- The funding that signals a paradigm shift
- How identity management works for AI agents
- The context: AI agents are becoming an operational workforce
- Concrete impact on Italian SMEs
- What has changed compared to six months ago
- A Milanese agency's view on the Italian market
- What to do now: three operational priorities
- Perspectives: the IAM market reinvents itself around agents
NewCore is a startup that just closed a $66 million funding round. Its goal is clear: to provide verifiable digital identities for AI agents operating within organizations. Until now, identity management exclusively concerned humans. Now, however, the scope is expanding significantly.
In fact, AI agents are taking on real operational roles: they access systems, execute transactions, and communicate with other software. Therefore, the security question shifts — it's no longer enough to know who the human user is, but you need to know which agent is acting, with what permissions, and in what context. This is exactly the problem NewCore aims to solve. We at SHM Studio we're keeping a close eye on this shift, because the impact on Italian SMEs jumping into artificial intelligence tools is very real and immediate.
Bottom line: identity management for AI agents isn't sci-fi anymore. It's an operational must-have that companies — even mid-sized ones — need to tackle right now, before the tangled mess of AI stacks makes governance impossible to fix later. SHM Studio accompanies SMEs on this journey of conscious AI adoption.
The funding that signals a paradigm shift
June 15, 2026, TechCrunch has reported the news of NewCore's launch with a $66 million round. The startup is positioning itself in a specific segment: managing the digital identities of AI agents in an enterprise context. This isn't a niche topic. On the contrary, it's a sign of a structural transition in how organizations think about cybersecurity.
Until recently, Identity and Access Management (IAM) systems were designed around the human user. Every employee had credentials, roles, and permissions. Therefore, the attack surface was relatively predictable. Today, however, AI agents are multiplying within enterprise stacks. They perform autonomous tasks, access databases, invoke APIs, and generate outputs that influence real processes.
Therefore, the question NewCore raises is as simple as it is urgent: who guarantees that an AI agent is operating with the correct permissions, in the right context, without being compromised or manipulated?
How identity management works for AI agents
The technical issue is trickier than it seems. An AI agent is not a user. It doesn't log in with a password. Plus, it can be spun up multiple times in parallel, run asynchronously, and chat with other agents. So, traditional IAM models just don't fit out of the box.
NewCore introduces an architecture based on cryptographic identities assigned to agents. Each agent receives a sort of "digital ID card" that certifies its origin, purpose, and permissions. This way, company systems can verify in real time whether an agent is authorized to perform a specific action.
Similarly to what happens with SSL certificates for websites, the idea is to create a verifiable chain of trust. However, the complexity increases because agents can be created dynamically, can evolve over time, and can operate on multi-cloud infrastructures. This makes governance particularly challenging.
To dive deeper into the underlying technical architecture, it is helpful to consult Gartner's analyses on Agentic AI , which have been pointing out non-human identity management as a top security priority for 2026-2027 for months.
The context: AI agents are becoming an operational workforce
NewCore's thesis is not isolated. In fact, the entire technological ecosystem is moving in the same direction. Platforms like Microsoft Copilot, Salesforce Agentforce, and a series of vertical tools are bringing AI agents into daily business processes. Not as passive assistants, but as operational players.
Consequently, companies find themselves managing a hybrid workforce: human employees and software agents collaborating on the same workflows. This hybridization creates new vulnerabilities. A compromised agent can exfiltrate data, manipulate processes, or act outside its mandate without any traditional control system detecting it.
According to McKinsey's latest State of AI Report , over 60% of large enterprises have already rolled out at least one AI agent in production. Among SMBs, that number is lower, but climbing fast. So, agent governance isn't just a big-corp problem.
Concrete impact on Italian SMEs
Italian small and medium-sized businesses are jumping on AI tools faster and faster. Customer service chatbots, order-taking agents, marketing automations. But let's be real, these rollouts rarely come with any serious security game plan.
The main risk isn't necessarily an outside attack. Often, it's more subtle: a misconfigured agent that gets into sensitive data, an automated task that runs unauthorized operations, a system acting on vague instructions with no checks in place. Small and medium businesses with limited IT resources are especially at risk because they don't have the safeguards that big companies already set up.
We at SHM Studio we see this dynamic firsthand when working with our clients. When we help an SME adopt AI tools — whether within our artificial intelligence services both in those of Digital marketing — agent governance is one of the key points we tackle right from the early stages. It's not just a technical detail to put off. It's a must-have for safe scaling.
What has changed compared to six months ago
Last year, talking about AI agent security felt mostly academic. Real-world hacks were super rare and barely documented. Fast forward to today, and the market has totally blown up. Meaning those risks went from 'what-if' to happening right now.
Three things helped drive this shift. First off, all the new frameworks for building agents—like LangChain, AutoGen, and CrewAI—made it way easier to get started. Then, enterprise platforms added built-in support for launching agents. And finally, the first security slip-ups involving badly configured agents started showing up in industry reports.
Consequently, the timing of NewCore's launch is no coincidence. The market is ready to recognize the problem. And investors have clearly decided that the solution is worth a 66 million dollar initial bet.
A Milanese agency’s view on the Italian market
From our Milanese viewpoint, we notice a certain gap between the speed at which Italian SMEs adopt AI tools and the speed at which they develop awareness of the associated risks. This is not a criticism. It's a structural observation: adoption always precedes governance, in every technological cycle.
However, the AI cycle is faster than previous ones. Therefore, the gap between deployment and control risks becoming problematic before companies have time to bridge it organically. For this reason, we believe that the topic of identity management for AI agents should enter the vocabulary of Italian SMEs today – not when the problem manifests.
The practical implications affect several areas. On the front of web and digital infrastructure , you need to know which agents have access to company systems. On the SEO and content , you need to track which agents generate or modify published content. On the paid campaigns and LinkedIn Ads , you need to check that automations act within authorized parameters.
What to do now: three operational priorities
There is no need to wait for solutions like NewCore to mature and become available on the Italian market to start structuring AI agent governance. There are concrete actions that SMEs can take starting today.
- Census of active agents: the top priority is knowing how many and which AI agents are running in the organization, what systems they touch, and what permissions they have. Often, this visibility is totally missing.
- Definition of action perimeters: every agent should have an explicit mandate. Therefore, you need to document what it can do, what it cannot do, and in what context it operates.
- Audit and logging mechanisms: agents must leave verifiable traces of their actions. This is not just a security requirement. It is also a condition for regulatory compliance, especially in view of the full implementation of the European AI Act.
To delve deeper into the regulatory framework, the official portal of the European Commission on the AI Act offers an up-to-date overview of the obligations that apply to AI systems in a business context.
Perspectives: the IAM market reinvents itself around agents
NewCore's round is likely the first of many. Much like what went down with cloud cybersecurity ten years back, we expect a dedicated non-human identity and access management sector to pop up over the next 18-24 months.
The implications for SMEs are twofold. On the one hand, solutions accessible even to organizations without large IT budgets will open up. On the other hand, regulatory pressure and that of commercial partners will push towards minimum governance standards for AI agents. Therefore, companies that start structuring themselves today will have a measurable competitive advantage.
In SHM Studio we will keep following this trend closely. If anyone wants to dive deeper into how to bake AI agent governance into their digital strategy, they can contact us directly . Also, our Blog it gathers updated analyses on AI, security, and digital transformation for Italian SMEs. For anyone considering how to structure their digital content to be AI-ready, our SEO copywriting services offer a concrete starting point.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.