Since the invention of the computer, humans have been the primary actors operating software.

That is changing. Companies will soon have more software actors than employees. They can be created instantly, operate continuously, and carry authority across every system a company runs. And the surface is exploding as the number, autonomy, and speed of these actors increase dramatically.

We are already seeing the cracks. Coding agents are routinely run without permission checks. Agents have deleted users' data and wiped production databases and their backups in seconds. During an internal evaluation, OpenAI models exploited a zero-day, escalated privileges, and used stolen credentials to compromise Hugging Face's production infrastructure. These incidents feel exceptional today, but will not be for long. Models are rapidly becoming more capable, and companies are accelerating AI adoption, access, and autonomy.

Modern access systems are designed for humans and assume they act slowly, intermittently, and with oversight. However, agents can discover, combine, and exercise access across systems at machine speed. A permission that might sit dormant for a human can be exercised thousands of times by an agent. Access control built for humans will not scale to a world of autonomous software.

Security must evolve. Organizations will need to know every agent that exists, what it can reach, who authorized it, what task it is performing, and what it is doing right now. Standing access will give way to short-lived, contextual authority. Safe, routine actions will happen autonomously while humans approve sensitive boundaries and exceptions. Policies must be enforced rigorously outside of models with audit trails to capture complete action trajectories. Containment and reversibility will become as important as prevention. Security and governance must operate continuously and at machine speed.

That's why we are launching Lumos Labs to push the frontier of governance and access management for agents. We're an applied AI team with the mandate to pave the way for the next generation of identity products in an agentic world. We will build alongside enterprise security teams, publish what we learn, and contribute to emerging industry standards. Lumos already governs human and non-human access for some of the world's largest enterprises.

Our north star is to make it safe for enterprises to give increasingly capable agents the access they need to be useful. This begins with visibility and governance, and will require interoperating with identity providers, agent runtimes, and emerging standards such as XAA for cross-app agent access. We believe the right place to start is with workflows where mistakes carry the greatest consequences: agents that move money, modify production infrastructure, or work with sensitive customer data.

If you want to collaborate on a safer agentic future, we'd love to talk.