The vendors that run your API and identity infrastructure have started treating AI agents as a new class of user, and that changes what your access controls will be expected to prove.
Rania Khalaf, Chief AI Officer at WSO2, recently described on the AI Engineer podcast how the 20-year-old infrastructure vendor is rebuilding its product line around agents as primary consumers of software. Her reasoning is simple. Agent traffic is still API traffic, but it has to be governed differently, and the identity discipline built for human users carries over. In practice that has meant extending WSO2's identity platform to cover agents, adding an AI gateway to its API platform, and in September moving its Agent Manager platform to general availability. According to InfoQ, the release centers on verifiable agent identity, role-based access, delegation, token exchange, and revocation. Khalaf's broader point is that every enterprise product will soon need to be usable by agents, not just people.
Control Gaps and Evidentiary Standards
For a bank CIO, the signal is that agent identity is moving out of custom engineering and into platforms already sitting in the stack. That is useful, and it also removes an excuse. Once mainstream identity vendors ship agent provisioning and revocation as standard features, an agent running on a shared service account stops looking like a pragmatic shortcut and starts looking like a control gap.
For the CRO, the question is evidentiary. An agent that pulls customer records, advances a case in AML review, or calls a payments API is exercising privileged access. Examiners and internal audit will ask what they ask about any privileged user: who authorized it, what it can touch, on whose behalf it acted, and whether access was pulled when the use case changed. Whether a given agent counts as a model is a separate debate. Either way, it is a privileged user, and access control expectations already apply.
The Seam Between Identity and Data Authority
The harder problem is the seam. Agent identity governs the front door. It does not tell you whether the customer record the agent acted on belonged to the right customer, or whether the data was current at the moment of action. Identity, entity resolution, and data freshness usually sit with three different teams, and the first serious incident will land in the gap between them.
Inventory Now, Architecture Within Two Years
On timing, the inventory is a this-year task. Many banks already have agents running that arrived inside SaaS renewals rather than through an approval process, and those agents cannot be governed until they are counted. The architecture work, a single identity and authorization plane spanning human and agent access, is a 12-to-24-month effort, and the banks that start it now will have an easier conversation with their examiners.
On timing, the inventory is a this-year task. Many banks already have agents running that arrived inside SaaS renewals rather than through an approval process, and those agents cannot be governed until they are counted. The architecture work, a single identity and authorization plane spanning human and agent access, is a 12-to-24-month effort, and the banks that start it now will have an easier conversation with their examiners.
