Short answer. Treat an AI agent like a service account with two additions. Give each agent its own identity so teams can trace and retire it, and carry the requesting user on each request so the agent can reach only what that person can. Without the second part, everyone who uses the agent gets the account's full access.
An agent needs its own identity once it acts for people
Service accounts were made for programs that run the same task on a schedule, without a person asking, so one fixed set of access works. An AI agent does different things for different people, based on what each one asks. On a service account, everyone gets the same access. With its own identity, each request carries the person asking, so the agent gets only their access.
Agents need person-level access checks without being managed as people
An agent should get the access of the person it works for, and keep an identity of its own. Each request is checked against what that person can reach, and that access ends when they leave. Because the agent has its own identity, teams can revoke or rate-limit it without touching the person's account. A service account offers neither: everyone shares its access, and shutting it off stops every job that uses it.
Identity providers can register agents, and checks on each request often need another layer
With a service account, the tool accepts any request the stored key allows. Many identity providers can now register an agent and the team responsible for it, which covers who the agent is. Deciding each request usually takes another layer between agents and their tools. It checks the request against the person asking, stops a revoked agent at its next call and records each decision.
Frequently Asked Questions
What is an AI agent identity?
An AI agent identity is the identity you register for one agent, along with the team responsible for it, so each request shows which agent is acting and for whom. In practice, it often replaces the shared key or personal token an agent runs on today.
Isn't an AI agent just another service account?
For an agent that runs one task on a schedule, it can be. Once several people use the agent, a plain service account gives all of them the same access and logs only the account name. The missing piece is the person asking, carried on each request.