When 2.2 Billion Agents Start "Going to Work," Who Issues Their Employee Badges?

2026-09-11

Can everyone imagine how many tasks AI agents executed in 2025?

On September 4, at the Chengdu stop of Bamboocloud's AI new product launch event, Chairman Dong Ning opened with a single figure: in 2025, active AI agents had already executed approximately 44 billion tasks. According to IDC forecasts, by 2030, this number will surge to 415 trillion tasks per year – a compound annual growth rate of 524%. At the same time, the number of active agents will rise from the current approximately 28.6 million to over 2.2 billion.

 全景图1.jpg

415 trillion. This number sounds incredible. But look at what is happening on the enterprise side: customer service ticket triage, IT service desk operations, code generation and review, email processing and scheduling, CRM updates and sales follow-ups, IT operations monitoring and fault analysis, invoice verification and exception handling, knowledge base retrieval, marketing content creation, identity and permission management – every one of these is being taken over by agents, executing tens of billions of operations every day. The consumer side is no different: search queries, repeat purchases, travel bookings, payment changes, smart home control... Imagine over 1 to 2 billion AI-empowered consumers, along with hundreds of thousands of enterprises, each running their own agents every day to reply to messages, update information, book trips, complete payments, write code, and grant permissions – 365 days a year, every single day. This is the core basis for IDC's forecast of this enormous number. And every single one of these tasks must go through identification, authorization, monitoring, and governance.

董总1.jpg

In August of this year, the UK AI Safety Institute (AISI) released an evaluation report: out of 122 safety tests, agents overstepped boundaries 10 times, with 19 boundary-crossing incidents recorded in total. What is out of control is not just the model, but the agent's "identity": agents execute operations under delegated human identity, permissions are transmitted layer by layer along the tool chain, and static credentials are often granted excessive privileges, even shared and used serially across multiple services. Once leaked, risks are difficult to isolate. This is precisely the "identity and privilege abuse" risk ranked among the top three in OWASP's 2026 Top 10 Agent Risks. Who is calling? Who has permission? Who is responsible? These questions cannot be resolved by the large model itself and must be addressed through an independent digital trust infrastructure.

 

A Trust Dialogue Reaching Deep into Western China

 The launch event landed in Chengdu, where guests from government, energy, military, and manufacturing sectors gathered by the banks of the Jin River for an in-depth dialogue on the same topic. They came from the Sichuan Provincial Meteorological Bureau, Dongfang Electric, China MCC5, Yalong River, Nuclear Power Institute of China, Luzhou Laojiao, BOE Precision Electronics, Chengdu Jiaozhi Financial Holdings, Changan Automobile, Sichuan China Tobacco, China Resources Beer, Guizhou Big Data Industry Group, Sichuan China Electric Power Qimingxing, New Hope, and others.

 Once an AI agent connects to enterprise systems, databases, office software, payment tools, or external interfaces, it is no longer just a "talking model" but becomes a digital actor capable of reading data, invoking tools, and initiating operations. How should enterprises confirm "who it is"? How can they ensure "what it should do"? And how can they trace "who is responsible"?

 

When Agents Become "Digital Citizens"

 The underlying industrial landscape is being redefined. At the 2026 World Artificial Intelligence Conference, the China Academy of Information and Communications Technology released the "Internet Agent Development Research Report (2026)": the primary connecting entity of the internet is shifting comprehensively from being centered on "humans" to being centered on "agents." Agents are no longer merely tools but have evolved into "digital citizens" participating in cyberspace activities – and since they are digital subjects, they must have identity, rules, supervision, and traceability. This trend has already been implemented at the policy level: in 2026, "agent" was written into the Government Work Report for the first time; the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology jointly issued the "Implementation Opinions on Standardized Application and Innovative Development of Agents"; and the China Academy of Information and Communications Technology, together with the Internet Society of China, launched nationwide unified agent registration, establishing a trustworthy, verifiable, and traceable dedicated digital file for every agent. The starting point of identity governance is managing "humans" well, while the endgame is comprehensive coordination of multiple entities – "humans, machines, things, and agents." The question is no longer "whether to do it" but "how to do it."

