By NHI Mgmt Group Editorial TeamBased on Cyera: “Rethinking Security in the Age of Agentic AI” (December 22, 2025)

TL;DR: Agentic AI systems collapse the gap between intent and execution, operating across enterprise systems at machine speed while legacy security models still assume humans decide and machines execute, according to Cyera. That makes visibility into data, access, and behaviour the decisive control plane, not static policy.


At a glance

What this is: This is an analysis of how agentic AI breaks legacy enterprise security assumptions by acting across systems with human-like autonomy at machine speed.

Why it matters: It matters because IAM, NHI governance, and control design now have to account for actors that are neither simple users nor ordinary software, and that changes how access, visibility, and accountability work.


Context

Agentic AI security is the problem space here: systems that interpret intent, choose actions, and operate across enterprise tools no longer fit the old assumption that humans decide and machines merely execute. That matters because identity and access controls were built around stable actors and predictable request patterns, not software that can pursue goals across systems.

The article argues that the security question is shifting from whether an AI system can do a task to how the enterprise governs what it is allowed to infer, access, and trigger while doing it. Once those systems act on behalf of people, access boundaries, policy enforcement, and visibility all need to reflect that behavioural change.


Key questions

Q: How should security teams govern agentic AI that can execute IAM tasks?

A: Start by treating the agent as an NHI with bounded authority, explicit ownership, and revocation procedures. Require human approval for high-risk actions, log every decision path, and enforce least privilege at the workflow level. If the agent cannot be audited or rolled back, it is not yet ready for autonomous IAM execution.

Q: Why do legacy IAM controls struggle with autonomous AI systems?

A: Legacy IAM controls assume stable identities, predictable requests, and access patterns that can be reviewed after the fact. Autonomous AI breaks that assumption because it can decide what to do, which data to use, and when to act during runtime. That makes static permissions and periodic review insufficient unless they are tied to live decision paths.

Q: What are the signs that AI data access is becoming too broad or misapplied?

A: Warning signs include broad or inherited permissions, retrieval paths that expose more data than the AI needs, and agents that can act on information they should only read. If security teams cannot explain why a connection exists, what data sits behind it, or where the output can go, the path is likely too permissive.

Q: Should organisations prioritize visibility or least privilege first for AI agents?

A: Organisations should do both, but visibility comes first because you cannot restrict what you cannot find. Once agents, tokens, and delegated workflows are discovered, least privilege can be applied to narrow scope and reduce blast radius. Without discovery, least privilege is incomplete because the hidden population remains unmanaged.


Technical breakdown

How agentic AI collapses the user and machine boundary

Traditional enterprise security models assume two identity classes: humans with intent and machines that follow instructions. Agentic AI introduces a third behavioural pattern, where a system interprets goals, selects actions, and interacts with applications on behalf of a user. That breaks deterministic assumptions in IAM because the same action may be initiated by a person, mediated by an agent, or propagated through delegated access. When the actor can reason in real time, security cannot rely on simple request origin alone. It has to interpret context, not just authenticate a session.

Practical implication: identity policy has to distinguish delegated agent activity from direct human activity before authorisation decisions are made.

Why visibility into data, access, and behaviour becomes the control plane

The article’s core security argument is that agentic systems amplify whatever data context and access context already exist. If an organisation cannot clearly see what data it has, who can reach it, and how it is being used, then an agent can turn that uncertainty into action at scale. Security tools built only for static entitlements struggle when behaviour changes continuously. The control problem is no longer just permissioning. It is understanding whether the system’s real-time actions are aligned with the sensitivity of the data and the scope of the task.

Practical implication: governance programmes should correlate identity, data sensitivity, and runtime behaviour instead of treating them as separate controls.

Why manual approvals break under machine-speed execution

Agentic AI can operate continuously, in parallel, and across many applications at once. That creates a timing problem for controls that depend on human review, exception handling, or queue-based approvals. Even well-designed manual workflows assume there is enough time to observe, decide, and intervene before the next action occurs. The article’s point is that this assumption no longer holds once intelligence operates independently at scale. Access decisions and behavioural checks have to move closer to issuance and runtime rather than rely on periodic governance cycles.

Practical implication: replace review-heavy control points with runtime guardrails that can intervene during execution, not after it.


