By NHI Mgmt Group Editorial TeamBased on Oasis Security: “Oasis named in Industry Analyst Report Highlighting Emerging Tech in AI TRISM and Agentic AI” (May 1, 2026)

TL;DR: Gartner’s January 2026 analysis says enterprises are moving from experimental generative AI to autonomous agents, and predicts 50% of all service requests will be initiated by non-human identity customers powered by agentic AI by 2030, according to Oasis Security’s summary of the report. Traditional IAM, PAM, and IGA controls do not handle non-deterministic agent behaviour.


At a glance

What this is: This analysis says agentic AI is exposing an identity governance gap because autonomous agents do not fit legacy IAM, PAM, and IGA assumptions about stable users and predictable access.

Why it matters: IAM, NHI, and governance teams need to rethink how identity is issued, constrained, and revoked when the actor is an AI agent that can create and discard access dynamically.

By the numbers:

  • By 2030, 50% of all service requests will be initiated by non-human identity customers powered by agentic AI systems, according to Gartner research cited by Oasis Security.

Context

Agentic AI changes the identity problem because the actor is no longer a person or a static service account. The article argues that enterprises are moving from experimentation to operational use, where access decisions, accountability, and governance have to cope with systems that act at runtime rather than on a fixed schedule.

In that model, the old assumption that identity can be provisioned, reviewed, and retired as a stable record starts to break down. For IAM, PAM, and IGA teams, the practical issue is not just more access, but access that can be created ephemerally, used immediately, and removed before conventional governance cycles ever see it.


Key questions

Q: How should security teams govern data access for agentic AI workflows?

A: Security teams should treat data access as part of the agent’s decision boundary, not as a separate storage problem. Scope access by use case, classify the datasets that influence actions, and verify that policies can constrain runtime behaviour as agents select tools and next steps. The goal is to prevent an agent from turning broad data reach into uncontrolled action.

Q: Why do traditional IAM and PAM controls struggle with autonomous AI agents?

A: Traditional IAM and PAM controls assume access can be granted, reviewed, and removed around a stable identity. Autonomous agents can create ephemeral identities, request access mid-session, and finish work before the next review cycle. The result is a governance mismatch, because the identity boundary moves while legacy controls still expect it to stay fixed.

Q: What are the signs that agentic AI is operating outside its intended security boundaries?

A: Common warning signs include agents accessing systems they were not meant to use, acting on data beyond their assigned scope, or producing chained errors that spread across workflows. Another signal is when decisions start relying on unverified memory or model output without human review. These patterns usually point to weak controls, poor monitoring, or excessive agency.

Q: How should teams implement AI access controls in a governance programme?

A: Start by inventorying every AI identity, including users, service accounts, API keys, model endpoints, and vendor connections. Then apply role-based access as the baseline and use context-aware policies for sensitivity, time, and purpose. The goal is to prevent broad standing access while keeping approvals auditable and aligned to business use cases.


Technical breakdown

Why agentic AI breaks traditional identity models

Agentic AI systems are not just another form of automation. The article describes them as non-deterministic actors that can make runtime decisions, request access dynamically, and generate ephemeral identities to complete tasks. That combination makes them different from both human users and conventional NHIs, because the access path is not fixed at provisioning time. Traditional IAM and PAM assume the subject, scope, and duration of access are knowable in advance. Agentic systems break that assumption by changing tool use and timing during execution.

Practical implication: treat agentic AI as a distinct identity class, not a variant of human or service-account governance.

Agentic access management and session-scoped identity

The article’s core control idea is to bind access to a specific agent action and then delete that identity when the session ends. In identity terms, this is closer to just-in-time access than to standing entitlement, but the key distinction is that the access decision is driven by agent intent in the moment. That matters because persistent credentials create unacceptable blast radius when the actor can act autonomously. The control objective is to shrink the useful lifetime of the identity to the exact task window.

Practical implication: design for session-scoped issuance and immediate revocation rather than persistent entitlements for agent activity.

Shadow AI and discovery gaps in agent inventories

The article also points to local agents and employee-installed tools that operate without IT oversight. That creates a discovery problem before it becomes an authorization problem, because you cannot govern what you cannot inventory. In practice, this means AI-SPM style visibility is a prerequisite for any credible governance model. Without detection of agents across cloud, SaaS, on-premises, and endpoint contexts, policy enforcement stays partial and accountability stays fragmented.

Practical implication: inventory agentic systems first, then map their identities, prompts, and access paths to governance controls.


Threat narrative

Attacker objective: The objective is not a classic breach, but unchecked agentic access that expands operational reach faster than identity governance can control it.

  1. Entry occurs when employees or business units introduce autonomous agents or local AI tools into workflows without identity oversight.
  2. Credential access happens when those agents request sensitive resources and receive scoped identities or access tokens to perform a task.
  3. Escalation occurs if those identities are not tightly bound to the session, allowing over-broad or repeated use beyond the intended action.
  4. Impact is governance drift: access is exercised faster than review cycles can observe, certify, or revoke it, leaving unmanaged identity debt.
  • Meta Muse agent hijack 2026: An undocumented Muse setting let local malware hijack Meta's personal AI agent, steal its authentication material and abuse user access.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic identity is not a new wrapper around NHI, it is a governance discontinuity. The article shows why autonomous agents cannot be managed as if they were service accounts with better prompts. Decision timing, tool choice, and session length are all runtime variables, so identity governance has to move from static assignment to dynamic authority boundaries. Practitioner conclusion: agentic AI requires its own identity model, not a renamed NHI playbook.

