By NHI Mgmt Group Editorial TeamBased on Clutch Security: “Why We Created the Agentic AI Masterclass” (March 30, 2026)

TL;DR: Agentic AI agents now browse the web, execute code, access SaaS applications, and take autonomous actions on behalf of users, creating a rapidly expanding attack surface that security teams are still struggling to define, according to Clutch Security. Access review processes assume privilege persists long enough to be reviewed; autonomous agents can acquire and discard access within a single session, breaking that premise.


At a glance

What this is: This is Clutch Security's account of how agentic AI is widening the NHI attack surface through autonomous web, code, and SaaS activity, embedded credentials, and shadow deployments.

Why it matters: It matters because IAM, IGA, and PAM teams now have to govern access patterns that can appear, act, and disappear faster than traditional review and certification cycles can observe.


Context

Agentic AI changes the security problem from managing static machine access to governing software that can select tools, reach into SaaS platforms, and take actions during runtime. That matters for identity programmes because the control assumptions behind review, approval, and ownership were built for slower, more predictable non-human actors.

Clutch Security frames the issue as a governance gap as much as a technology gap: developers are embedding credentials in MCP servers, employees are connecting agents to business systems, and shadow AI is spreading without a clear operating model. The result is not just more access, but more ways for NHI exposure to emerge outside normal identity control planes.


Key questions

Q: What breaks when agentic AI is allowed to act with embedded credentials?

A: The control problem changes from isolated secret protection to governed runtime access. Embedded credentials let agents reach SaaS applications, internal systems, or code execution paths without the usual visibility into who owns the access, what it can reach, or when it should be revoked. The result is hidden privilege accumulation.

Q: Why do autonomous agents make traditional access reviews less effective?

A: Access reviews assume permissions persist long enough to be observed, challenged, and recertified. Autonomous agents can obtain, use, and discard access within a single session, which means the risky action may occur before the next review cycle. That makes runtime enforcement more important than periodic certification alone.

Q: How should teams govern shadow AI without losing visibility into NHI risk?

A: Treat shadow AI as an identity discovery problem first. Teams need continuous discovery of agents, connectors, and delegated workflows, plus ownership and purpose data attached to each runtime actor. Without that inventory, normal joiner-mover-leaver processes and certification cycles cannot govern what they cannot see.

Q: What is the difference between human access assumptions and agent access assumptions?

A: Human access assumptions rely on approval, predictable use, and reviewable activity. Agent access assumptions have to account for dynamic tool choice, runtime execution, and access that may be consumed without human pacing. That means the control model must shift from user-centric review to governed delegation and continuous visibility.


Technical breakdown

Why agentic AI expands the NHI attack surface

Agentic AI is not just another application layer because it can decide which tool to use, when to use it, and which data or system to reach in the moment. That runtime variability means the identity problem shifts from static provisioning to dynamic authorization and traceability. When agents browse the web, execute code, and connect to SaaS systems, every dependency becomes part of the trust boundary. If those dependencies are not inventoryable and governable, security teams lose line of sight into what the agent can touch and why.

Practical implication: Treat agent runtime behaviour as part of the identity boundary, not just the application boundary.

Why embedded credentials and MCP servers change governance

The article points to developers installing MCP servers with embedded credentials, which turns the integration layer into an identity concentration point. Once credentials are baked into the path that agents use to reach tools, the risk is no longer limited to a single secret being stolen. It becomes a compound exposure problem involving ownership, reuse, scope, and revocation. That is classic NHI governance territory, but the agentic context makes it harder because the access may be consumed by systems that are not centrally visible or manually operated.

Practical implication: Inventory and govern every credential path that an agent can inherit, not only the agent itself.

How shadow AI breaks access review assumptions

Traditional access review assumes a stable identity with a persistent entitlement set that can be certified after the fact. Agentic AI breaks that model when access can be requested, used, and discarded inside a single session or task. In practice, the control failure is temporal as much as structural: by the time a reviewer sees the entitlement, the meaningful risk may already have happened. That is why governance has to move closer to issuance, authorization, and continuous visibility instead of relying on periodic recertification alone.

Practical implication: Shift review evidence from periodic entitlement lists to runtime issuance and activity telemetry.


