By NHI Mgmt Group Editorial TeamBased on Astrix Security: “Identity: The Missing Link in Agentic AI Security – Astrix Named in New Gartner® Report” (January 15, 2026)

TL;DR: AI systems will initiate 50% of service requests by 2030, while over 60% of enterprises are expected to secure the AI lifecycle through dedicated platforms, according to Gartner, and Gartner’s Emerging Tech report places Astrix Security in the Agentic AI Security category. The practical issue is not model intelligence but runtime identity, authorisation, and governance for agents that act across trust boundaries.


At a glance

What this is: Astrix Security’s review of Gartner’s AI TRiSM research says agentic AI security is becoming a core enterprise control problem because autonomous agents depend on non-human identities, runtime authorisation, and governance that most IAM models do not yet cover.

Why it matters: IAM, PAM, and NHI teams need to treat agentic AI as a runtime identity problem because agents can initiate actions, access systems, and expand attack surface faster than static governance processes can keep up.

By the numbers:

  • Gartner expects more than 60% of enterprises to secure the AI lifecycle through AI security platforms by 2030, up from less than 10% in 2025.
  • Gartner predicts that AI systems will initiate 50% of all service requests by 2030, driven largely by agentic AI.
  • Astrix Security says 35% of senior cybersecurity leaders suspect unsanctioned use of GenAI but lack concrete visibility into where and how it is being used.

Context

Agentic AI turns identity into a runtime control problem, not just an onboarding problem. The issue is no longer whether a model can generate output, but whether an autonomous system can be governed when it can initiate actions, access systems, and interact with other tools and agents.

Astrix Security’s analysis of Gartner’s Emerging Tech report places that problem squarely inside enterprise IAM, because AI agents rely on non-human identities, credentials, and authorisation paths that are often poorly inventoried and over-privileged. That makes discovery, policy enforcement, and session-level control part of the core security design.

The article’s broader point is that AI adoption is outpacing the identity controls needed to make it safe at enterprise scale. In that sense, agentic AI does not create a new security discipline so much as it exposes where existing governance assumptions stop working.


Key questions

Q: What breaks when AI agents inherit access from users and service accounts?

A: The main failure is that inherited access can be broader than the agent’s actual task, so privilege becomes easier to reuse than to govern. Once an agent can chain tool calls across systems, the original approval no longer describes the full blast radius. Security teams need to treat inherited access as a live identity surface, not a one-time provisioning artifact.

Q: Why do AI agents change the way organisations think about runtime authorisation?

A: Because the decision to act now happens inside the session, not only at provisioning time. Runtime authorisation gives teams a way to constrain tool use, API calls, and data access to the current task, which is essential when the agent can initiate actions independently and cross trust boundaries without a human approval gate.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.

Q: Should organisations treat service accounts and AI agents under the same authorization model?

A: Yes. Service accounts, AI agents, and other workloads are all non-human principals that need centrally governed access decisions, even if their runtime behaviour differs. Treating them under one authorization model reduces blind spots, exposes overprivilege faster, and gives security teams a common way to enforce least privilege across delegated machine identity.


Technical breakdown

Why agentic AI changes the identity control plane

Agentic AI is different from conventional automation because the system does not just execute a fixed workflow. It can select actions at runtime, call tools, and cross trust boundaries using non-human identities such as API keys, service accounts, and tokens. That means the identity layer has to govern both who or what the agent is and what it is allowed to do in a given session. Traditional IAM models were built around stable subjects and predictable request patterns, which is why they struggle once the actor can decide and act dynamically.

Practical implication: treat every agent as a governed identity subject with explicit runtime authorisation, not as an application feature.

Why shadow AI becomes an identity inventory problem

The article repeatedly points to discovery and governance of AI agents as a prerequisite for control. That matters because an undiscovered agent is not just an unmanaged model, it is an unmanaged identity with possible access to systems, data sources, and APIs. Once shadow AI exists, access reviews and entitlement recertification cannot operate reliably because the subject itself is missing from inventory. In NHI terms, this is the same failure pattern seen when service accounts are created outside lifecycle controls, except the operational pace is faster and the blast radius can expand across multiple tools in one workflow.

Practical implication: build agent and NHI inventory together so hidden identities are visible before access is approved or expanded.

Policy-based access only works when session context is enforced

Runtime authorization is the control that turns agent governance from policy on paper into enforcement in motion. In this model, the agent should receive only the permissions needed for the current task, with contextual checks on tool use, data access, and transaction scope. Without that session-level enforcement, least privilege becomes a provisioning-time statement rather than an active boundary. The article’s reference to contextual inspection across tools, APIs, and data sources is important because it shows the control surface is not a single application, but the full transaction path the agent can traverse.

Practical implication: enforce task-scoped policy decisions at runtime across tools, APIs, and data sources, not just at account creation.


Threat narrative

Attacker objective: The objective is to exploit unmanaged or over-privileged AI agent identity paths to reach data and systems with less scrutiny than conventional users receive.

