Agent Identity Is the New Perimeter
Brazilian banks deployed AI agents before anyone wrote the security playbook. That's not a criticism — it's the same dynamic that made Brazil the world's most inventive fintech market. Speed creates exposure; exposure creates opportunity.
The data from 2026 makes the exposure concrete. Kiteworks' 2026 cybersecurity survey found that 65% of companies experienced AI agent security incidents this year. More telling: organizations that enforced least-privilege access for their agents — a practice where each agent receives only the minimum system permissions its task requires, nothing more, with no accumulation over time — reported a 17% breach incident rate. Those without it: 76%, according to Teleport's 2026 AI security research. That 59-percentage-point gap is not a technology problem. It is a design philosophy problem.
Here is how the credential problem compounds. Most enterprises granted their AI agents the same kind of broad, persistent access they once gave human system administrators. The agents accumulated permissions as tasks expanded; those permissions were rarely revoked. When an agent's assigned scope grows to include read/write access to credit decisioning systems, loan origination data, or payment rails, a single compromised credential becomes worth far more to an attacker than a stolen human login.
The scale of what's coming clarifies the stakes. Gartner estimates that by 2028, the average Fortune 500 company will run more than 150,000 AI agents. Today, only 13% of organizations say they have adequate governance in place to manage that population. The SAP LeanIX Agentic AI Survey 2026 found that less than half of companies maintain a current inventory of the agents they've deployed. You cannot protect what you haven't catalogued.
Brazil's financial sector is where this tension runs highest, for structural reasons. The country's largest banks rebuilt core credit and compliance workflows around agentic AI at a pace that outstripped European and North American peers. That depth of adoption creates an asymmetric surface: the more an agent fleet is woven into financial operations, the more consequential a governance gap becomes. Breadth of deployment without breadth of credential control is a risk that grows nonlinearly.
This is where the investment thesis lives. Agent-native identity and access management (IAM) — the practice of managing which software systems can access what data and take what actions — is an established field when designed for human users. It is early and underfunded when designed for autonomous AI agents that change tools dynamically, operate across multiple services simultaneously, and hold credentials that are never challenged by a multi-factor authentication prompt. Standard human-user IAM assumes a stable role with predictable behavior. AI agents don't work that way.
The Banco Central's record on financial infrastructure — Pix, Open Finance, the emerging Drex architecture — is one of proactive structural investment before problems become crises. The question is which companies build the native security layer for agent populations in financial services, and whether those builders come from a market that already understands both the regulatory expectations and the operational complexity at scale.
The window between broad deployment and comprehensive governance is, historically, where the most durable infrastructure bets get made. That window is open now.
| Metric | Value |
|---|---|
| Firms with AI agent security incidents (2026) | 65% |
| Breach rate — with least-privilege access | 17% |
| Breach rate — without least-privilege access | 76% |
| Projected Fortune 500 agent count by 2028 | 150,000+ |
| Organizations with adequate agent governance (2026) | 13% |
Frequently asked questions
What is agent sprawl and why does it create security risk?
Agent sprawl occurs when a company deploys AI agents faster than it can track and govern them. Because agents accumulate permissions over time and those permissions rarely get revoked, the attack surface — the total set of access points an attacker could exploit — grows with every agent added. Most enterprises have no current inventory of which agents are running or what each one can access.
How do AI agent breaches differ from traditional data breaches?
Traditional breaches usually involve stolen human credentials or software vulnerabilities. Agent breaches occur when an autonomous system, already granted broad access to business data, is manipulated through prompt injection — a technique where malicious instructions are hidden in data the agent processes — or has its API credentials stolen. The agent's legitimate access makes the breach harder to detect and the damage faster to compound.
Why are Brazilian financial institutions particularly exposed to agent security risks?
Brazil's banks rebuilt core credit and compliance workflows around AI agents at a pace that outstripped most global peers. The deeper agents are embedded in financial operations — credit decisions, payment authorization, compliance review — the more sensitive the credentials each agent holds, and the more consequential any single compromise becomes.