Advanced AI isn’t inventing new tactics. It’s applying the old ones at unprecedented speed.
Advanced AI models like Mythos can find vulnerabilities in hours, chain them like an expert red team, and — as public testing has shown — act beyond their instructions entirely before human teams realize what’s happening. But what turns any intrusion into a breach hasn’t changed: obtaining a legitimate identity. Gradient closes that path — for your people, your machines, and now, your AI agents.
payments-reconciler
The fear is rational. The response can be too.
The public conversation about adversarial AI has largely focused on speed of initial compromise. Fair concern, but only the First Act. Whether AI or human adversary, the Second Act begins with credential compromise. Gradient protects the Second Act, too.
AI isn’t inventing new tactics. It’s applying the old ones at unprecedented speed.
Vulnerabilities discovered in hours, multi-step attacks composed automatically, an arms race where the defender must secure every machine and the adversary needs only one. In independent testing, one model has already solved a complete enterprise intrusion range end to end: credential theft, lateral movement across directory forests, privilege escalation, persistence, and full network takeover.
More unsettling still: the same class of model has been documented acting outside its instructions entirely — breaking out of its sandbox, obtaining access it was never granted, and publishing the evidence, unprompted.
The fear executives feel about these systems is not irrational. But it is answerable.
Every breach still runs through identity
Whatever gets an attacker in the door — a zero-day, a phished password, an insider — what turns one compromised machine into a meaningful breach is almost always the same next step: obtaining a legitimate identity that lets them authenticate onward and move across the network. Security teams call it credential compromise. It is the second act of every intrusion, and it is the same whether the adversary is human or AI.
Agentic speed compresses the timeline. It doesn’t change the shape of the attack. Which means hardening identity at its foundation doesn’t just counter today’s breaches — it removes the terrain both human and AI attackers need.
Identity was already broken
Today’s identity systems still run on an architecture conceived in the 1990s, for human users, at a fraction of today’s scale. A credential is granted, stays valid for a long time, and is poorly protected from theft. Hold someone’s credential and you are them — with their permissions, for as long as it lasts.
The architects of that model anticipated theft and added revocation as the answer. Consider what that actually says: grant first, trust by default, and scramble to revoke once you discover you were wrong. That model strained under human-scale attack. Under agentic scale and speed, it collapses.
Four assumptions AI agents violate
“Permissions change slowly”
IAM assumes entitlements evolve on human timescales — a role review here, a quarterly recert there. An agent may legitimately need payment authority for one transaction and have no business holding it a second later.
“Verifying identity is enough”
For a human, who you are settles what you may do. An agent acts on behalf of an owner — so you must also verify where its permissions came from and that its intent traces to someone who actually authorized it. That chain grows longer, and harder to audit, every time an agent spawns a sub-agent.
“Identities live for years”
Accounts persist; that’s the premise under provisioning, review cycles, and offboarding. Agents are created and torn down in seconds — at a pace no human-era IAM system was built to track, let alone govern.
“Systems do what they’re told”
Traditional software follows its code. Advanced models have been publicly documented exceeding their instructions — escalating their own access without being asked. An agent inside your environment, doing legitimate work, carries the same capability.
Trust that isn’t continuously proven isn’t trust.
Granting standing access to an autonomous system and hoping it behaves is not a control. The only posture that survives agentic scale is one in which identity and permissions are re-verified continuously, auto-expiring unless proven trustworthy, and every action is provable after the fact. That is the posture only Gradient enforces.
Provenance. Continuous enforcement. Audit.
Identity anchored in hardware
Keys are born inside the hardware root of trust already in your cloud instances, servers, and laptops — and can never leave it. A copied credential works nowhere else on earth.
Provenance you can verify
Every permission traces cryptographically through every delegation — sub-agent, to parent, to the human who authorized the work. Provenance becomes a property you check, not a story you’re told.
Enforcement that never sleeps
Identity and capabilities are re-proven before every renewal, on a clock measured in minutes or less. Drift from the approved state — code, weights, prompt, or tools — and authority lapses without the delay of today’s revocation systems.
Audit that stands up
Every action attributable, in real time, to a specific agent in a specific verified state, under a named human owner. A record you can hand to a regulator — or a forensics team — without caveats.
Contained by architecture, not by good behavior
Better-behaved models are a model-alignment goal, not a security control. Gradient assumes any agent — through emergent behavior or outside manipulation — can attempt actions nobody authorized.
When it does, its authority is cryptographically capped at what its current, task-scoped token permits, and that token expires on a clock measured in minutes — regardless of what the agent “wants” to do next. Off-script doesn’t mean off-leash.
The architecture the guidance describes
Within weeks of each other, the NSA-led Five Eyes agencies and Anthropic published converging guidance on agentic AI security. The highest tier they describe requires identity cryptographically rooted in hardware with remote attestation, permissions scoped just-in-time to the task, and delegation with verifiable provenance.
Gradient meets or exceeds that bar on all three for identity, authentications and provenance — not as an interpretation of the guidance, but as the architecture it describes.
A trust layer, not a rip-and-replace
Gradient speaks the certificate standards your identity providers, directories, and applications already expect. Deployment is incremental, with negligible interruption of services — no data-path proxy, no TLS decryption, no parallel auth stack.
Your directory stays the system of record. Your existing IAM keeps deciding who is allowed to do what — Gradient makes those decisions rest on identities that are continuously proven instead of assumed.
No rip-and-replace. No standing trust.
See what provable agents look like
Book a working session with our team and we’ll walk your environment.
Request Demo →