OpenAI’s disclosure about the Hugging Face incident gave security leaders a jawdropping lesson in just how powerful and unpredictable AI agents can be. During internal cybersecurity evaluations, OpenAI said its models circumvented internet-isolation controls, communicated through unauthorized channels, exploited weaknesses in shared infrastructure and ultimately reached Hugging Face systems. The most stunning part is not just that they escaped the sandbox. The agents secretly created their own communications channel inside OpenAI’s infrastructure, used it to share exploits and techniques for getting internet access, rebuilt that channel after OpenAI wiped the system, coordinated and delegated work across agents, and then used what they learned to compromise Hugging Face.
Here’s where it goes from jawdropping to frightening: OpenAI says is that the people responsible for the later incident response did not understand the existence, scope or significance of the agents’ improvised communications network and inter-agent coordination. They did not connect the broader activity to the Hugging Face compromise until weeks later.
Most enterprises are facing a more familiar version of this Hugging Face incident. Businesses are moving quickly to give agents access to applications, data, APIs, tools and workflows, while security teams are still working out how those agents should be discovered, identified, governed and controlled. The result is a widening gap between the speed and maturity of AI adoption and the security operations needed to manage the risks that come with it.
That maturity gap is the focus of The CISO’s Guide to AI Agent Identity Security Maturity, a webinar with AppViewX’s Chief Product Officer, Paul Trulow, Dr. Srijith Nair, Group CISO at Beyond One, and Scott Kennedy, CISO at AppViewX, were remarkably open about their experiences. They examined the problem from the perspective of the executives who actually have to turn emerging security principles into operating programs.
As much of the industry conversation is being driven by researchers, vendors, standards bodies and AI platform providers, this discussion is much closer to the decisions security leaders now have to make about priorities, investment, risk tolerance and how quickly their organizations need to move.
Nair puts his finger on one of the most difficult aspects of the problem. Security has traditionally had the option of slowing an initiative down when the controls were not ready, but the economics and organizational momentum surrounding AI make that approach increasingly unrealistic. “You don’t have the luxury of doing that in the AI agent world,” he says. Business leaders see productivity, automation and economic value, while security organizations are being asked to establish sufficient control without becoming the reason those initiatives cannot move forward. His conclusion is that security has to mature alongside the business and in many organizations is already racing to catch up.
The AppViewX Agent Identitiy Security Maturity Model maps that progression across five levels.
- L1, Ad Hoc, describes an environment in which agents are largely unmanaged and security has little reliable visibility into their ownership, credentials, privileges or activity.
- L2, Managed, introduces centralized inventory, named owners, dedicated agent credentials, basic risk classification, access controls and logging.
- L3, Core Identity, moves toward standardized governance, automated discovery, unique agent identities, stronger credential lifecycle management, least privilege, explicit delegation and behavioral monitoring.
- L4, Delegated Authority, adds continuous verification and enforcement through deeper AIBOMs, just-in-time credentials and entitlements, cryptographically verifiable delegation, continuous risk assessment and automated containment.
- At L5, Autonomous, controls become dynamic and operate at agent speed, with live access graphs, intent-aware risk, adaptive authorization and real-time remediation.
That progression makes Kennedy’s assessment particularly striking: “most organizations, I think, are somewhere between L1 and L2 currently.” In other words, many enterprises are still moving from unmanaged agent activity toward basic visibility, ownership and control even as the business is putting agents into increasingly consequential applications and workflows. Kennedy describes the move to L2 in very practical terms: knowing which agents exist, who is responsible for them and, critically, “what can that agent do?”
As we saw in the Hugging Face incident deep dives, visibility is critical and often lacking, but the discussion makes an important distinction between seeing an agent and actually having it under control. An inventory can tell security that an agent exists but it doesn’t always indicate who is accountable for it, what authority it has accumulated, what systems it can reach or what happens when its behavior changes. Kennedy suggests having the answer to two critical questions: “Who’s responsible for the agent, and then what can that agent do?” Those are simple questions until an enterprise is dealing with hundreds or thousands of agents being created across different platforms, business units and development environments.
As programs develop, periodic inventories and point-in-time access decisions have to give way to controls capable of keeping up with agents that can be created, modified and granted new capabilities much faster than human identities. The webinar explores how discovery, accountability, authentication, authorization, delegated authority, risk and detection have to mature together, while recognizing that organizations will not advance all of those capabilities at the same pace.
Nair argues that reaching an advanced level across every security domain may neither be practical nor economically justified; the level of investment should reflect the sensitivity of the workload, the authority being granted and the business risk involved. Some environments may require much stronger controls sooner, while others can remain at a lower level of maturity without creating unacceptable exposure. That turns the maturity model into a prioritization mechanism rather than a compliance scorecard.
It also creates a better conversation with the board and the rest of the business. Instead of telling leadership that “AI risk is increasing,” a CISO can describe where the organization has control, where it does not, which agent populations create the greatest exposure and what capability needs to mature next. Kennedy notes that AI has put many security programs “back on their heels,” and argues that agent security is already appropriate for board-level discussion because maturity gives leaders a much more concrete way to understand gaps and make investment decisions.
If your business is already experimenting with or deploying AI agents, watch The CISO’s Guide to AI Agent Identity Maturity,to hear Dr. Srijith Nair and Scott Kennedy examine where enterprises are today, how CISOs should think about advancing agent identity security capabilities, and which parts of the maturity model deserve attention first as adoption scales.







