Identity, AI/ML, Governance, Risk and Compliance

“Stop asking whether AI works and start asking what it can reach”: C1 CISO on AI agent security

AI agents are already inside the enterprise, often with access to business systems, data, and security tools. The problem is that many companies still do not have a clear view of where those agents are running, what they can reach, or who is responsible for their access.

This is becoming an identity issue. Security teams have spent years managing access for employees, contractors, and applications. Now they have to account for agents that can act on their own, move between systems, and make decisions much faster than a person could.

C1 CISO Kevin Paige says most CISOs understand the risk, but what they are missing is visibility. Many organizations know they have a growing number of non-human identities, but they cannot confidently say how many exist, what permissions they hold, or whether those permissions are still necessary.

C1 is trying to address that gap by bringing people, workloads, and AI agents into an identity governance model. The company has also launched Autonomous Worker, an agent that handles some identity governance tasks itself.

In this conversation with MSSP Alert, Paige talks about how companies should think about access for AI agents, where current identity programs are falling short, and how MSSPs and other partners can build services around discovery, access reviews, governance, and ongoing monitoring.


MSSP Alert: What does C1 actually do, and why is identity suddenly such a big part of the AI agent conversation?

Kevin Paige: C1 is an AI-native identity security platform. In plain terms, we govern access. Who can get into your most important systems, what they can do once they are in, and whether that access should still exist tomorrow. For years, that meant two populations, people and applications. Now there is a third one in the building, the AI agent, and it is the fastest-growing of the three.

Identity moved to the center of the AI conversation for a simple reason. An agent is only as safe as what it is allowed to do. It does not matter how capable the model is if it is holding a standing credential in finance, IT, and customer data, and nobody is watching what it touches. The old question was who has access. The new question is what this agent can do, on whose behalf, and whether it is staying inside those lines. Agents act, decide, and move between systems at machine speed, so the cost of getting access wrong is far larger than it was when identities were just people and apps. C1 brings all three populations, people, workloads, and agents, into one place where you can see them and govern them.

MSSP Alert: When you talk to CISOs, are they worried about AI agents having too much access, or are they still trying to figure out where these agents even exist?

Kevin Paige: Both, but not in equal measure, and not in the order you would hope. The worry about too much access is real. Our 2026 Future of Identity Report found that 87% of security leaders now rate non-human identity risk as urgent, so the concern is there. The problem is that they cannot see the agents well enough to act on it. Only 22% say they have full visibility into their non-human identities. Agents are getting spun up by developers, by business teams, by SaaS tools that quietly shipped an AI feature last quarter, and almost none of it runs through a central identity process.

So the honest state for most security leaders is that they know it matters, and they still cannot find all of it. You cannot govern what you cannot inventory, and right now, the inventory is the gap. The access problem sits downstream of a visibility problem, and the visibility problem is bigger than most teams think.

MSSP Alert: C1 just launched Autonomous Worker, an AI agent doing identity governance work. If AI agents are creating new identity risk, how do you make sure the agent fixing identity problems does not become another identity problem itself?

Kevin Paige: The honest answer is that the agent doing the governance has to live under the same rules as every other identity, and we built it that way on purpose. Our governance agents are modeled as regular users inside the platform. They get their own roles, their own permissions, their own entitlements, and they are subject to the same policies they enforce. The watcher is not above the system. It is an identity inside it.

Underneath that, the controls are concrete. Each agent gets a finite, predefined set of tools, and if a task is not in its toolkit, it simply cannot do it. The core instructions are immutable, so an agent cannot be talked out of its own guardrails by clever input, which is how we defend against prompt injection. We separate the agents that can take action from the ones that read untrusted input, so the piece that can approve access never touches raw user text. Every action an agent takes is logged in detail and tagged as agent activity, and a human can be inserted at any point in the flow. The way we put it internally is that their work can be approved by humans, but humans no longer have to do the work itself. If our own governance agent could not be governed, we would have disproven our own product. So it is the most tightly scoped worker on the network, not the least.

MSSP Alert: Your 2026 identity report says 95% of enterprises are already running AI agents autonomously. Are CISOs treating this like a real identity problem yet, or is it still sitting in the AI experimentation bucket?

Kevin Paige: That number is the whole story, because it means the experiment is already over. When 95% of organizations are running agents that autonomously perform IT or security tasks, this is not a lab project. It is production, touching real systems and real data right now.

And to your question, the awareness is actually there. In the same research, 87% of leaders called non-human identity risk urgent, and nearly half already run more non-human identities than human ones. So most CISOs are past denial. What they are missing is not belief, it is capability. They know it is real, they rate it urgent, and they still do not have the visibility or the controls to do much about it yet. That gap between knowing and doing is where the risk actually lives. The reframe I push is simple. Stop asking whether the AI works and start asking what it can reach.

MSSP Alert: For partners, where does C1 fit in? Is this mainly a security sale, an identity governance sale, or a bigger services conversation around helping customers find and control non-human workers?

Kevin Paige: It opens as a security conversation, because fear is what gets the meeting, but it lands as identity governance, and for partners the real prize is the services layer on top. Finding and controlling non-human workers is not a one-time project. Agents get created and retired constantly, their access drifts, and the population never stops moving. That is not something you install and walk away from. It is an ongoing discipline, and ongoing disciplines are exactly what partners are built to deliver.

We frame it for partners as governing access across humans, workloads, and agents, and helping customers adopt AI securely and at speed. Whether a partner resells or refers, the durable framing is the same. You are the team that helps a customer find every non-human worker they did not know they had, decide what each one should be allowed to touch, and keep that true as the population changes week over week. The product underneath can be C1. The relationship on top belongs to the partner, and it renews.

MSSP Alert: Where is the revenue opportunity for partners? Can they turn this into assessments, access reviews, governance projects, managed monitoring, or ongoing services?

Kevin Paige: All of it, and the smart way to see it is a ladder, not a menu. The entry rung is the assessment. Every customer needs someone to walk in and answer a question they cannot answer themselves. How many non-human identities and agents do we actually have, and what can they reach? That discovery work is billable on day one, and it draws the map for everything that follows.

From there it climbs. The map becomes access reviews and cleanup, which become standing governance projects, which become the real recurring revenue, ongoing identity security for the non-human population. And that annuity is bigger than the human side, because nearly half of enterprises already run more non-human identities than human ones, and agents churn far faster than employees, so the review-and-recertify cycle never ends. A partner who owns identity security for a customer's agents owns an engagement that grows every time that customer adds another one. That is the opportunity. Not a license resale. A permanent seat as the team that keeps the customer's non-human workforce under control.


Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds