TL;DR: A single innocent request can enable agentic AI to merge multiple authenticated contexts into one operational identity, allowing cross-system lateral movement, data exfiltration, phishing, or malware distribution, according to Lasso Security's IdentityMesh research. The finding makes clear that existing MCP and browser-based controls assume boundaries the agent does not preserve.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “IdentityMesh: Exploiting Lateral Movement in Agentic Systems”.
Key questions
Q: What breaks when an agent can combine multiple authenticated contexts into one workflow?
A: The boundary between systems breaks down.
Q: Why do cross-system agent workflows create lateral movement risk?
A: Because read access in one system can feed write actions in another without a fresh trust decision.
Q: How can teams tell whether agentic access controls are actually working?
A: Look for evidence that every privileged action is logged with actor type, target resource, and policy decision, and that denied requests are being blocked before execution.
Practitioner guidance
- Disable persistent approval modes Remove allow-always and YOLO-style settings from agent deployments so each cross-system action requires explicit review.
- Separate read and write privileges by system Do not let the same agent session both collect sensitive data from one system and write to a different system without a fresh authorization boundary.
- Restrict cross-origin browser agent behaviour Treat browser-integrated agents as a distinct control surface and limit their ability to move between authenticated web applications under one session.
Bottom line: IdentityMesh shows that agentic systems can collapse multiple authenticated contexts into one operational identity, creating a lateral movement path across otherwise separate services.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
IdentityMesh is not a tool failure, it is a boundary failure. The attack works because the agent treats separate authenticated systems as one operational identity, so the security boundary disappears at runtime. That means the control problem is not only permissions, but the assumption that permissions remain separable once the agent starts chaining read and write actions. Practitioners should treat cross-system identity fusion as a distinct governance problem, not a variant of ordinary access sprawl.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What is the difference between delegated access and identity fusion in agentic AI?
A: Delegated access is intended and bounded, with clear scope and separate control points. Identity fusion happens when an agent merges several credentials or sessions into one operational entity, so a request in one system can trigger unauthorised action in another without a fresh trust check.
👉 Read our full editorial: IdentityMesh shows how agentic systems collapse identity boundaries
IdentityMesh is not just a tool-integrity problem, it is a boundary-collapse problem. The research shows that agentic systems can merge authenticated contexts into one operational identity, which breaks the assumption that each system boundary is separately preserved. Once that assumption fails, traditional per-application authorization no longer describes the real risk surface. Practitioners should treat the agent session itself as the new boundary object.
A few things that frame the scale:
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations treat browser agents differently from backend MCP agents?
A: Yes. Browser agents inherit live authenticated sessions across sites, which means cross-origin movement can look like ordinary user behaviour even when the agent is bridging separate applications. That makes browser-based automation a distinct governance problem, not just another tool integration.
👉 Read our full editorial: IdentityMesh shows how agentic systems collapse identity boundaries