Identity-first security in the age of AI agents requires that CISOs own IAM. IAM is vital for securely enabling and scaling AI agent automation while guarding against profound risks agentic AI introduces for enterprise IT environments. CISOs need to enforce accountability, exert influence on controls and securely scale agentic AI. IAM teams need to align with cybersecurity and bring the culture of business enablement to cybersecurity teams that have the reputation of being the office of no.