Ephemeral identity is becoming the decisive control boundary. The article’s session-scoped access pattern reflects a broader shift: if the actor is allowed to act only for the duration of a task, standing privilege becomes the wrong unit of control. That changes how IAM, PAM, and IGA should be evaluated, because the real question is whether the issuance and deletion of access are tied tightly enough to the agent’s task lifecycle. Practitioner conclusion: measure the lifetime of authority, not just the presence of authority.

Agentic governance exposes a new identity gap that legacy certification cycles cannot close. Access review processes were designed for identities that persist long enough to be observed and recertified. That assumption fails when an agent can create, use, and discard access within a single session. The implication is not merely better review cadence; it is a rethink of where governance starts and ends for autonomous systems. Practitioner conclusion: move controls upstream to issuance, discovery, and policy enforcement at runtime.

Shadow AI turns identity governance into an inventory problem before it becomes an access problem. Unmanaged local agents can exist outside central IAM visibility while still touching sensitive systems and data. That means the first failure is often not permission misuse but absence of authoritative discovery. Practitioner conclusion: discovery and inventory are now core governance controls for agentic AI, not optional hygiene.

Agentic AI adoption is forcing AI TRISM and identity governance to converge. The article aligns with the broader market signal that governance, risk, and accountability need to be handled together when machines are making operational decisions. In practice, this pushes identity teams closer to AI governance, because access decisions and model behaviour are no longer separable concerns. Practitioner conclusion: treat agentic identity as a cross-domain governance issue spanning IAM, PAM, and AI risk management.

From our research library:

What this signals

Agentic identity is now a governance boundary, not a future concept. The practical shift is that access decisions have to be made at issuance time for a runtime actor, because conventional review cycles assume an identity persists long enough to be observed. That assumption no longer holds once the system can act, request tools, and disappear inside one task.

Ephemeral authority will become the dominant design constraint for autonomous systems. Security teams should expect more pressure to replace standing privilege with task-scoped issuance, short-lived tokens, and authoritative discovery of all agent instances. The programme implication is clear: identity governance, AI governance, and endpoint visibility now need to operate as one control plane.


For practitioners

  • Define a distinct agentic identity class Document agentic AI as a separate governed actor type with its own issuance, authority, and revocation rules rather than folding it into human or service-account policy.
  • Inventory shadow AI across endpoints and cloud Extend discovery to locally installed agents and unmanaged AI tools so access decisions are based on an authoritative inventory, not assumptions about approved platforms.
  • Bind access to task-scoped sessions Issue access only for the exact session needed by the agent, and remove the identity immediately after the task completes to avoid standing privilege.
  • Align governance with AI TRISM Coordinate identity, risk, and accountability decisions so agentic access policy, monitoring, and review operate under the same governance model.

Key takeaways

  • Agentic AI exposes a governance gap because autonomous systems do not fit the identity assumptions built into legacy IAM, PAM, and IGA.
  • The article ties that gap to fast-growing adoption and Gartner’s projection that 50% of service requests will be initiated by non-human identity customers powered by agentic AI by 2030.
  • The practical response is to govern agents as a separate identity class, with discovery, task-scoped access, and immediate revocation as core controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAgentic systems here create and use identities dynamically, which is the central governance problem.
Recommendation — Constrain agent privilege boundaries and verify identity before each autonomous action.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article warns that static or broad entitlements become unsafe when agents act at runtime.
Recommendation — Reduce agent entitlements to the minimum scope needed for each task session.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governance, accountability, and decision rights for AI systems.
Recommendation — Establish AI governance ownership and decision rights for agentic access policies.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe identity gap is an authorization problem as much as a visibility problem.
Recommendation — Review access permissions for autonomous systems against task-specific authorization boundaries.
CSA MAESTROAgentic AI threat modelingThe article concerns the governance and threat surface of agentic AI systems.
Recommendation — Model agent identity, access, and decision paths as part of AI threat analysis.

Key terms

  • Agentic Identity Gap: The mismatch between legacy identity governance and AI agents that make access decisions at runtime. It appears when controls assume the actor is stable, predictable, and reviewable after the fact, while the system can create ephemeral identities and change tool use mid-session.
  • Session-Scoped Access: Session-scoped access is permission that exists only for a defined task or time window and is expected to end when the task ends. For NHI governance, it reduces lingering authority and makes AI-driven activity easier to review, revoke, and investigate when behaviour changes.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • AI-SPM: AI Security Posture Management extends security visibility into AI models, prompts, outputs, and supporting workflows. It gives teams a way to identify risky AI usage, check policy alignment, and monitor how AI systems interact with data and identity controls over time.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org