What changed
- The primitives shipped. Microsoft's Entra Agent ID reached general availability in April 2026, extending Zero Trust to non-human identities. Okta's Cross App Access, introduced in June 2025 as an open OAuth extension, spent 2026 widening its ecosystem.
- A standards body named the risks. OWASP maintains a Non-Human Identities Top 10 covering service accounts, API keys, OAuth tokens, workload identities and AI agents, alongside a Top 10 for Agentic Applications 2026.
- The money arrived. On deal-tracking counts, startups at the intersection of AI and security raised roughly $855M across more than 150 seed rounds in 2026, on pace for a record year.
- And so did the postings. Market surveys report AI governance hiring up around 150 per cent year on year, with more than 14,000 open roles matching a governance search on LinkedIn — a platform search count, not a clean taxonomy.
- The novelty is oversold. OWASP's own agentic guidance says agents mostly amplify existing vulnerabilities rather than inventing new ones. The role is real; the marketing around it is not.
Three things had to land at once
New job titles appear constantly and most of them evaporate. What separates a durable role from a conference-circuit fashion is whether three independent things happen in the same window: someone builds the primitive, someone names the risk, and someone writes the cheque. One alone produces a research agenda. Two produce a product category. All three produce a headcount request that survives a budget review.
In 2026 all three landed on the same problem.
| Pillar | What landed in 2026 | What it gives a team |
|---|---|---|
| Primitive | Entra Agent ID general availability (April 2026); Okta Cross App Access, an OAuth extension positioned as vendor-neutral, extended to Amazon Bedrock and opened to rival identity providers in May 2026 | Agents become first-class directory objects with policy that follows them across applications, rather than shared secrets pasted into a config file |
| Standard | OWASP Non-Human Identities Top 10; OWASP Top 10 for Agentic Applications 2026 | A shared vocabulary — NHI2 secret leakage, NHI7 long-lived secrets — that lets an engineer and an auditor describe the same failure |
| Capital | ~$855M across 150+ seed rounds in 2026; Act Security out of stealth with $60M; Hush Security's $30M Series A aimed squarely at non-human identities and enterprise agents | Vendors with sales teams, which is how a technical problem becomes a line item in someone's budget |
The consolidation signal is already visible further up the market. Cyera's billion-dollar approach to Oasis, which we covered in Cyera's $1B bid for Oasis, put a price on the category well before most enterprises had written a policy for it.
Why an agent is not a service account
The technical case for a distinct identity type is narrower than the pitch decks suggest, but it is genuine. A classic service account is a standing identity with a fixed set of permissions and a credential that lives until someone remembers to rotate it. It has no notion of whose behalf it is acting on, no expiry tied to a task, and usually no clean revocation path that does not break something else.
An agent needs all three of those properties. It acts on behalf of a specific human, with a scope that should be delegated rather than inherited, bounded in time to the task, and revocable the moment the task ends or the human's own access changes. Okta has since added agent discovery to its Identity Security Posture Management product and agent identities to Universal Directory. Those features exist because most organisations still cannot answer the first question — how many agents do we have — let alone the second one about what each of them is permitted to touch.
That gap is why the enumeration problem comes before the policy problem. If you want the practical mechanics rather than the market view, our guide to least-privilege credentials for AI agents works through scopes, token lifetimes and rotation in the detail this piece skips.
The credential problem underneath
The urgency does not come from anything exotic. It comes from the oldest failure in the book. The two entries doing most of the damage in OWASP's list are NHI2 and NHI7 — secret leakage and long-lived secrets — which, on the published incident write-ups of the past two years, sit behind most of the named non-human identity breaches. The scale underneath them comes from secret-scanning vendors rather than from any independent audit, so read it as a scan-derived estimate: those vendors report that public GitHub absorbed nearly 29 million new hardcoded secrets during 2025, a 34 per cent increase year on year, and that 64 per cent of the secrets that leaked as long ago as 2022 were still working in early 2026.
Read that last figure again. Two-thirds of credentials that leaked four years ago still work. Now add agents, which by their nature hold more credentials, use them more often, and are deployed by teams who did not previously ship anything that authenticated to third-party systems. Non-human identities already outnumber human ones in cloud environments by roughly 45 to 1 on a widely cited industry estimate — a figure worth treating as directional rather than measured, since nobody audits it centrally. Agents move that ratio in one direction only.
The part the vendors would rather you skipped
Here is the awkward sentence sitting in the middle of OWASP's Top 10 for Agentic Applications 2026: agents mostly amplify existing vulnerabilities rather than creating entirely new ones. That is a standards body, not a competitor, saying that the discipline being sold as unprecedented is largely the discipline you already had, operating at a scale you were not prepared for.
This matters for how you hire. If the problem were genuinely novel, you would need people who had studied it, and there would be almost nobody. If the problem is amplification, you need people who are good at credential hygiene, delegation modelling and audit trails — skills that exist in your platform and security teams already, applied to a new object type. The second framing is both more accurate and considerably cheaper to staff.
