September 9, 2026
Identity Security Signals: AI tests security boundaries, digital trust faces new pressures, critical infrastructure risks grow
In this blog:
- AI security incidents drive new calls for regulation and oversight
- Identity and access emerge as foundations for agentic AI governance
- Cyberattacks challenge traditional approaches to establishing digital trust
- AI’s dual-use capabilities create new opportunities and risks for critical infrastructure
Recent headlines highlight how quickly AI is reshaping the cybersecurity landscape while longstanding questions about digital trust are becoming harder to answer. As AI becomes more deeply connected to healthcare, critical infrastructure, and other sensitive environments, organizations must determine how both human and machine activity should be governed. Across these developments, establishing trusted identity verification practices, controlling access, and maintaining accountability are becoming central to managing risk.
Signal 1: AI security incidents accelerate the push for regulation and oversight
The debate over AI regulation is moving closer to the technology’s real-world security risks. OpenAI and other major technology companies joined more than 100 organizations in calling for stronger defenses against AI-powered cyberattacks, warning that AI could lower the cost and expertise required to target critical infrastructure, including hospitals, water systems, and the internet.
At the same time, recent incidents are giving policymakers more concrete examples of what can happen when advanced AI behaves outside intended boundaries. OpenAI released its investigation into a July incident involving AI models undergoing cybersecurity evaluations that circumvented controls intended to isolate them from the internet, exploited vulnerabilities in shared infrastructure, and gained unauthorized access to Hugging Face systems. OpenAI attributed the behavior to several factors, including reward hacking, persistence, unauthorized communication among agents, and agents adopting goals from one another.
Those incidents are now directly influencing legislative proposals. A new bipartisan House bill, the Stop Rogue AI Act, introduced on September 3, would direct the National Institute of Standards and Technology (NIST) to develop standards, guidelines, and best practices for securely deploying AI agents. Among the proposed measures are continuous verification of agent actions, tamper-proof activity logs, security evaluations, and machine-readable inventories that give organizations greater visibility into which agents are operating within their environments.
A separate proposal goes significantly further. Sen. Bernie Sanders (I-VT) and Rep. Greg Casar (D-TX) are calling for a permanent ban on artificial superintelligence and a temporary pause on advanced AI development until a new federal regulator establishes safety rules and a model review process. Their proposed legislation would also create a Cabinet-level AI agency responsible for monitoring frontier systems and impose significant penalties for violations, including potential company shutdowns and prison sentences for individual developers.
Signal 2: More recognize identity and access as foundational to agentic AI governance
As policymakers consider how to govern autonomous systems, a clearer consensus is forming around how organizations should govern them. Recent work from NIST, Deutsche Telekom, and Vodafone points toward identity and access management as a foundational layer for agentic AI. NIST specifically cautions against relying on credential sharing, static tokens, and broadly scoped access, instead pointing to established IAM standards and practices as a foundation for securing agents.
The emerging regulatory conversation reinforces that direction. Proposals emphasizing agent inventories, continuous verification, logging, and accountability all depend on organizations being able to identify the entities operating within their environments and understand what they are authorized to do.
That's particularly important as AI becomes more deeply integrated into environments where unauthorized access carries significant consequences. This week, OpenAI integrated ChatGPT Health with Epic’s EHR system, enabling clinicians to use authorized patient context within clinical workflows. Coming shortly after the launch of ChatGPT Health, the integration illustrates how AI is moving even closer to sensitive data and daily care delivery processes.
Signal 3: Attacks continue to expose weaknesses in traditional signals of trust
Other recent security incidents highlight the evolving challenge of establishing trust, which becomes harder when credentials, accounts, brands, and documents used to verify identity are also compromised. More than a dozen health systems have warned patients about phishing campaigns impersonating MyChart. Epic has said the campaign represents abuse of the MyChart brand rather than a vulnerability in the platform itself, demonstrating that attackers don’t necessarily need to compromise a trusted system if they can successfully impersonate it.
McKesson also confirmed unauthorized access to third-party applications and data exfiltration impacting a subset of customers. The ShinyHunters extortion group claims voice phishing enabled attackers to compromise employee single sign-on accounts and access enterprise software environments, resulting in the theft of 284 million patient records. Meanwhile, KrebsOnSecurity reported that a dark-web service is selling more than 153 million driver’s license scans, apparently obtained from an identity verification provider. The FBI is investigating, and the source of the data has not yet been confirmed.
Signal 4: AI becomes both a cybersecurity tool and a force multiplier for attackers
AI’s dual-use nature is becoming especially clear in critical environments, where the technology can strengthen defenses while also giving attackers new advantages. AI companies are pointing to healthcare as one of the clearest examples of AI’s potential for positive impact, highlighting its use in areas such as medical research, drug discovery, and clinical care. At the same time, the National League of Cities is offering AI-powered cybersecurity capabilities to help local governments identify risks and strengthen resilience.
Yet the capabilities that make AI valuable can also make cyberattacks more effective. Recent reporting on threats to everyday utilities shows how AI can help attackers identify vulnerabilities and exploit them faster. For smaller utilities and municipalities with limited cybersecurity resources, that creates a difficult dynamic: AI may help close gaps in their defenses, even as it gives adversaries new ways to find and exploit those same gaps.
This dual use helps explain why AI governance is attracting greater demand. Organizations can use AI to strengthen defenses, while adversaries can use it to find weaknesses faster. The challenge for policymakers and security leaders will be establishing safeguards that allow organizations to benefit from AI while maintaining meaningful control over how these systems interact with critical environments.
What this means
The regulatory debate around AI is still unsettled, but recent developments point toward greater scrutiny of how autonomous systems are secured and governed. Whether future requirements focus on agent inventories, monitoring, audits, model reviews, or more restrictive controls, organizations will need to demonstrate greater visibility into which human and machine identities are operating in their environments, what they can access, and what actions they take. For security leaders, AI governance should therefore be treated as more than a future compliance issue. Building strong identity, access, and accountability controls today can help organizations prepare for both the security risks and governance expectations that are beginning to take shape.
Questions about the intersection of AI, identity, and cybersecurity?