The National Institute of Standards and Technology’s National Cybersecurity Center of Excellence (NCCoE) is examining how existing identity standards and practices can be applied to software and AI agents. Early this year, the center published a draft concept paper on software and AI agent identity and authorization. Unlike a conventional application or service account, an AI agent may independently choose among tools, retrieve records, generate content, deploy code, or initiate transactions. Agentic AI can amplify identity sprawlFor agencies, agentic AI is not a separate security problem. The same problem can apply to an AI agent whose initial access was approved but whose role, integrations, or capabilities have since expanded.