NEW YORK and LONDON, Sept. 09, 2026 (GLOBE NEWSWIRE) -- Orchid Security, the company that unlocks safe AI adoption by solving identity at its core, today announced identity drift detection and application-level kill switches for AI agents. AI agents can complete authorized objectives beyond their initial privilege level within seconds. AI agents do not need to “break” security controls or workflow guardrails. They can find and use the identity debt already embedded across the enterprise: hard-coded credentials, orphaned accounts, unmanaged authentication paths and excessive permissions. The new AI readiness controls help enterprises scale AI adoption without losing control.
AI Adoption Is Now a Board Mandate
Boards have moved from asking whether their companies should adopt AI to asking how quickly they can scale it. Resisting is no longer a viable security posture. What enterprises need is a defensible plan that enables adoption while keeping autonomous agents inside authorized boundaries.
"AI transformation is exciting. Identity hygiene is not," said Roy Katmor, co-founder and CEO of Orchid Security. "Boards are no longer asking whether AI will be adopted—they are asking why it is not moving faster, and security cannot answer with a blanket 'no.' Enterprises need to observe how agents act, understand when they drift, and govern them immediately, including terminating the authority through which they operate."
The obstacle is not agent behavior. It is what agents inherit. Agents do not need to break security controls to exceed their intended scope—they find and use the identity debt already embedded across the enterprise: hard-coded credentials, orphaned accounts, unmanaged authentication paths, and excessive permissions. Orchid's Identity Gap 2026 found that 57% of enterprise identity is unseen and unmanaged. Agents can turn that identity dark matter into an active path to elevated access in seconds to minutes—far faster than periodic governance reviews can detect or contain it.
An Operational Framework For Agent Adoption: Observe→ Understand→ Govern→ Prove
Orchid enables continuous, auditable AI-Readiness and defensibility:
What Enterprises Should Be Able To Demonstrate
Before autonomous agents are deployed at scale:
Regulators are converging on the same requirements. NIST's draft Cyber AI Profile notes that “regardless of where organizations are on their AI journey, their cybersecurity programs need risk management approaches that support and integrate the realities of advancements in AI.” In Europe, DORA obliges financial entities to demonstrate control over ICT access and third-party dependencies, an obligation that does not pause because the entity acting is an agent rather than a person.
Availability
Following the recent agentic enhancements to Orchid's Identity Control Plane in May, the capabilities below are now available:
Orchid has also expanded its integration ecosystem:

Shannon Wilkinson, CIO and CISO at Findlay Automotive Group, described the tension from the practitioner's seat: “The challenge is how to enable the business to move faster and realize the productivity that AI agents bring, but it honestly terrifies a lot of us. At Findlay we're leaning heavily into AI to build a better customer experience. At the same time we must define guidelines, put guardrails in place and, above all, know what the identities are doing.”
Enterprises have ignored identity dark matter in general, and poor identity hygiene specifically, for a long time now- which is one of the reasons that threat actors are more likely to log in than hack in today. But exposing AI agents to all the identity clutter that has accumulated over time is a recipe for disaster.
To learn more about Orchid Security’s approach to securing autonomous identities or request a demo, visit https://www.orchid.security/use-case/guardrails-for-autonomous-identity.
Gartner Security & Risk Management Summit, London 2026
Orchid Security will be at the Gartner Security & Risk Management Summit at ExCeL London, September 22-24. The team will be onsite to discuss AI readiness and identity dark matter with security and risk leaders. Stop by Booth #105 for a live walkthrough of the platform, or schedule a meeting in advance through the form to guarantee time with our team.
About Orchid Security
Orchid Security sees straight into the application binary to deliver the industry’s first Identity Control Plane, transforming IAM complexity into clarity, compliance, and control. Its Identity-First Security Orchestration platform continuously discovers enterprise applications, analyzes their native authentication and authorization flows, and accelerates onboarding into governance systems, putting true identity insight in front of security leaders and practitioners, without the months of manual work traditionally required for each task or informational ask. By exposing and remediating the ‘identity dark matter’ hidden across modern environments, Orchid helps enterprises solve identity at its core; reducing risk, lowering operational costs, and achieving compliance at scale.
Media Contact
Chloe Amante
camante@montner.com
Montner Tech PR
A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/4c9d25ca-3bff-4595-b77a-4ce41608c9b2