TL;DR: An AI agent can pass every access check and still act on something false. In Josh's Lab, one agent made up a research source and a second agent wrote two documents on top of it. Every permission held all night. Access controls ask if an agent is allowed. You also have to check what it believes.
Key takeaways:
A chatbot writes. An AI agent acts, and it has permission to go ahead on its own.
Princeton researchers chained three AI systems that were each 90 to 97 percent accurate. The chain scored 74 percent.
In a fall 2025 survey by the Cloud Security Alliance and Strata Identity, 28 percent of 285 IT and security pros could trace an agent's actions back to a person.
In July 2025, an AI coding agent at Replit deleted a production database and made up more than 4,000 fake user records.
Identity tells you which agent acted. A check at the handoff tells you if its answer is true.
What makes an AI agent different from a chatbot?
A chatbot writes. An AI agent acts. Send a chatbot a billing complaint and the customer gets an apology and a link. Send it to an agent and the agent reads the email, finds the double charge, issues the credit, and writes back. It goes ahead on its own and skips the approval step.
That's the picture Michelle Savage and I open with in our chapter for John Kindervag's new book. The agent has hands, and that's the whole difference.
It gets more interesting when you run several agents together. One digs up information and passes it to a second. The second builds something and passes that along. Each handoff takes seconds, and no person reads it.
The second agent trusts the first one's work. That trust is the design. It's why the chain is fast.
Speed has a price. The chapter cites researchers at Princeton who linked three AI systems in a chain. Each one was between 90 and 97 percent accurate alone. Together they scored 74 percent. One run in four came out wrong, even though every link was mostly right.
So the question for a leader shifts. You already ask how good each agent is. Start asking how good the chain is.
What happened in Josh's Lab the morning an agent made up a source?
One of my AI agents, Scout, made up a research source. A second agent, Quill, wrote two documents on top of it. I caught it before nine the next morning, at a routine handoff. By then the false source had been shaping real work for most of a day.
I run a set of AI agents at home, in Josh's Lab. I break things there on purpose. I'd rather see how agents fail in my house than at a client's.
Scout digs up research and Quill writes from what Scout returns. A third agent, Atti, moves finished work along. Quill and Atti treat whatever Scout hands them as true.
That morning I saw a source I couldn't place. It looked right at a glance. The journal title fit the topic, and the institution behind it sounded real.
The journal was made up. So were the sources behind it. Scout had invented the whole chain.
Quill had already used it twice. First for a client-facing summary, then for a cleaner internal version. Atti was ready to send the work on when I stopped it.
By then the argument in both documents had bent to fit a made-up source. I rebuilt both from scratch, and it cost me most of a day.
A bigger version of this happened in public. In July 2025, an AI coding agent at Replit deleted a company's production database during a code freeze. Then it made up more than 4,000 fake user records and at first reported the damage couldn't be undone. Replit's CEO called it unacceptable.
Why did every access control pass that night?
Every control passed because each one asked the same question: is this agent allowed to do this? The answer was yes all night, and yes was correct. Scout used only the access it was given. There was no attack and no stolen password. The trouble was in what Scout believed.
I've turned that night over many times. Audit Scout against the policy I wrote and it passes clean. Quill and Atti passed too. They took input from a source they'd been told to trust, and they trusted it.
This is where Zero Trust comes in. John Kindervag created it, and its rule is "never trust, always verify." Zero Trust checks every request, every time. It checks who's connecting and what state their device is in.
AI agents need one more check on top of that. You verify the action as well as the connection. And you verify what the agent believes before the next agent builds on it.
We named the closing section of the chapter "Permission Is Not Proof." An agent with valid access and bad information passes every access check you own.
What does identity give you, and where does it stop?
Identity is what let me clean up. Every agent in Josh's Lab has its own name and writes one line for each action it takes. So I traced the false source to the exact agent and the exact minute. Identity told me who. It couldn't tell me the answer was wrong.
Without those lines I'd have been guessing. I'd have thrown out good work along with bad.
Plenty of companies are missing that trace today. Their agents share one account, or run on a service account someone set up years ago. The log says the account acted. It's silent on which agent, and on whose behalf.
The numbers back this up. In fall 2025, the Cloud Security Alliance and Strata Identity surveyed 285 IT and security professionals. Eighty-four percent doubted they could pass an audit focused on agent behavior or access. Only 28 percent could trace an agent's actions back to a human sponsor everywhere they run.
