Podcast: Play in new window | Download
Subscribe: Apple Podcasts | RSS
Amihai Niederman joins me on this episode of the TechSpective Podcast to talk about what happens to identity security once AI agents start outnumbering the humans on a company’s network. He’s the co-founder of NewCore, a startup betting the answer isn’t another tool bolted onto what companies already run. It’s a rebuild.
That bet is worth taking seriously. The identity stack most companies run today wasn’t built for this problem. It was built for a much smaller one.
Identity Grew Up As An IT Problem
For most of its history, identity has been treated as plumbing, not protection. Active Directory sat inside the network. If it got breached, the conversation was about how someone got past the firewall. Identity itself wasn’t seen as the thing that failed. That framing made sense when the network was the perimeter.
It stopped making sense once everything moved to the cloud. Identity providers became the real gatekeepers. Stealing a password turned out to be a lot easier than breaching network hardware. The industry responded the way it usually does. It bolted on point solutions, one after another, each one solving a piece of the problem on its own.
NewCore talked to more than 100 CISOs while building its product. The average company, they found, runs 8.3 identity tools. That’s a vendor number, worth taking with a grain of salt, but the picture rings true. A pile of tools from different makers, held together, hoping the seams don’t split.
Agents Break The Math, Not Just The Tools
None of that was built with AI agents in mind, and that’s where the trouble really starts. An agent isn’t just a faster version of a person logging in. Amihai draws a real line here. A lot of what gets called an agent today is really a power tool, with a person still making every meaningful decision. It only becomes an agent once you hand it a full task and let it decide which tools to use, in what order, on its own. At that point it stops being a stand-in for a human. It needs its own governance.
That distinction matters because of scale. Agents can work something like 100 times faster than a person, and they never log off. That’s not a modest bump in the number of identities a company has to manage. It’s closer to 100 times as many. A ninth tool doesn’t fix a jump that size. Amihai compares it to converting a gas engine to run on electricity. You can’t patch your way there.
Most companies are handling this the sensible way for now. Deploy one agent. Watch it closely. Adjust, then repeat. That works fine at a ratio of one agent to one human. It falls apart once the ratio flips, and the flip is coming faster than most rollout plans assume.
The Resistance Isn’t Where You’d Expect It
The instinct is to assume the hardest part of an identity rebuild is convincing a CISO to hand someone new the keys to the whole environment. It usually isn’t. CISOs already live with what’s broken in their current stack. They know exactly what they’re trying to fix. The real friction shows up everywhere else in the company. Old identity connections nobody wrote down. Employees who need a new authenticator app. A migration slow enough that nothing breaks along the way.
That’s the harder, less glamorous problem. It’s also the one that will decide whether identity security catches up to what AI agents are about to demand of it.
There’s more to this conversation than fits here. Where identity security goes as the ratio of agents to humans keeps climbing. A sharp comparison involving stoplights and self-driving cars. How NewCore is thinking about protecting actual people while building for a mostly agentic future.
Catch the full episode on the TechSpective Podcast:
- Rebuilding Identity Security From Scratch for the Age of AI Agents - September 21, 2026
- Moving Past Indicators Toward Behavior - September 9, 2026
- When the AI Breaks Its Own Rules - September 2, 2026




