By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: NewcorePublished October 5, 2026

TL;DR: AI agents now open pull requests, provision accounts and change production systems, but Newcore argues that responsibility breaks when actions run under shared service accounts without a traceable owner, delegation record or approval trail. Accountable autonomy depends on distinct identity, least privilege and human oversight at the point of high-consequence action.

Editorial analysis by NHI Mgmt Group, based on content published by Newcore: “Every Agent Action Needs an Owner: Building Accountability into AI Agents”.


At a glance

What this is: Newcore’s analysis says AI agents create an accountability gap when they act with borrowed authority, shared credentials and no clear human owner for consequential decisions.

Why it matters: IAM, PAM and NHI teams need to translate agent action into provable identity, delegation and approval chains before autonomous workflows touch production, money or permissions.


Context

AI agents are software actors that can take actions, not just suggest them. In this article, the core problem is accountability: once an agent can open pull requests, send emails, provision accounts or change systems, identity and governance controls must show who acted, on whose behalf, and who approved it.

The article frames that gap as a governance failure, not a model failure. Existing human IAM patterns assume a person, a manager and a durable permission chain, while many agent workflows still run under shared service accounts or unclear delegation paths.

For IAM and NHI programmes, the relevant question is whether the organisation can prove ownership and authority for each agent action. The article argues that oversight has to be built into identity, delegation, approval and revocation paths, especially for high-consequence tasks.


Key questions

Q: What breaks when AI agents rely on shared service accounts or API keys?

A: Shared credentials hide which actor actually performed the action, make revocation coarse, and blur accountability across humans and machines. They also let multiple agents inherit the same authority, which increases blast radius and makes incident investigation much harder when something goes wrong.

Q: When should organisations require human approval for an AI agent action?

A: Require human approval when the action could change infrastructure, expose sensitive data, move laterally across systems, or trigger a business-critical workflow that is hard to reverse. Approval is also warranted when the agent’s decision depends on ambiguous input or external data that cannot be trusted at face value. High-consequence actions need a human stop point.

Q: What are the warning signs that agent accountability is failing?

A: Approval rates near 100%, unclear ownership for sub-agent actions, and audit logs that cannot identify the delegator or approver all suggest the control is ceremonial. If the organisation cannot explain who answered for a specific action after the fact, accountability has already failed in practice.

Q: How should fraud teams balance AI automation with human oversight in decision-making?

A: Fraud teams should use AI to handle high-volume pattern detection, anomaly scoring, and rapid triage, then keep humans in the loop for edge cases, novel fraud patterns, and high-impact actions. The practical goal is not full autonomy, but a hybrid operating model where models improve speed and coverage while analysts provide judgment, context, and continuous training feedback.


Technical breakdown

Why borrowed authority breaks agent accountability

Agents often execute under permissions that belong to a person or shared service account, which makes attribution and control fragile. If the credential is not bound to the agent as a distinct identity, the organisation cannot reliably say who exercised the authority, who delegated it, or who can revoke it. That is not just an audit problem. It is a structural weakness in the authorization chain, because the system no longer has a stable accountable subject for the action. Practical implication: bind every agent to a distinct identity and delegation record before it is allowed to touch anything consequential.

Practical implication: Bind each agent to a distinct identity and delegation record before it can act on consequential systems.

Why human approval must sit outside the agent prompt

The article is clear that instructions inside a system prompt are not controls. Agents can be induced to ignore those instructions, especially when exposed to ambiguous content or prompt injection hidden in documents, pages or emails. Real approval has to happen in the tool or API layer, where the action cannot proceed without an explicit human decision. That separates policy from enforcement and prevents the model from talking its way around the gate. Practical implication: enforce approval at the integration boundary, not inside the model workflow.

Practical implication: Enforce human approval in the tool or API layer, not in prompts the agent can ignore.

How audit trails and revocation complete the control chain

Accountability is not complete until the organisation can prove what happened and stop it when needed. A usable audit trail should capture the agent, owner, delegator, target, outcome and approver, while revocation must let the owner halt in-flight work and remove access immediately. Without those two capabilities, approvals become symbolic and incident review becomes guesswork. The article’s point is that trusted autonomy depends on a reversible chain of authority. Practical implication: test audit completeness and kill-switch effectiveness before scaling agent access.

Practical implication: Test audit completeness and kill-switch effectiveness before widening agent access.


Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Accountability is the first identity control that breaks when agents move from suggestion to execution. A human can be named, supervised and recertified. An agent acting under shared credentials can diffuse responsibility across the model, the launcher and the system owner until no one is clearly accountable. The implication is that agent governance has to start with a distinct subject of record, not with policy language.

