Continuous identity becomes the new front line for AI agents: theCUBE’s Fal.Con 2026 day two keynote analysis
Identity security has always worked the same way: log in once, get trusted until you log out. That model breaks down the moment an AI agent does the logging in, since an agent can call a dozen tools in the time it takes a human to read one email. The industry’s fix is continuous AI agent identity: authorizing every action an agent takes in real time, not just at the start of a session.
CrowdStrike Holdings Inc. built part of its Fal.Con 2026 keynote lineup in Las Vegas around that shift, with President Michael Sentonas detailing how the Falcon platform now handles identity. Krista Case (pictured, left), principal analyst and practice lead for cyber resilience and security at theCUBE Research, said the resulting capability was one of the announcements that stood out most to her on day two.
“It’s looking at continuous authorization, having that continuous approach, as AI agents are continuously accessing data and taking actions,” Case said. “CrowdStrike is scoping access to specific tasks with short-lived authorization that can be revoked when the task ends.”
Case was joined by fellow analysts Dave Vellante (right) and Rebecca Knight (center), for a day two keynote analysis of Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed CrowdStrike’s push toward continuous AI agent identity and what an agentic SOC will require.








