IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Ping Identity launches controls for personal AI agents

Ping Identity launches controls for personal AI agents

Wed, 2nd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Ping Identity has launched Enterprise Personal Agent Access, aimed at companies using personal AI agents such as Claude in workplace systems.

Available through PingOne Privilege, the offering is already being piloted with global enterprise customers. It is designed to identify personal AI agents in supported environments, link their sessions to a user and device, and control what those agents can access and do.

The launch comes as businesses grapple with the spread of AI agents beyond centrally approved software. Employees and developers are increasingly using desktop assistants and coding agents in day-to-day work, sometimes with access to internal services, repositories, databases and cloud infrastructure.

That creates a security problem for organisations that built identity controls around human users rather than software agents acting on a person's behalf. Ping argues that these tools can move across systems at machine speed, making it harder for companies to track who initiated an action and whether it should have been allowed.

Research from Gravitee, cited by Ping, found that 48% of production AI agents are running unsecured. Against that backdrop, identity and cyber security suppliers are focusing more closely on how enterprises can discover agent use, restrict access and retain an audit trail.

Runtime controls

Ping said its system detects an AI agent when it is initiated in supported environments and associates the session with the person and device behind it. It then applies policy enforcement in front of managed resources to decide whether actions should be allowed, denied or logged, whether a sensitive task should require human approval, or whether access should be revoked in real time.

The approach extends beyond AI applications themselves. Personal AI agents may connect to MCP servers, code repositories, internal services and APIs, Kubernetes clusters, databases and cloud systems, potentially giving them access to some of the most sensitive parts of a company's technology estate.

For software development teams, Ping said the product allows agents to commit code and reach approved resources without storing long-lived credentials. It also records whether an action was taken by the developer or by the agent, giving security teams a clearer record of activity.

The launch also reflects a broader shift in enterprise software towards governing a mix of AI models and agent tools from different providers. Ping said its controls are intended to work across multiple agent environments, with Claude and Claude Code highlighted as supported examples.

Andre Durand outlined the company's view of the challenge facing large organisations as agent use broadens across departments and workflows.

"Enterprises are deploying a number of different AI models, agents and platforms," said Andre Durand, Founder and CEO, Ping Identity. "The security challenge is establishing a common way to see and govern all of them. The question isn't whether an agent is intelligent enough to act, but whether the enterprise can see and control its action when it does."

Growing concern

Security reviews have become a sticking point for many AI deployments, especially when an agent can take actions rather than simply generate text or recommendations. In those cases, companies need to know what agents are running, what systems they can reach, what permissions they hold, and whether responsibility for a mistake lies with the user or the software agent.

Identity management vendors have been adapting access controls, authentication and authorisation systems for this new layer of software activity. The aim is to preserve the accountability companies expect from human users while recognising that AI agents can execute tasks autonomously and at much greater speed.

Ping said Enterprise Personal Agent Access is part of that effort, with a focus on visibility from discovery through to enforcement at the moment an action is attempted. It also said it took part in Anthropic's Project Glasswing to evaluate advanced AI in the security and resilience of its own codebase and internal systems.

The latest product is likely to be watched closely by companies trying to balance AI adoption with internal controls, especially where personal AI agents are already appearing in developer workflows and on employee desktops before formal governance has caught up.

According to Ping, every recorded action can be attributed to the developer or the agent involved in the session, giving security teams a record of what the agent did, when it happened and the user associated with the session.