Borrowed authority is not a safe default for agentic systems. The article shows that agents inherit permissions that were never tied to a durable owner at the moment of use. That means traditional human IAM assumptions about delegated responsibility, manager oversight and signed-off access do not survive unchanged. The practitioner conclusion is that authority must be explicitly attributable at the identity layer.

Accountable autonomy is a named governance model, not a soft principle. Meaningful human oversight, traceable delegation and revocable authority are the only things that make high-impact agent actions governable at scale. Frameworks such as the NIST AI Risk Management Framework and EU AI Act align with that direction, but the operational test is whether the organisation can prove who approved what. Practitioners should treat accountability as a runtime control, not a policy statement.

Escalation thresholds should be based on consequence, not on whether an action is technically automated. Low-risk actions can run with logs alone, but production change, permissions, money movement and external communication require named approval. That distinction matters because over-gating everything produces rubber stamps, while under-gating high-impact actions leaves no owner when something fails. The control question is consequence, reversibility and proof, not whether the workflow feels routine.

Identity platforms are becoming the control plane for agent governance. The article’s structure is important: approval, audit, delegation and revocation all converge on identity. That means NHI and IAM teams are now responsible for making agent behaviour legible to auditors and stoppable by humans. The field is moving toward agent identity as a first-class governance object, and practitioners should plan accordingly.

From our research library:

What this signals

Accountable autonomy: The control boundary is shifting from model behaviour to who can answer for each action. If an organisation cannot bind execution to a named owner, delegation record and revocation path, the workflow may be operationally automated but it is not governable.

Approval should sit where the action is executed, not inside instructions the agent can reinterpret. That means identity teams need to move from policy language to enforceable gates in orchestration, APIs and privilege boundaries, especially for production changes and permission grants.


For practitioners

  • Define a distinct identity for every agent Stop using shared service accounts as the default execution layer for AI agents. Give each agent its own identity so actions can be attributed, scoped and revoked without affecting unrelated workloads.
  • Record delegation for every task Maintain a durable link between the agent, the human owner and the task being performed, including sub-agent chains. If the owner cannot be named, the task should not inherit authority.
  • Move approval to the tool boundary Require explicit approval in the API or orchestration layer for any action that changes production systems, permissions, customer data, external communication or money movement.
  • Gate high-consequence actions by impact tier Classify actions by reversibility and blast radius, then require human sign-off only where the consequence justifies it. Use logs alone for low-risk, reversible work and named approvers for irreversible changes.
  • Test revocation and kill-switch paths Verify that the accountable owner can halt the agent, revoke credentials and stop in-flight work immediately. Treat an untested kill switch as an unproven control.

Key takeaways

  • AI agents create a governance problem when they act with borrowed authority and no stable owner behind the action.
  • The article argues that accountability depends on distinct identity, traceable delegation and enforceable approval before consequential actions run.
  • Without audit and revocation at the identity layer, organisations cannot prove who authorised agent activity or stop it cleanly when behaviour changes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack surface, NIST AI RMF sets the technical controls, and EU AI Act defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governance, oversight and accountability for AI actions.
Recommendation — Establish governance rules that assign accountability, approval and audit responsibility for every agent action.
EU AI ActArt. 14 — Human oversightMeaningful human oversight is the article's central control concept for consequential AI actions.
Recommendation — Design human oversight mechanisms that can intervene before high-impact agent actions execute.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on agent authority, delegation and misuse of inherited permissions.
ASI09 — Human-Agent Trust ExploitationIt warns that agents can be manipulated past weak approval language or unsafe oversight.
Recommendation — Bind agent actions to named owners and scoped privileges to prevent identity and privilege abuse. Place approval gates outside the prompt so human trust cannot be exploited by the agent.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingRevocation and kill-switch control are central, especially when agent authority must be removed quickly.
Recommendation — Ensure agent credentials can be revoked immediately when an owner suspends or offboards the agent.

Key terms

  • Accountable Autonomy: A governance model in which an AI agent can act independently, but every meaningful action is still tied to a named owner, a delegation record and an enforceable approval path. In practice, autonomy is only safe when the organisation can prove who authorised the action and who can stop it.
  • Delegation Chain: A delegation chain is the sequence of identities, credentials, and tool calls an agent uses to complete a task across systems. It matters because each step may appear acceptable on its own while the combined path produces an outcome no reviewer would have approved directly.
  • Human Oversight: Human oversight is the requirement that a person remains responsible for reviewing, approving, or correcting AI-driven output before it causes a material action. In governance terms, it is the control that prevents automation from becoming unowned authority.
  • Borrowed Authority: Borrowed authority is the security condition where an agent can act with permissions that originated from a user, service account, or connected application. It is what makes prompt injection operationally dangerous. The attacker does not need new credentials if the agent can already exercise valid ones on their behalf.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on October 5, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org