AI agents are quickly becoming part of everyday development work, but the security controls surrounding them have not caught up. New research from 1Password suggests many companies are giving agents access to sensitive systems and credentials without a reliable way to limit, monitor, or revoke that access.
The company surveyed 500 developers and 500 IT and security professionals in the United States. It found that 40 percent of developers grant AI agents persistent access to systems or credentials. In other words, the agent may retain access even after the task it was assigned has ended.
That should make security teams uncomfortable. An AI agent with long-lived credentials is not simply another employee account. It can operate rapidly, interact with several systems, and take actions without someone reviewing every step. A credential that stays active longer than necessary gives attackers another target while also increasing the damage an agent could cause through a mistake, prompt injection, or poorly scoped instruction.
The research arrives as 1Password expands further into privileged access management. Its approach is based on eliminating standing access for people, machines, and AI agents. Rather than handing an agent a permanent credential, access is created when needed, limited to the task, evaluated against company policy, and removed automatically when the work is finished.
This is generally called just-in-time access. It is not a new security idea, but AI agents make it far more urgent.
According to 1Password, 46 percent of developers already use AI agents in production environments. Another 45 percent expect to use them within the next two years. That means 91 percent are either using agents now or anticipate doing so soon.
The problem is that many companies appear to be adopting agents first and figuring out governance later.
Sixty-five percent of developers said they are expected or encouraged to use AI agents, yet only 33 percent believe they have a highly secure way to do so. Sixty-seven percent said their company’s approach to agent security has gaps.
That disconnect is easy to understand. Businesses want the speed and productivity AI agents promise. Developers are being pushed to automate workflows, generate code, investigate problems, and connect services. Security teams, meanwhile, are expected to control what those agents can access without slowing everyone down.
The result can be a collection of API keys, service accounts, tokens, and other non-human identities that are difficult to track. Some may have more access than they need. Others may never expire. In poorly managed environments, nobody may know which agent is using which credential or who authorized the activity.
1Password found that 71 percent of respondents use at least one insecure method to manage secrets and non-human identities. Twenty-four percent of developers said they hardcode credentials, 20 percent share them through email or Slack, and 43 percent do not use a dedicated secrets manager or vault.
Those habits were already risky before AI agents entered the picture. Giving an autonomous or semi-autonomous tool access to the same credentials can amplify the problem.
The consequences are not limited to hypothetical attacks. Eighty-six percent of respondents reported some type of credential-related issue involving non-human identities. Thirty-eight percent experienced service disruptions, outages, or delays caused by credential problems. Twenty-seven percent reported a security incident or breach involving overprivileged non-human identities. Among developers using AI agents, that breach figure increased to 33 percent.
AI agents can also be manipulated through content they encounter while completing a task. Nearly half of developers, 47 percent, said an agent had taken an unintended action after following instructions embedded in an untrusted webpage, document, email, or tool output. This type of attack is commonly called prompt injection.
Prompt injection is especially troubling when an agent has broad or persistent access. A malicious instruction hidden inside a document may be far less dangerous when the agent can only perform one narrowly defined action. The risk grows when that same agent can read company files, access email, query internal systems, or use credentials that remain valid indefinitely.
The survey found that AI agents have access to customer information, intellectual property, HR records, or other sensitive data at 71 percent of respondents’ companies. It also found agents accessing unapproved data at 41 percent of organizations.
This does not mean AI agents should be blocked from useful systems. An agent without access cannot do much. The more important question is whether access is limited to exactly what the agent needs, lasts only as long as necessary, and produces an audit trail that a human can review.
That is where 1Password believes its privileged access approach can fit. Instead of trusting an agent with a raw, reusable credential, the platform can issue temporary access for a specific request. The company says organizations should be able to see what an agent accessed, identify who approved the request, and trace actions back to both the agent and the person responsible for it.
The survey indicates that customers are looking for those capabilities. Fifty-two percent of respondents wanted a centralized view of access across people and agents. Forty-seven percent wanted task-specific credentials that expire automatically. Fifty-one percent wanted complete audit trails, while 53 percent wanted clearer accountability for agent actions.
Of course, the research comes from a company selling access-management products, so its conclusions support the market 1Password wants to enter. That does not make the findings meaningless, but organizations should evaluate the methodology and their own environments before treating every percentage as universal.
The larger warning still makes sense. Companies are giving AI agents access to production systems faster than they are building policies to govern them. Permanent credentials may be convenient during development, but convenience can become a serious liability when an agent is compromised, confused, or tricked.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz