The Velocity Paradox: Security Can't Keep Up with AI
A SailPoint report reveals that companies are deploying autonomous agents while maintaining security controls from another era. We analyze the impact on SMBs.

Companies have entered a race to adopt autonomous AI agents that promise to accelerate business. However, a recent SailPoint report, titled Horizons of Identity Security, hits the nail on the head: most still rely on security architectures designed for another era. This is what the report calls the velocity paradox: investing in operations at AI speed, but maintaining security controls at human speed. The result is a gap that keeps growing.
For an SMB or a small IT team, this paradox is not an abstraction. When an AI agent is deployed to automate tasks, that agent needs credentials, access, and permissions. If identity management remains anchored in manual processes, the agent inherits privileges that no one reviews as often as necessary. And that's where the problem begins.
What it means for an SMB
The SailPoint report points out that organizations are trapped in this contradiction: business at full speed, security at human pace. In practice, this translates into three fronts that any IT team should monitor:
- Uncontrolled non-human identities. AI agents operate with service accounts, tokens, and API keys. If they are not managed as full-fledged identities, they become permanent backdoors.
- Excessive permissions. It is common to give the agent more access than necessary so that it "doesn't fail." This expands the blast radius if something is compromised.
- Insufficient manual review. Access controls are reviewed quarterly or annually, but agents change behavior in a matter of days.
The paradox is not only technical, it is about governance. If AI makes operational decisions at high speed, security must be able to respond at that same speed. And today, that doesn't happen in most SMBs.
Practical recommendations for the IT team
You don't need to wait to have a mature SOC to start closing the gap. These are the measures we recommend at ForgeNEX, adapted for small teams:
- Inventory non-human identities. Before deploying an agent, document which accounts it will use, with what permissions, and who is responsible. If it's not in the inventory, it shouldn't be in production.
- Apply the principle of least privilege. Start with read-only permissions and expand as needed based on demonstrated need. Review those permissions every time the agent changes tasks.
- Automate access reviews. If AI operates daily, its credential review cannot be annual. Schedule periodic checks and alerts for unexpected changes.
- Separate environments. A test agent should not have access to production data. It seems obvious, but it's one of the most repeated mistakes.
- Define a revocation plan. What happens if the agent behaves anomalously? There must be a clear procedure to deactivate it without breaking the business.
This approach connects directly with what we already discussed in The AI agent inherits your credentials: the risk is not in AI itself, but in how we give it access. And also with AI in the SOC: how much autonomy to cede without losing control?, where we already raised that autonomy without supervision is a time bomb.
The cost of not acting
The velocity paradox is not solved by buying one more tool. It is solved by changing the way we manage identities and access. If your company is deploying AI agents to gain efficiency, but keeps identity management in spreadsheets and annual reviews, the risk grows faster than the benefit.
At ForgeNEX we see many SMBs that have made the leap to AI without updating their security model. It's not about slowing adoption, but about accompanying it with proportionate controls. Business speed should never be an excuse to leave security behind. After all, a compromised agent can do more damage in a minute than a distracted employee in a month.
Security cannot continue to be the handbrake of AI; it must be the seatbelt that allows acceleration without going off the road.
Source: The Hacker News. Analysis and adaptation: ForgeNEX.