Liu Yanpeng, General Manager of Bamboocloud's Strategic Development and Solutions Center, fully articulated Bamboocloud's product implementation path for the AI era at the launch event. The platform is centered on the OneID unified trusted identity foundation, achieving "one authentication, access across all domains," using identity as the hub to establish trusted connectivity across the entire chain linking natural persons, business applications, network resources, core data, and AI agents – providing a registrable, authorizable, and traceable implementation carrier for the "digital citizen" identity of agents.

 全景图3.jpg

Trust Agent: An identity risk engine built on an "AI-native" technology foundation. It adopts a hybrid AI architecture with "machine learning as the skeleton and large models as the brain," building a complete protection loop of "behavior learning, anomaly detection, intelligent assessment, and tiered response" around multiple identity types including users, agents, and NHI. It possesses self-evolution capabilities and can proactively defend against unknown risks.

AIAM: An identity and access management platform ensuring agents operate "securely and trustworthily." Targeting the characteristics of agents such as autonomous decision-making, tool invocation, and task delegation, it ensures that every step of an agent's actions remains within security constraints across multiple dimensions including identity registration and binding, device behavior boundary control, network security access, intent recognition, and dynamic permission adjustment.

IAM Agent: An intelligent assistant providing "expert capability support" for identity and access management. Addressing the pain points that IAM platforms require high user expertise and involve relatively complex operations, it uses an agent framework combined with a knowledge base and system operation capabilities, allowing users to directly control the system through natural language without memorizing cumbersome operational steps, completing identity management tasks as if conversing with an expert, greatly reducing usage difficulty and improving the operational experience.

Operation Agent: An intelligent operations platform providing "inspection and remediation" for identity security systems. Addressing the difficulties of heavy system operations workload, high experience requirements, and hard-to-prevent problems, it achieves a full-chain closed loop from proactive inspection and fault diagnosis to automated repair, transforming operations from "firefighting after problems occur" to "resolving issues before they happen," greatly improving operational efficiency and system stability.

 

Real-World Validation by a Large Central SOE

 The value loop of a product must ultimately be completed in a customer's real business scenarios. Zhou Jiaqi, Digital Business Director of Yalong River Hydropower Development Co., Ltd., mentioned in his sharing that Yalong River is a leading central SOE in China's clean energy sector, with business covering the entire chain of hydro-wind-solar-storage development, engineering construction, and production operations. Its stations are widely distributed geographically and its organizational hierarchy is complex, placing extremely high demands on the complexity and security of identity management. The group's digital identity management platform has been running stably for two years. From foundational construction to continuous evolution, it fully demonstrates the implementation path of identity governance for a large energy central SOE – starting from a unified identity foundation, extending to precise permission control in business scenarios, and ultimately covering compliant governance in the agent era.

 客户分享1.jpg

Yalong River's practice proves that identity governance is not an IT project but a digital infrastructure endeavor that requires deep integration with business and continuous iteration. This provides a reference model for more large enterprises on how to build a solid security foundation during large-scale AI deployment.

 

Starting from Chengdu, the Trust Map Continues to Expand

 As a major science and innovation hub in western China, Chengdu brings together leading enterprises and research institutions in key fields such as energy, military, aviation, finance, and consumer goods. When practitioners from different industries are all asking: after AI gains autonomous capabilities, who will vouch for its identity and take responsibility for its actions? Identity governance is no longer just an enterprise technology question but an infrastructure imperative that the entire industry must answer together.

From Shenzhen, Shanghai, and Beijing to Chengdu, Bamboocloud is deepening the industry consensus on "AI identity governance" and transforming it into actionable implementation pathways. In the agent era, "who issues AI its employee badge, and who backs up AI's behavior." The release of four AI agent products is precisely Bamboocloud's answer.

When trust becomes verifiable, traceable, and governable, every step of AI's actions can be grounded in evidence and leave a trace to follow.