The rush to deploy AI agents across Australian workplaces has run well ahead of the plumbing needed to keep them in check, and a growing cohort of security vendors is now trying to close that gap. The latest is Rubrik, the US-listed data security company, which has launched a product it calls Agent Identity aimed squarely at governing the fast-multiplying population of software agents acting on behalf of employees.
As SecurityBrief Australia reported, the offering is designed to give organisations a way to see, authenticate and control the AI agents operating inside their systems, treating each one as an identity that needs to be managed rather than an anonymous process quietly reaching into sensitive data.
Why agent identity has become a problem
For most of the past two decades, corporate security has been built around two categories of identity: human users, who log in with credentials and multi-factor prompts, and machine identities such as service accounts and API keys. Agentic AI blurs that neat division. An AI agent is not a person, but nor is it a static piece of infrastructure. It reasons, chains together tasks, calls other tools and can act with a degree of autonomy that a traditional service account never had. It might read a customer record, draft an email, trigger a payment workflow and query a database in a single sequence, often using the permissions of whichever human set it running.
That creates a governance headache. If an agent inherits a broad set of employee privileges, a single compromised or poorly scoped agent can become a fast route into data it was never meant to touch. Security teams have taken to describing this as the rise of non-human identities, and analysts have been warning for months that these identities now vastly outnumber human ones inside large organisations. Rubrik’s pitch with Agent Identity is that companies cannot secure what they cannot see, and that agents need their own identities, their own access boundaries and their own audit trail.
The company has been repositioning itself from a backup and recovery specialist into a broader cyber resilience and data security player, a shift chief executive Bipul Sinha has pushed since the firm’s 2024 float. Agent Identity extends that story into the agentic era, tying the control of AI agents back to the data those agents can reach.
Two ways of reading the launch
Supporters of this approach argue that identity is the only sensible place to draw the line. Network perimeters have largely dissolved, and in a world where an agent can be spun up in minutes, controlling who and what an agent is, and what it is allowed to do, is more durable than trying to police every connection. On that view, extending established identity and access principles to AI agents is a logical and overdue step, and vendors moving early are simply meeting demand that boards are already feeling.
Sceptics counter that a flurry of new agent-security products risks adding complexity rather than removing it. Many enterprises already run a tangle of identity providers, privileged access tools and data governance platforms, and bolting on yet another layer specifically for AI agents could deepen the sprawl. There is also a live debate about whether agent controls belong in a dedicated product or should be built into the identity platforms companies already own. Critics of the standalone approach worry that buyers will end up managing human identity in one place and machine identity in several others, which is precisely the fragmentation that lets risky agents slip through the cracks.
Both camps agree on the underlying problem. The question is architecture, and that debate is far from settled.
What it means for Australia
The timing is awkward, in the useful sense, for Australian organisations. Agentic AI has moved from pilot to production remarkably quickly here. Westpac has publicly talked up AI agents in its investor cost-savings plans, National Australia Bank has been testing safeguards around banking agents, and agentic tools are being rolled into retail, logistics and property operations across the country. Every one of those deployments creates exactly the kind of non-human identity that Agent Identity is built to corral.
Australia’s regulatory environment sharpens the stakes. Under the Privacy Act and the Notifiable Data Breaches scheme, an AI agent that reaches data it should not, or that is hijacked to exfiltrate records, is not a technical curiosity but a reportable incident with legal and reputational consequences. The Australian Prudential Regulation Authority’s CPS 234 information security standard already obliges banks, insurers and superannuation funds to maintain tight control over who and what can access their systems, and prudential regulators have made clear they expect that discipline to extend to new technology rather than lapse around it. An unmanaged fleet of autonomous agents sits uncomfortably against those obligations.
There is a sovereignty angle too. Much of the agentic tooling Australian firms are adopting is built offshore, and questions about where agent activity is logged, where identity data is stored and who can inspect it will matter to sectors handling health records, financial data and critical infrastructure. Australian security leaders weighing products like Rubrik’s will be asking not only whether the controls work, but where the resulting telemetry lives.
What’s next
The immediate test is adoption. Agent identity is a crowded and rapidly forming category, with established identity giants, cloud platforms and a wave of startups all staking claims, so buyers will be watching for interoperability with the identity and data stacks they already run rather than a rip-and-replace. Expect Australian chief information security officers to trial these controls quietly before committing, and to press vendors on how agent identities are provisioned, revoked and audited at scale.
The broader trajectory is clearer. As agents take on more consequential work, the governance conversation will shift from whether to control them to how tightly, and Australian regulators are likely to take a keener interest as incidents inevitably surface. For now, Rubrik’s launch is a marker of where enterprise security is heading: toward a world where the thing logging in might not be a person at all, and where knowing exactly what your AI agents are allowed to do becomes as fundamental as knowing your own staff.
Sources: SecurityBrief Australia.


















