Then there are the agents you've never heard of. Someone in Marketing buys one with a company card and connects it to the customer database. Some people call these shadow agents. The chapter cites IBM's count: one in five breached companies traced the breach to shadow AI, and the heaviest users paid about $670,000 more per incident.
Two earlier posts go deeper on this side. One covers how an AI agent should log in to its tools. The other shows how OAuth consent grants give you an AI inventory you already own.
What does your AI agent believe, and who owns that?
Michelle Savage wrote this half of the chapter. Every agent works from two kinds of material: what you wrote for it, and what it picks up while working. The agent treats both as true. In most companies the written part has no owner and no date. She calls it the least governed document in your company.
Michelle has spent years writing the rules that tell systems how to talk. When I described the Scout morning, she spotted the cause right away. The instructions were the problem.
Scout's journal was the second kind of material. It came with no author and no approval. Quill gave it the same weight as the rules we'd written ourselves.
Her fix starts with a short document she calls the never list. It holds the rules an agent can't break. The catch is that something other than the agent has to be able to check each rule.
"Never make up a source" fails that test. An agent that invents a citation has no idea it did. The chapter shows the version that works, along with the rest of the list. Our post on what a never list for AI agents is walks through two of the rules.
Where should you check first?
Check the handoff between agents. Count your chains before you count your agents. A chain is any place one agent passes work to another with no person in between. Start with the chain closest to a customer. Then verify the one thing that would hurt most if it were wrong.
That handoff is where my bad morning came from. It's also the least-watched spot, and there's a reason.
Two markets sell into this problem. One sells identity and enforcement. The other sells output checking. In most companies, security buys the first and a platform or data team buys the second. Different budgets, different bosses.
The handoff between two agents sits right between those two teams.
The standards show the same blind spot. In December 2025, OWASP published its first top ten risks for agentic applications. Insecure communication between agents made the list. So did cascading failures and memory poisoning. An agent inventing a fact and passing it on as true isn't there yet.
After that morning, we changed one thing in the lab. Research now gets checked against an outside source before it moves on. If you want the stop button side of this, read how to stop an AI agent before it acts.
Where can you read the full chapter?
The chapter is "Identity and Instructions: The Two Controls Every AI Agent Needs," by Josh Woodruff and Michelle Savage. It's in John Kindervag's new book, Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era. Illumio published it in October 2026.
John created Zero Trust, and for this book he handed the pen to people who put it to work. Our chapter sits next to chapters by Dr. Chase Cunningham, George Finney, Rich Mogull, Jason Garbis, and others.
This post covers the story and the argument. The chapter has the to-do list. It gives you five steps for controlling who's acting and five for controlling what an agent believes. It also has the full never list, written so each rule can be checked.
Download Cyber Resilience at Machine Speed.
John also wrote the foreword to our own book in 2025. Agentic AI + Zero Trust: A Guide for Business Leaders carries his idea over to AI agents.
Frequently asked questions
Can an AI agent pass an audit and still be wrong?
Yes. An access audit checks what the agent was allowed to touch. Scout stayed inside its permissions the whole night and still made up a source. A clean access audit tells you the agent followed its rules. The facts the agent used are a separate check.
Is a made-up source a security problem or a quality problem?
It's both, and that's why it slips through. Security teams own identity and access. Platform and data teams own output quality. A false fact moving between two agents belongs to neither team by default. Put one named person in charge of that handoff.
Does Zero Trust apply to AI agents?
Yes. Zero Trust is the foundation, and it works on an agent the way it works on a person. You remove trust that was assumed and verify every request. AI agents add one more check on top: verify the action, and verify what the agent believes.
What's a shadow agent?
A shadow agent is an AI agent working inside your systems that security has no record of. A team signs up for a product and connects it to company data. It has no named owner and no log you can read, so shutting it off takes too long.
What's one thing to do this week?
Pick the chain closest to a customer. Find the spot where one agent hands work to the next. Add one check there, such as opening every cited link before the next agent uses it. Then put one person's name on that check.
Find out where your agents stand
Take the free assessment at verifiedagents.ai/assess. It takes about ten minutes and scores your agent controls across the five ATF elements, starting with Identity Management.
You know who has access to your systems. Now find out what your agents believe.
