Every company spent the last decade locking down who its employees are. Almost none have done the same for the AI agents now acting on their behalf. Baselayer, a New York startup, just raised a $35 million Series A to build identity infrastructure specifically for AI agents, and that funding round is a signal that machine identity is quietly becoming the biggest unmanaged risk in enterprise software.
What is the Concept
AI agent identity management is the practice of issuing, verifying, and revoking credentials for autonomous software agents the same way companies manage logins for employees. An AI agent that can read a database, send an email, or execute a trade needs a verifiable identity, scoped permissions, and an audit trail, not a shared API key buried in an environment variable.
This differs from traditional identity and access management because agents are created, cloned, and retired far faster than human accounts, and a single agent might need to authenticate across a dozen internal tools in one workflow.
Why It Matters Now (2025-2026 Context)
Enterprises deployed AI agents into production faster than their security teams could inventory them. A 2025 survey pattern repeated across the industry: companies know how many employees they have, but almost none can say how many AI agents are running with standing access to customer data or financial systems. Baselayer's raise, led by investors betting on this exact gap, confirms venture capital sees non-human identity as the next mandatory line item in enterprise security budgets, not an optional add-on.
For CTOs and founders, this means the AI agent identity market is moving from theoretical to funded and productized within a single funding cycle, which shortens the window before it becomes a standard vendor requirement in enterprise procurement.
How AI Is Changing This
Traditional identity providers like Okta and Azure AD were built around the assumption that a human logs in once and acts predictably. AI agents break that assumption: they act continuously, spin up sub-agents, and chain permissions across systems in ways a human never would in a single session. The contrarian insight is that the biggest AI security failures in 2026 will not come from the model itself, they will come from an agent that was never supposed to have the access it used.
A useful mental model here is what we call the Non-Human Identity Stack: every AI agent needs an identity layer, a permissions layer, and an audit layer, stacked the same way human identity, role-based access, and logging are stacked today. Most companies currently have zero of the three for their agents.
Real-World Examples
Consider a mid-size SaaS company that deploys an AI agent to automatically process refunds under $100. Without scoped identity and permission boundaries, that same agent's credentials, if reused elsewhere in the codebase, could be exploited to approve refunds of any size or access unrelated customer records. This is exactly the failure mode Baselayer and similar vendors like Astrix Security have been funded to prevent, and it mirrors the access-sprawl problems that plagued API keys and service accounts before dedicated secrets management tools existed.
Practical Insights / Actions
Future Outlook
Expect AI agent identity management to follow the same trajectory as cloud security posture management: a niche category in 2025-2026 that becomes a compliance checkbox by 2028 as regulators and cyber insurers start asking specifically how companies govern autonomous agents. Startups like Baselayer that raise early and ship fast will likely become the reference vendors enterprises benchmark against once this becomes a standard RFP requirement.
Conclusion
Baselayer's $35 million round is less about one startup and more about an entire category of risk finally getting a name and a budget line. Founders and CTOs running AI agents in production should treat this as the moment to audit agent access before an incident does it for them. RP SoftTech helps growing companies map their AI agent footprint and build an automation roadmap that scales without creating an unmanaged identity risk.




