
This summer has seen us in interesting times. Agent harnesses and their capabilities have been at the forefront of the industry’s consciousness, and you could see it across the sheer number of talks on it. Much discussion has been around the nature of frontier models, their potential impacts on productivity when used in conjunction with appropriate harnesses, and the need to inject identity-related conventions into the enterprise.
There are plenty of meaningful solutions being worked on to help prevent errant agents in the enterprise, as well. For instance, we are seeing the creation of standards (Such as IETF draft on OAuth Client ID Metadata Documents or the IETF draft on Identity Assertion JWT Authorization Grants), best practices (Such as the AIMS draft that Jeff Lombardo wrote about recently), and articles abound providing a path forward. These are powerful, meaningful works. However, we are left with gaps that cannot be resolved with these solutions alone- securing the path of known agent to enterprise resource does not end the fight.
What do I mean, here? Specifically, I am talking about the increasing prevalence of capable, locally-ran generative models. Coupled with abliteration- Abliteration being a process that uncensors generative models by removing the model’s ability to refuse requests by various means- these local models (Called abliterated models or “Heretic models” after Heretic, a tool that performs the work) have no compunctions to perform actions on behalf of the user, any action. These local models will potentially be given credentials from users to perform actions. This could range from the mundane to the momentous. One can quickly imagine a scenario where a business user offers such a model the credentials to their CRM to create dynamic reports for them, or access to a corporate git repo to help write code or develop gating around a build process. One can likewise imagine a scenario where a user utilizes a local abliterated model to perform actions as an insider threat to the organization.
Research1 has been performed and presented2 in this field. With local, open-weight models becoming increasingly capable and the ease3 by which these local models are having their rejection mechanisms stripped, this means these models can perform tasks that would otherwise be rejected by a frontier model in a manner that while is not at the forefront of capability, is sufficient in many cases to get done what the user is looking to get done. I will not editorialize the ethics of abliteration or the usage of abliterated models (As has been done recently across the United States’ legislative branch4), but I will note that any grandstanding about whether or not they should exist at this point is moot- the tools and techniques exist, and they are at our door. As a matter of practicality, your humble offer has engaged with local models inside of Capture the Flag (CTF) environments (With permission!) and has found them impressively effective in performing tasks sufficient to perform at the top end of these CTFs; the capabilities of these models are impressive, and I can see a point not even a few years from now (It’s already happening!) where local models are used in conjunction with frontier models to maximize cost efficiency while maintaining quality in a wide range of tasks.
You may be thinking “Models that could harm us take huge resources to run”, and that is not necessarily true. Laptops already in the enterprise, such as the humble Macbook Pro, can run local models with impressive performance. x86-based architectures are moving towards this as well, because the market has a demand for AI- there are already compact desktops that can perform this work with some degree of prowess, and it stands to reason chipmakers will look to rise to this demand further. An astute reader may think “This is a whitelisting problem at runtime, not an identity problem”, and I would offer you are partly right. While there are means by which to determine if something we don’t want running is running, life finds a way. Even still, in the era of BYOD organizations cannot stop every new tool that comes out that can act as an inference server, or act as an agent harness. We’re left what I reluctantly call “Shadow agents”, in the way shadow IT is manifested- it’s a bad term, but the intent is to make it clear the agents performing actions on behalf of users are not vetted by the organization or necessarily approved.
So what do we do as practitioners of identity to help mitigate this risk in the enterprise? We fall back to fundamentals. The machine acting on behalf of the user still has to come to a remote service, still has to present credentials, and still has to send requests to the remote system. We can determine when the user logs in, how they move in the system, and the speed at which they perform operations. Agents categorically do not act like users- which means we can determine if a user is potentially letting a machine act on their behalf, shut down the session, and communicate the concern to the rest of the enterprise. And while a sufficiently devious agent acting on behalf of a user may seek to emulate the user, we have a historical understanding of how a user (Not just this user) may move through the system and what actions they may take in what order. This is powerful information, and signaling inside of a robust continuous authentication process that can help us differentiate.
It’s fair to have concern over the changing nature of how we interact with systems. Systems are moving faster, in non-deterministic ways, and in ways that may not necessarily be beneficial on any given action. It is not fair, however, for the marketing hype to pretend we are entirely defenseless in this brave new world. The defenses of the past may no longer tell the whole story, but they still tell a story- sufficiently robust authentication and authorization, as far down in the stack as possible, allow us a great deal of mitigation against the risk of an errant agent.
References
1: https://go.alice.io/hubfs/alice-abliteration-report-april2026.pdf
2: https://www.unomaha.edu/ncite/news/2026/09/dc-demo-day2.php
4: https://www.yahoo.com/news/articles/lawmakers-shown-jailbroken-ai-plan-223247817.html

Rusty Deaton has been in Identity and Access Management for over a decade. He began in technology as a technical support engineer for a Broker-Dealer and has since worked across many industries, carrying forward a passion for doing right by people. When not solving problems, he loves to tinker with electronics and read. He currently works as Federal Principal Architect for Radiant Logic.





