍ - [AI in Cybersecurity, Identity Governance & Access Management in 2026](https://www.cakewalk.security/blog/ai-cybersecurity-access-management-considerations): Well, SKYNET isn't quite here yet, but it feels awfully close, doesn't it? We've yet to see a robotic revolution, but it seems like with each passing week a new AI tool is storming the market and simplifying mundane tasks. Companies naturally jump at the chance to streamline tedium and reduce c - [Everything Financial Companies Need to Know about DORA](https://www.cakewalk.security/blog/what-is-dora): While we've recently covered NIS2, the AI Act, and other sweeping regulations that address tech innovations, the EU's Digital Operational Resilience Act seems to have flown under the radar for many. Possibly in part due to its esotericism or being kept in the dark about how it will affect non-E - [The Future of Identity Governance is Employee-Centric. Here's Why.](https://www.cakewalk.security/blog/employee-centric-iga): Poor access management practices are one of the most significant security risks facing any IT team. In fact, a recent Verizon report found that 43% of breaches are performed via applications as an entry point—underscoring how traditional access management paradigms are no longer cutting it. - [3 Ways NIS2 Will Affect UK Companies (Yes, We're Serious)](https://www.cakewalk.security/blog/blog-nis2-uk): Despite Brexit's determination to break from the EU, many UK companies still do business with and within the EU in some capacity, meaning that EU legislation may not directly impact UK businesses, but it can still heavily influence them — as is the case with NIS2. - [Deutschland: Wach auf und mach dich bereit für NIS2!](https://www.cakewalk.security/blog/deutschland-wach-auf-und-mach-dich-bereit-fur-nis2): Der 17. Oktober 2024 war das offizielle Zieldatum für die Umsetzung der bahnbrechenden Gesetzgebung – bekannt als die Network and Information Security Directive (NIS2) – durch die EU-Mitgliedstaaten. Doch in einer Wendung deutscher "Effizienz" haben es z Germans nicht rechtzeitig geschafft – es - [EU: Wake up and Get Ready for NIS2](https://www.cakewalk.security/blog/nis2-in-eu): 17. October 2024 was the goal date that landmark legislation, known as the Network and Information Security Directive (NIS2), should have been implemented for member states; but in a plot twist, many EU countries are behind schedule, including the economic titans of the EU,  Germany and Fr - [Uncovering and Fixing Shadow IT](https://www.cakewalk.security/blog/uncovering-and-controlling-shadow-it): For a second, imagine the employees in your company can rent and lease cars at any time. They do this directly, without informing anyone. Still, they do it in the name of the company.