Identity Security and PAM Blog for CISOs and IT Security Pros

Collective Cyber Defense Starts with Identity

Written by Art Gilliland | Aug 28, 2026, 8:41:25 PM

OpenAI is warning business and security leaders that AI-enabled cyberattacks are about to become far more widespread and sophisticated. This puts critical systems like hospitals, water treatment plants and internet infrastructure at greater risk.

In an open letter signed by more than 120 organizations, including Microsoft, Google, AWS, Anthropic, Cisco and CrowdStrike, OpenAI is calling for collective action on cyber defense.

We support this call. The signatories describe a limited window in which defenders can use AI to fix weaknesses that have accumulated for years.

Patching is only half the answer

The easy reading of the letter is a patching mandate: Find the vulnerabilities before the attackers do and fix them faster than ever. That work is necessary. But if you look closely at the letter’s list of what has left systems exposed, you’ll find longstanding bugs, unpatched software, excessive permissions and weak authentication.

Excessive permissions and weak authentication are identity problems. They are also what attackers use after they get in, no matter how they got in. A vulnerability is the door. The access you granted months ago decides how far the attacker gets. AI decides how fast. Mapping an environment and finding the credentials worth stealing used to take a skilled attacker weeks of patient work. AI does that now, at scale, against every organization at once.

The letter recognizes that patching has limits: Where a system cannot be patched without disrupting essential services, it calls for compensating controls, applied and verified. For many of those systems, the compensating control an organization can apply fastest is identity. You may not be able to patch the legacy system that runs a treatment plant, but you can control which identities reach it, remove the standing access that surrounds it and record every action taken on it.

Access control is work every organization can start this quarter. It requires no new invention, and it does not take essential services offline.

Standing privilege is what attackers inherit

Most organizations have powerful access sitting unused across their environment, waiting for someone to inherit it. An administrator keeps production access because they might need it later. A service account holds broad permissions around the clock for a process that runs once a week.

Unused access is still access, and AI has made every attacker faster at finding it

The pressure is moving the wrong way. Delinea’s 2026 Identity Security Report, “Uncovering the Hidden Risks of the AI Race”, found that 90% of security teams are under pressure to loosen identity controls to keep AI initiatives moving. We are widening access at the exact moment attackers are accelerating.

Zero standing privilege (ZSP) closes that gap without slowing the business and is scoped to the task at hand. Access is granted when it is needed, scoped to the task at hand and removed when the task ends. An attacker who compromises an identity then inherits nothing, and the blast radius stays contained.

The letter's ask of AI companies is one Delinea already meets: runtime authorization

My conversations with CISOs and security leaders keep landing on the same two questions: How to adopt AI faster without sacrificing security, and how to defend against AI-driven attacks. They sound like separate problems, but it’s the same control: what an AI identity is allowed to do.

The open letter asks frontier AI companies to ensure agentic identities are traceable and accountable. Underneath that task is a harder truth: an AI model cannot be held accountable. Instead, the organization that deploys the AI model should be held responsible. Delinea runs AI agents inside our own business, and if one of them causes damage, we are responsible.

AI agents are already privileged identities that appear, act and disappear faster than traditional access controls can handle. Like human identities, AI agents use all the access you give them. Unlike human identities, you cannot always predict what an agent will do next. 

That’s why authorization has to happen at the moment of action, not just the moment of access. Point-in-time access controls were built for humans. AI agents need continuous authorization: commands, queries and actions evaluated against policy before they execute, tied to a named identity, under the authority of an accountable human sponsor. Actions that fall outside policy do not run.

What best practices look like for securing identities

  • Create an inventory of actions, not an inventory of agents. Agents appear and disappear faster than an inventory cycle can track them.

  • Don’t waste time with agent discovery. Start with control and build an inventory out from the systems that matter. An inventory of actions AI is taking is more valuable for risk reduction.

  • Retire standing privilege. Start with the accounts and systems an attacker would gain the most from inheriting.

  • Broker every secret you can’t eliminate. Vault it, rotate it and deliver it only for the connection that needs it.

  • Keep authorizing after the door opens. Evaluate every action taken by the identity, not just the initial access. This runtime authorization process ensures you control every action during the entire session.

  • Hold every agent to a named account. Know which agent acted, under whose authority and exactly what it did.

Where collective defense starts

Collective defense doesn’t mean every organization does everything. Collective defense means each of us moves first where we can make the most difference and then share what works. For cybersecurity companies, the letter is specific: Strengthen existing tools, close gaps now and measure progress by how many organizations are protected. For everyone else, it is identity: the access you’ve already granted and the agents you’ve already deployed.

Collective defense is new. What attackers are after is not. The window won’t stay open, and organizations that spend the window on the access they already control will be ready for what comes through next, because something will.

See how Delinea controls what AI agents, humans and machines do once they have access.