It also sets the bar for testing. The failure modes are concrete enough to be probed, as AgentRedBench's 215 authorisation attacks demonstrated — and a candidate who has run something like that against their own agent has shown you more than a certificate does.
One number doing heavy circulation this year claims that 98.5 per cent of organisations describe their AI governance staffing as inadequate. That is a vendor survey figure, and a result that round and that near-unanimous should raise an eyebrow rather than a budget request. Self-selected respondents answering a question posed by a company selling the remedy do not produce measurements. Use it as a mood reading if you like; do not put it in a board paper.
What the role pays, and where
The compensation picture is unusually well documented for a discipline this young, though every figure below is a market survey of posted ranges rather than audited pay data, and should be read as such.
| Market | Posted range | Notes | Source type |
|---|---|---|---|
| United States, individual contributor | $120,000 – $270,000 | Median $158,750; 85% of postings ask for 5+ years | Axial Search analysis of 146 postings, January 2026 |
| United States, director / VP / chief | $300,000+ | Same dataset, senior band | Axial Search, January 2026 |
| India, experienced practitioner | ₹21 – ₹48 lakh | Metros pay roughly 10–20% above tier-2 for the same band | Market salary survey |
| United Kingdom | No comparable published dataset | Demand concentrated in financial services and the regulated sector | Not available — treat any single quoted UK figure with caution |
| Sector premium, both markets | +20% to +30% | Financial services and healthcare over general tech, same role | Market salary survey |
We have deliberately left the UK figure out rather than filling it with a number we cannot stand behind. The honest position is that UK demand is visible and the pay bands are not yet published in a form worth quoting.
Every article here is written by a Verified Builder. Want your name on the next one?
AI Tech Connect lists AI engineers, founders and researchers across India and the UK — and the people hiring browse it to find them. Adding your profile is free.
Become a Verified Builder →UK and Indian demand are not the same shape
British demand clusters in financial services and the wider regulated sector, driven by FCA conduct expectations and ICO scrutiny of automated decision-making. Add extraterritorial reach: a UK firm placing a system on the EU market inherits obligations regardless of where its engineers sit. Article 50 transparency duties applied from 2 August 2026, while the Digital Omnibus pushed the high-risk regime for standalone Annex III systems to 2 December 2027 and for AI embedded in Annex I regulated products to 2 August 2028 — the sequencing we set out in our piece on what the EU AI Act actually enforces now. That deferral bought time; it did not remove the requirement to know which of your agents touch a high-risk use case.
Indian demand has a different centre of gravity. It sits in global capability centres and services firms carrying compliance obligations on behalf of Western clients, which means the governance work arrives as a contractual deliverable rather than a domestic regulatory one. That shapes the job: more evidence production, more mapping between a client's control framework and your own, less arguing with a domestic regulator. It is also where the hiring volume is, as we cover in our guide to AI roles in global capability centres.
The pay gap between the two markets is real and there is little point pretending otherwise. A ₹21–48 lakh band does not convert to the US median, and it does not need to — but anyone choosing between a Bengaluru GCC role and a London fintech role should price the difference honestly, including the fact that the GCC role often carries broader scope earlier.
"The interview that got me the offer was not about frameworks. They asked me to walk through how I would revoke a single agent's access to one downstream system at 2am without taking down the other eleven agents sharing that integration. I had actually built that, so I had an answer. Nobody asked me which certification I held."
— Arjun, Verified Builder · Bengaluru, INNobody has ten years of experience in this
Eighty-five per cent of postings ask for five or more years, in a field whose central primitive reached general availability four months ago. Those two facts cannot both be satisfied. What hiring managers are actually screening for is judgement about credentials and delegation, and they have written "5+ years" because that is what the requisition template demanded.
This is the rare moment where demonstrable proof-of-work genuinely beats credentials, because the credentials do not exist yet. A public repository showing an agent with scoped, time-bounded, revocable access to two real systems, a written threat model, and a log of what happened when you tried to break it — that artefact answers the question the interview is groping towards. Our companion guide published today, the AI governance engineer career path, maps the skills in sequence, and the proof-of-work path into AI agent security covers what to build and how to present it.
The uncomfortable corollary is that the window closes. Roles defined by scarcity of evidence get harder to enter once the evidence becomes standardised — once there is a certification, a syllabus and a recognised employer path, the advantage of having built something shifts back towards the advantage of having been credentialed. That transition usually takes two to three years. This is year one.
Where this settles
Our reading is that agent identity does not remain a standalone job title for long. It is more likely to be absorbed — into platform engineering at organisations that treat it as a credential problem, and into risk and compliance at organisations that treat it as a documentation problem. The teams that get it right will be the ones that refuse to let it become purely either.
For now, though, it is a title with open requisitions, a funded vendor ecosystem behind it, and a shortage of people who can prove they have done the work. If you are one of those people, the move that pays is to make the work visible while the evidence is still scarce. Proof is currently worth more than a CV in this corner of the market, and that will not stay true indefinitely.