NHI Mgmt Group analysis

Agentic AI is not just another automation layer. It creates a new identity behaviour class that legacy controls do not model well, because the system is making choices in the moment rather than executing a fixed script. That means security teams are no longer governing a user or a workload in isolation. They are governing a decision-making actor that can cross application boundaries and act before human review cycles complete.

Data visibility is now an identity control, not just a governance concern. When an agent can act on data it can infer, retrieve, or transform, unknown data becomes unknown access. The enterprise does not just need cataloguing for compliance reporting; it needs data context to constrain what the agent can reach and why. Without that context, access expansion becomes a default outcome rather than an exception.

Legacy identity assumptions collapse when intent and execution separate. Least privilege was designed for actors whose purpose could be understood at provisioning time. That assumption fails when an autonomous system infers the next best action mid-session and can change tool use as context evolves. The implication is that entitlement models built around static intent no longer describe actual behaviour.

Security teams should treat behaviour as the unit of governance. The article makes clear that permissive access, uncontrolled delegation, and opaque runtime action are now the real risk surface. That pushes identity programmes toward continuous observation of how an actor behaves across systems, not just whether authentication succeeded. The result is a governance model where what the actor does matters more than what the actor is labelled.

Named concept: runtime intent governance. This article points to a control gap where enterprises can no longer govern only who or what can log in. They must govern which inferred intents are acceptable, which behaviours are allowed to unfold, and where action should be interrupted. Practitioners should read this as a shift from static permission management to runtime oversight of delegated intelligence.

From our research library:

What this signals

Runtime intent governance: Agentic AI pushes identity security away from periodic review and toward continuous control of inferred action. Once systems can decide and act within the same session, governance has to focus on what behaviour is allowed to unfold, not just who authenticated.

The practical consequence for IAM and NHI teams is that delegated access, application permissions, and data sensitivity can no longer be managed as separate workstreams. The programme has to understand how an agent’s access path changes as context changes, because that is where least privilege starts to erode.

Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey. That gap suggests most programmes still lack the behavioural controls needed to govern agents in production.


For practitioners

  • Map delegated AI activity to identity boundaries Inventory where agentic systems log in as users, inherit application access, or act through service accounts so you can separate direct human sessions from delegated machine actions.
  • Tie data sensitivity to runtime authorisation Classify the data that agents can reach, then constrain action based on sensitivity and task context rather than assuming broad access is acceptable once authentication succeeds.
  • Reduce dependence on manual approval queues Move high-risk decisions closer to issuance and execution so that controls can block or narrow agent actions before they propagate across multiple systems.
  • Instrument behavioural telemetry for agent sessions Capture tool use, cross-application actions, and delegation patterns so security teams can distinguish normal delegated activity from scope drift or misuse.

Key takeaways

  • Agentic AI changes security from managing static identities to governing actors that infer and execute actions in real time.
  • The central risk is not just more automation, but the collapse of assumptions about who is acting, what they can see, and how quickly they can move.
  • Practitioners should anchor governance in runtime behaviour, data context, and delegated access boundaries rather than in login events alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on delegated agent behaviour and privilege expansion across enterprise systems.
ASI01 — Agent Goal HijackAgents interpret intent in real time, so goal manipulation is a primary risk in this article.
Recommendation — Apply ASI03 to constrain delegated agent privileges and monitor for identity-bound scope creep. Use ASI01 to validate agent goals against approved task boundaries before execution.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article highlights agents logging in as users and blurring actor boundaries at authentication time.
NHI-05 — Overprivileged NHIThe article warns that access expands naturally as agents become embedded in workflows.
Recommendation — Review NHI authentication paths to ensure agent-mediated sessions are distinguishable from human logins. Audit agent and service access for privilege that exceeds the task scope or sensitivity of the data.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsContinuous access governance is central because the article focuses on controlling what agents can do at runtime.
Recommendation — Align entitlements and authorisations with runtime agent behaviour rather than static login events.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governing autonomy and accountability for AI systems in production.
Recommendation — Define governance roles that own approval, monitoring, and escalation for autonomous AI behaviour.

Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
  • Runtime behaviour: Runtime behaviour is what an agent actually does after access has been granted, including tool use, data access, sequencing, and response to untrusted inputs. In agentic systems it is often the real security signal, because harm can occur without any authorization failure.
  • Identity Boundary: The point in an application where authentication and authorisation decisions are enforced. In Node.js systems, this often sits in APIs, middleware, and session handling code, making it the place where governance, runtime behaviour, and security evidence intersect.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org