{"data":{"id":"a110408c-7bf0-4003-a688-1d59669282cb","title":"IAM for AI agents: A Practical Enterprise Framework","summary":"This guide argues that identity and access management (IAM) for AI agents must treat each agent as a non-human identity with a human owner, a defined purpose, scoped authorization, an expiration, and continuous monitoring. It states that conventional IAM platforms express intended access but cannot show what an agent actually executed, a gap the guide calls identity dark matter. It also cites OWASP's excessive agency risk (LLM06) as a failure mode that static role assignment cannot bound.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://thehackernews.com/2026/09/iam-for-ai-agent.html","publishedAt":"2026-09-28T18:20:38.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-09-28T18:20:38.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}