AI Agents Running as Users: Rig Security's $12M Launch Exposes an Identity Control Gap
What happened
Rig Security emerged from stealth on September 29, 2026. It announced $12 million in seed funding to address what it describes as a runtime identity gap in enterprise AI agent deployments. The company's platform, described in its launch coverage, uses an identity correlation engine and a lightweight sensor running on employee devices. These tools tell apart a human user's actions from those of an AI agent operating under that user's credentials. When an agent behaves unexpectedly or is compromised, the platform can block the agent's actions without locking the human account. The launch reflects a growing concern documented across recent incidents. These include the seven-incident agentic AI threat cluster that exposed identity and logging gaps, and the standing agent credentials control gap analysis. Rig's approach sits within a broader industry shift toward treating AI agents as distinct identities rather than extensions of human accounts.
Why it matters
- ·Most enterprise identity systems grant AI agents the same access rights as the human user they operate under. This means a compromised or misbehaving agent can read email, move files, or submit transactions with no separate access log. Existing controls like multi-factor authentication do not address this gap.
- ·Regulators and guidance bodies including those behind the Five Eyes Guidance on the Careful Adoption of Agentic AI Services are increasingly treating agent identity as a distinct governance requirement. Compliance teams that rely only on user-level access controls may find their programs fall short of emerging expectations.
- ·The vendor market for agent identity controls is now active and growing. Compliance teams that have not yet inventoried which agents run under human credentials face a procurement and risk-assessment backlog, and the cost of inaction rises as agent deployments scale.
Governance controls affected
What to do now
- ☐Ask your IT and engineering teams to list every AI agent currently running inside your environment and confirm whether each one operates under a named human user's credentials or has its own dedicated account.
- ☐Review your access logs to determine whether agent actions are currently distinguishable from human actions. If they are not, you have a logging gap that affects both incident response and audit readiness.
- ☐Evaluate whether your existing identity management tools can block or restrict an AI agent independently of the human account it runs under, and document any gaps found.
- ☐Add agent identity separation to your next vendor due-diligence review cycle, and ask current AI vendors how their platforms handle the distinction between human and agent actions at the access level.
- ☐Update your AI agent inventory to record, for each deployed agent, the account credentials it uses, the systems it can reach, and who is accountable for its behavior if it acts outside its intended scope.
What to watch next
Regulators and standards bodies are moving toward formal requirements for separate agent identities. Bodies such as the Non-Human Identity Management Group and the Five Eyes coalition already treat this as a baseline expectation. Compliance teams should monitor whether the EU AI Act enforcement priorities expand to cover agent identity controls as agentic deployments become more common. The vendor market will also accelerate. New entrants alongside established identity providers will compete to define what adequate agent identity governance looks like. Early procurement decisions may lock organizations into architectural choices that are hard to reverse.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