  1. Entry occurs when an agent or embedded AI system is introduced into the enterprise without complete discovery or governance, leaving its identity and access paths outside normal control.
  2. Credential or privilege abuse follows when the agent inherits broad access through static credentials, over-privileged service accounts, or poorly scoped tokens.
  3. Escalation happens as the agent crosses tools, APIs, and data sources with little session-level inspection, expanding its effective reach beyond the original task.
  4. Impact is the loss of reliable control over who initiated actions, what data was touched, and whether the agent’s behaviour matched policy expectations.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic AI exposes an identity governance assumption that was designed for stable, human-paced subjects. Access provisioning, review, and revocation models assume the actor is known, inventoryable, and slow enough to govern between sessions. That assumption fails when the actor can initiate work, select tools, and move through systems at runtime. The implication is that identity governance has to move from static subject management to live control of agent behaviour.

Agent identity discovery is now a prerequisite for trust, not an administrative nicety. Enterprises cannot govern what they cannot enumerate, and AI agents create a hidden estate of identities that may sit outside IAM, PAM, and security tooling. This is not just shadow IT with a new label. It is shadow identity with autonomous reach, and that makes inventory accuracy a control outcome rather than a reporting metric.

Policy without runtime enforcement does not constrain agentic systems. The article’s emphasis on runtime authorisation and contextual inspection reflects a broader market truth: agentic AI breaks the old assumption that permissions set at onboarding remain valid throughout execution. For practitioners, the important shift is from granting access to continuously constraining behaviour.

Ephemeral intent, persistent credentials: that combination creates the new governance gap for agentic AI. The agent’s objective can change within a session while the credential it uses remains static, which means the trust decision is made once but the action path unfolds many times. That mismatch is why identity, not just model governance, is becoming the decisive control point.

The market is moving toward identity-first AI security because the failure mode is operational, not theoretical. Gartner’s framing confirms that enterprises are treating AI risk as a control-plane problem across discovery, authorisation, and monitoring. Practitioners should expect procurement, architecture, and audit requirements to converge on whether agent identity is visible, constrained, and attributable across the full lifecycle.

From our research library:

What this signals

Ephemeral intent, persistent credentials: this is the core governance tension in agentic AI. Identity teams have spent years optimising lifecycle management for stable subjects, but autonomous agents can change tasks, tools, and scope within a single session. That shifts the control point from periodic review to issuance-time and runtime enforcement.

A mature programme now needs one inventory for agents, service accounts, secrets, and API credentials rather than parallel records split across platform teams. Without that join, shadow AI becomes a shadow identity problem, and neither audit nor response teams will have a trustworthy view of blast radius.

The operational signal is plain enough: 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey. That figure points to a governance gap that will widen unless identity controls move closer to execution time.


For practitioners

  • Map every AI agent to an identity owner Create an inventory of all AI agents, embedded copilots, and autonomous workflows, then tie each one to a named business and technical owner so no agent sits outside accountability.
  • Separate agent discovery from access approval Do not approve runtime access for an agent until its associated non-human identities, credentials, and tool connections are visible in one inventory and reviewed together.
  • Apply runtime authorisation to every agent session Use policy-based controls to scope tool calls, API access, and data access to the current task, then log each decision for later audit and investigation.
  • Inspect agent activity across the full transaction path Correlate session activity across tools, APIs, and data sources so abnormal behaviour, excessive privilege, and unsanctioned adoption are visible in one control view.
  • Treat third-party and embedded agents as external trust boundaries Review vendor-hosted or embedded agent integrations for offboarding, isolation, and revocation gaps before they are allowed to inherit enterprise access.

Key takeaways

  • Agentic AI turns identity into a runtime control problem because autonomous agents can initiate actions, call tools, and cross trust boundaries without waiting for a human review cycle.
  • The central risk is not only model behaviour but unmanaged non-human identities, static credentials, and access paths that outlive the task they were meant to support.
  • Practitioners should shift from periodic review to inventory, ownership, and session-level enforcement so agent access is constrained while the work is actually happening.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centers on AI agents inheriting and misusing identity and privilege at runtime.
Recommendation — Map agent runtime access to ASI03 and constrain privilege to the current task and session.
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article highlights AI agents relying on exposed API keys, tokens, and other machine credentials.
NHI-05 — Overprivileged NHIOver-privileged non-human identities are a central risk in the article’s description of agent deployments.
Recommendation — Scan agent estates for leaked secrets and revoke exposed credentials before agents inherit them. Review AI agent entitlements and remove permissions that exceed the task or environment scope.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about organisational control of AI systems, ownership, and accountability.
Recommendation — Assign governance roles for AI agents and require accountability for access, behaviour, and lifecycle decisions.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article repeatedly focuses on authorisation and entitlement control for AI agents.
Recommendation — Use PR.AA-05 to verify that AI agent access is authorised, scoped, and reviewed.

Key terms

  • Agentic AI Security: Agentic AI security is the discipline of securing autonomous AI systems that can take actions, use tools, and chain decisions without direct human approval at each step. It covers identity and access management for AI agents, prompt injection defence, tool call governance, credential scoping, and runtime monitoring. As agentic systems acquire real-world authority, API access, file writes, workflow triggers, the security model must treat them as non-human identities with explicit lifecycle controls, not trusted processes.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org