These ‘workload identities’ typically receive far less governance, often because they sit inside an application or project and become someone else’s technical dependency once implementation is complete. AI agents fall squarely into this workload identity population, but they introduce a design consideration that fixed automation does not. Microsoft describes workload identities as machine identities used by applications and services, noting that they cannot perform MFA, often lack a formal lifecycle, and may depend on stored credentials. “The OpenAI incident shows the consequences when capability, connectivity and authority combine in ways the architecture did not anticipate,” Blank concludes. “Workload identity governance keeps that authority limited, understood and accountable as agents become part of ordinary business systems.”