Identity security has always worked the same way: log in once, get trusted until you log out. That model breaks down the moment an AI agent does the logging in, since an agent can call a dozen tools in the time it takes a human to read one email. The industry’s fix is continuous AI agent identity: authorizing every action an agent takes in real time, not just at the start of a session.
CrowdStrike Holdings Inc. built part of its Fal.Con 2026 keynote lineup in Las Vegas around that shift, with President Michael Sentonas detailing how the Falcon platform now handles identity. Krista Case (pictured, left), principal analyst and practice lead for cyber resilience and security at theCUBE Research, said the resulting capability was one of the announcements that stood out most to her on day two.
“It’s looking at continuous authorization, having that continuous approach, as AI agents are continuously accessing data and taking actions,” Case said. “CrowdStrike is scoping access to specific tasks with short-lived authorization that can be revoked when the task ends.”
Case was joined by fellow analysts Dave Vellante (right) and Rebecca Knight (center), for a day two keynote analysis of Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed CrowdStrike’s push toward continuous AI agent identity and what an agentic SOC will require.
Why continuous AI agent identity can’t stop at login
The capability traces back to CrowdStrike’s acquisition of SGNL, a $740 million deal announced in January and productized in June as Continuous Identity for AI Agents. The system evaluates who owns an agent, who is calling it and its device’s risk posture before authorizing each action, applying the same real-time model to human and non-human identities alike.
“It’s not just about understanding their privileges and what they should have access to,” Case said. “It’s about understanding how their behavior evolves over time and having the right safeguards in place to prevent them from going off the rails, whether maliciously or just through drift.”
Nonhuman identities are multiplying fast: CrowdStrike researcher Adam Meyers told the same crowd that AI agents are now generating roughly 2.5 times more detections than humans do. CrowdStrike’s own threat research published this week found the average eCrime breakout time has fallen to 29 minutes, with the fastest intrusion clocked at 27 seconds.
“It’s not just about the speed of detection and response,” Case said. “It’s also the confidence: This is a true risk, we’re prioritizing it, and this is the right way to keep critical business services online.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of the Fal.Con event:





