Skip to main content
NTT DATA AI agents learning company context, digital identity, data analysis, and machine learning concepts.

Editorial illustration for NTT DATA: AI Agents Need More Than Identity to Learn Company Context

AI Agents Need More Than Shared Credentials

NTT DATA: AI Agents Need More Than Identity to Learn Company Context

4 min read

Sixty-nine percent of enterprises running AI agents are still letting those agents share credentials, according to VentureBeat research published in June. That's not a minor configuration problem. Companies tracking security incidents and near-misses found a direct line between shared credentials and higher rates of both.

At VB Transform 2026, two executives working the security side of enterprise AI pushed back on the idea that fixing identity solves the problem. Mukesh Karki, CTO of NTT DATA AIVista, and Mayank Upadhyay, chief security and trust officer at Snowflake, say identity is table stakes. What comes after it, tracking what an agent actually did with its access and proving that record can't be altered, is where most deployments fall short.

The stakes go beyond internal risk management. Karki frames it as a regulatory question: companies need audit trails solid enough to satisfy outside auditors, not just internal security teams. Without that, he argues, organizations don't have a real license to run autonomous systems at scale. Upadhyay traces the root issue further back, to assumptions inherited from an older, more predictable model of software.

Enterprises also need action-level authorization and tamper-resistant audit trails built into every agent interaction if they’re going to deploy autonomous systems safely at scale.

Why this matters

We keep hearing "treat AI agents like employees" as if that solves governance, and Karki's point at VB Transform lands hard: it doesn't scale. You can onboard a new hire over months, watch how they handle edge cases, revoke access if something feels off. Nobody's doing that with a fleet of a thousand agents spun up for quarterly reporting or code review.

The 69% figure from VentureBeat's June research, enterprises still sharing credentials across agents, is the real headline here, not the identity fixes vendors are pitching. If agents share logins, you can't tell which one touched what, and "tamper-resistant audit trail" stops being a compliance checkbox and becomes the only forensic record you'll have after an incident. For teams building or buying agent infrastructure right now, the lesson from Karki and Upadhyay is blunt: authorization needs to happen at the action level, not the login level.

Anyone shipping agents into production without that distinction is building on the same shaky foundation that produced those incident numbers in the first place.

Common Questions Answered

What percentage of enterprises are still allowing AI agents to share credentials according to VentureBeat research?

According to VentureBeat research published in June, 69% of enterprises running AI agents are still letting those agents share credentials. This represents a significant security configuration problem, as companies tracking security incidents have found a direct correlation between shared credentials and higher rates of both security incidents and near-misses.

Why does NTT DATA's Mukesh Karki argue that identity alone is insufficient for securing enterprise AI agents?

Mukesh Karki, CTO of NTT DATA, emphasizes that enterprises need more than just identity management to secure AI agents at scale. He advocates for action-level authorization and tamper-resistant audit trails built into every agent interaction, arguing that identity fixes alone do not adequately address the governance challenges of deploying autonomous systems safely.

How does the approach to onboarding AI agents differ from traditional employee onboarding according to the article?

Unlike human employees who can be onboarded over months with careful observation of how they handle edge cases and selective access revocation, AI agents are typically deployed at scale in large fleets without this gradual monitoring process. The article notes that companies cannot practically apply traditional employee governance practices to thousands of agents spun up for quarterly reporting or code review.

What specific security measures does NTT DATA recommend for autonomous AI agent deployment?

NTT DATA recommends implementing action-level authorization controls and tamper-resistant audit trails built into every agent interaction as essential security measures for safe autonomous system deployment. These measures go beyond basic identity management to provide comprehensive governance and accountability for AI agent operations at enterprise scale.

LIVE18:38Hush Security: AI Agents Create New Identity Governance Gap