Threat narrative

Attacker objective: The objective is to exploit agentic access paths to reach business systems, misuse delegated credentials, and expand compromise across otherwise hidden NHI surfaces.

  1. Entry happens when employees or developers connect agents to business systems and MCP servers carry embedded credentials into the environment.
  2. Credential exposure or abuse follows when those credentials or connected permissions are read by the wrong document, reused by the wrong workflow, or inherited without visibility.
  3. Escalation occurs as the agent reaches internal systems, SaaS applications, or code execution paths that exceed what the original reviewer understood.
  4. Impact is the rapid expansion of attack surface and control loss across shadow AI and agent-driven access paths.
  • JADEPUFFER agentic ransomware 2026: The first documented agentic ransomware used harvested keys, default MinIO credentials and a default Nacos signing key to wipe a database.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic AI is forcing the NHI problem into a new operating model: the security issue is no longer only whether a service account exists, but whether a software actor can independently discover, combine, and consume access at runtime. That changes what counts as an identity boundary and makes static credential governance insufficient on its own. Practitioners should treat the agent as a first-class identity subject, not just a user proxy.

Access review is becoming a lagging control for agentic systems: traditional certification assumes access is stable long enough to be observed, reviewed, and approved. That assumption fails when an agent can acquire and discard privileges inside a single session or task. The implication is not simply more frequent reviews, but a rethink of what evidence can actually prove governance for transient actors.

Embedded credentials are turning integration layers into governance hotspots: once MCP servers or other agent connectors carry secrets, the risk is no longer isolated to one secret or one app. The blast radius is defined by reuse, inheritance, and hidden downstream reach across SaaS and internal systems. Practitioners should map where agent access is being inherited rather than explicitly granted.

Shadow AI is now an identity-discovery problem, not just an inventory problem: unmanaged agents can exist without the normal procurement, onboarding, or approval trail that security teams rely on. That means identity governance has to find unregistered runtime actors before it can secure them. The practical conclusion is that discovery, ownership, and lifecycle control must move closer to the point where the agent becomes operational.

Ephemeral credential trust debt: the more organisations rely on short-lived or embedded credentials for agentic workflows, the more they accumulate trust they cannot later reconstruct cleanly. Short duration does not equal low risk when the actor can act autonomously and invisibly. Practitioners should assume the governance gap is created at issuance, not at incident response.

From our research library:

What this signals

Agentic AI identity governance now has to start before review ever begins: review cycles assume a stable entitlement can be certified after the fact, but autonomous actors can create and consume access inside a single runtime window. That means the governance question is no longer only who approved access, but whether the programme can observe access at the moment it exists.

Agentic AI is turning identity discovery into the first control plane: unmanaged agents, hidden connectors, and embedded credentials create a programme where access may exist before ownership does. The practical response is to find runtime actors earlier, classify them correctly, and attach governance to the point where they become operational.

69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey. That view matches what IAM teams are already seeing: traditional lifecycle and review models do not map cleanly to software that decides, acts, and releases access dynamically.


For practitioners

  • Define agent identities explicitly Record every agent, MCP connector, and delegated workflow as a governed identity subject with an owner, purpose, and scope.
  • Inventory embedded credentials Find credentials embedded in agent toolchains, connectors, and developer-managed integrations, then trace which systems those credentials can reach.
  • Move review left to issuance Use issuance-time policy and runtime telemetry instead of relying only on periodic entitlement recertification for agent access.
  • Separate human and agent access paths Prevent agents from inheriting human access assumptions, especially where SaaS permissions or code execution paths are shared.
  • Build a shadow AI discovery workflow Continuously scan for unmanaged agents and connector registrations so new runtime identities are discovered before they become operational.

Key takeaways

  • Agentic AI expands the NHI problem from static credentials to runtime actors that can reach tools, SaaS systems, and code execution paths on their own.
  • The governance gap is visible in review cycles, because access may be consumed before a certifier ever sees a meaningful entitlement.
  • Practitioners need discovery, ownership, and issuance-time control over agents and connectors, not just periodic access recertification.

Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Embedded Credential: A credential embedded in software, firmware, or automation that can be reused outside its intended context. In practice, it becomes a silent trust bridge between systems. For agents and connected devices, the risk is not the secret alone but the reach it grants if runtime controls are weak.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org