Session 1: The New NHI Risk Reality — When AI Agents Start Making Decisions | Non-Human & Agentic AI Identity Summit @ Identiverse 2026
Speakers: Shriram Santhanam, Chief Cyber Officer, Human Managed | Andrej Safundzic, Co-Founder & CEO, Lumos | Don D’Souza, Director of Cybersecurity, Fannie Mae | Ashay Raut, Principal Engineer, Amazon
In this session from the Non-Human & Agentic AI Identity Summit at Identiverse 2026, identity and cybersecurity leaders explore what happens when AI agents stop being a concept and start being an identity problem — one that existing governance frameworks, least privilege models, and ownership structures were never built to handle.
The panel opens by establishing why agentic AI represents a genuine shift in the NHI risk landscape, not just an extension of it. AI agents act autonomously, spawn sub-agents, make access decisions, and operate across environments without a human in the loop — and most organisations have no clear answer yet on how to identify, own, or govern them. The visibility gap that already exists for traditional NHIs becomes significantly harder to close when the identities themselves are dynamic and self-generating.
From there, the conversation gets into the specifics. The panel covers the three distinct types of AI agents and why each presents different identity and authorisation challenges. They examine why least privilege — already difficult to enforce at scale for traditional NHIs — becomes even more complex when agents need bounded context and dynamic permissions rather than static access rights. Accountability is a central theme throughout: when an AI agent makes a decision that causes harm, who owns that? How do you establish chain of custody across agent-to-agent interactions? What does logging even look like when the decision-making is autonomous?
The session draws heavily on real-world practitioner experience. Don D’Souza brings the regulated environment perspective — what identity governance looks like when you have compliance obligations on top of the technical complexity. Ashay Raut tackles the authorisation layer: the difference between pre-tool and post-tool authorisation, and why context-aware access decisions are becoming essential. Andrej Safundzic addresses the question of whether AI agent autonomy should be earned incrementally rather than granted upfront, and what that would look like in practice. Shriram Santhanam frames the broader organisational challenge — the “crunchy shell, soft centre” problem that leaves internal systems exposed once an agent has gained initial access.
The panel closes with a look at the emerging standards landscape and what identity teams need to do now to get ahead of autonomous and spawning agent architectures before they become ungovernable.