TL;DR: Agentic AI systems plan, decide, and act inside enterprise environments, and a global survey cited by Lasso Security found 97% of security leaders expect a material incident this year while only 6% of budgets are allocated to the risk. Existing IAM and monitoring models struggle because agent behaviour changes at runtime and can chain across tools and data sources.
At a glance
What this is: This is a best-practices analysis of agentic AI security that argues current enterprise controls fall short because agents act at runtime, chain across tools, and operate under identities with broader access than intended.
Why it matters: It matters because IAM, PAM, and security monitoring teams now have to govern non-human actors that can change behaviour mid-session, which breaks assumptions behind static permissions, alerting, and review cycles.
By the numbers:
- 97% of security leaders expect a material AI-agent-driven security incident this year, according to Lasso Security.
- Only 6% of security budgets are currently allocated to this risk, according to Lasso Security.
Context
Agentic AI is software that can plan, choose actions, and execute them inside enterprise systems with limited or no human review at each step. In identity terms, that makes the agent a non-human identity with tool access, memory, and the ability to take actions that may be difficult to reverse.
The security gap is not just exposure to bad prompts. The larger issue is that current IAM and monitoring models were designed for predictable applications, while agentic AI can change behaviour as session context, tool access, and model output change. That means governance has to shift from static policy assumptions to runtime control and continuous observation.
Key questions
Q: What breaks when agentic AI is governed like a normal application account?
A: Security controls break down because agentic systems do not behave like fixed-function applications. They can choose actions at runtime, combine tools in unexpected ways, and move faster than periodic review cycles. That means static roles, annual recertification, and one-time approvals do not fully describe the risk or contain the behaviour.
Q: Why do overprivileged agent identities create such a large security risk?
A: Because agents can turn ordinary tool access into destructive action at machine speed. If an agent can reach email, internal APIs, file systems, or cloud resources with broad permissions, a small prompt or supply-chain issue can become deletion, exfiltration, or workflow abuse. The risk is amplification through legitimate access, not model magic.
Q: How do security teams know if agentic AI controls are failing?
A: The main signs are session drift, repeated retry loops, unauthorized tool calls, and behaviour that diverges from the documented task sequence. If the agent keeps moving through steps after intent-to-tool alignment weakens, the system is drifting beyond its control envelope. In practice, teams should measure the full execution path, not isolated prompts.
Q: Should organisations prioritise runtime controls or prompt rules for agentic AI governance?
A: Runtime controls should take priority because prompt rules are advisory, not enforced policy. Prompt text can be manipulated, but infrastructure and authorisation layers can bound tools, data, and execution conditions. Organisations should treat prompts as guidance and runtime policy as the governing control.
Technical breakdown
Why agentic AI breaks static task boundaries
Agentic systems do not behave like conventional applications that follow a fixed request and response path. They select actions at runtime based on memory, tool access, and prior steps in the same session. That means a prompt is not the full policy surface. The real control surface is the combination of allowed tools, reachable data sources, and execution conditions. If those are not bounded in policy, the agent can improvise outside the intended task scope. For security teams, the practical challenge is that task scope must be enforced as an identity and authorization property, not as natural language guidance.
Practical implication: define agent task scope in policy and authorization, not in prompt text.
Least privilege for agentic AI identities and tool access
Agents inherit the permissions of the identity under which they run, which makes over-scoped service identities especially dangerous. A broadly privileged agent can read, write, call APIs, and execute code across systems that were never meant to share one access path. Because agent workflows evolve, static permissions drift out of alignment quickly. Time-bounded tokens, dedicated service identities per role, and allowlisted tool access reduce the blast radius, but only if access scope is tied to actual runtime task needs. The key distinction is between identity permissions on paper and what the agent can actually do when executing.
Practical implication: scope each agent to a dedicated identity, narrow tool allowlist, and short-lived credentials.
Continuous monitoring for agent behaviour, not just application events
Conventional monitoring is weak against agentic systems because legitimate-looking tool calls can still be harmful. The useful signal is sequence and context: which tools were called, in what order, with what inputs, and whether the result fits the agent’s usual role. Behavioural baselines matter because prompt injection and manipulation often produce outputs that look syntactically normal. Security teams need tracing that follows the reasoning chain across sessions, not just the final log line. Without that, compromise is detectable only after the action has already completed.
Practical implication: baseline normal tool sequences per agent and alert on deviation from expected runtime behaviour.
Threat narrative
Attacker objective: The attacker’s objective is to turn a trusted non-human identity into a credentialed proxy that can move data or execute actions under legitimate access.
- Entry occurs when malicious instructions are embedded in retrieved content, tool output, or another data source the agent is designed to trust.
- Credential access happens when the agent uses its inherited identity and over-scoped permissions to call tools or query data beyond the intended task.
- Escalation and impact follow when the manipulated agent performs actions that appear legitimate, including chained tool calls or downstream transactions that security teams cannot easily unwind.
Breaches seen in the wild
- OmniGPT breach claim 2025: A hacker claims to have leaked 34 million OmniGPT AI chat messages holding users' API keys and credentials; OmniGPT has not confirmed it.
- Meta AI Instagram Account Takeover: 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Agentic AI creates an identity problem before it creates an application problem: these systems are non-human identities that can plan, choose tools, and execute actions inside live enterprise environments. That means their risk cannot be reduced to prompt safety or model quality alone. The real governance issue is that they operate as active identities with delegated authority, so IAM, PAM, and workflow governance all become runtime control problems.
Static privilege assumptions collapse when the actor decides at runtime: least privilege was designed for a role whose intent is known at provisioning time. That assumption fails when the actor is autonomous in execution because tool choice and action timing are not fixed in advance. The implication is that identity governance has to treat runtime behaviour as part of authorisation, not as an after-the-fact log review.
Ephemeral-looking agent actions still create durable blast radius: even when a task appears short-lived, a manipulated agent can chain tools, retrieve sensitive context, and trigger irreversible downstream actions in one session. Conventional access review cycles assume there will be a stable entitlement to recertify later, but agent behaviour can outrun that cycle. Practitioners need to rethink how they define evidence, accountability, and revocation when the session itself is the attack window.
Unregistered agents are the new shadow identity problem: the article describes agents entering through engineering, cloud operations, and low-code business build paths without a consistent security review. That pattern widens the gap between inventory and actual identity surface area. The governance conclusion is straightforward: if you cannot inventory the agent, you cannot govern its access, its lifecycle, or its risk.
Runtime policy is becoming the decisive control plane for agentic AI: the strongest signal in the article is that boundaries encoded in prompts are weaker than boundaries enforced in infrastructure and authorisation layers. That does not just add another control. It shifts the centre of gravity from model behaviour to identity enforcement, which is where enterprise governance will be won or lost.
From our research library:
- Organisations that describe themselves as confident in their AI deployment actually experience a 72% security incident rate, compared to 33% for those who remain cautious, according to the 2026 Infrastructure Identity Survey.
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.
- Read next: Agentic AI Identity Maturity Model
What this signals
Shadow AI will become a shadow identity problem: agents built in low-code tools, cloud platforms, or engineering workflows can appear faster than security can inventory them. The programme risk is not just undocumented tooling, but undocumented identities with delegated access that bypass normal review and offboarding paths.
Agentic AI security has to be governed as identity lifecycle, not model lifecycle: once an agent can act, the questions become who owns it, what it can reach, how long it lives, and how it is revoked. Those are lifecycle and access governance questions first, and AI questions second.
Security teams should expect the control plane to shift toward runtime authorisation and behavioural monitoring, because static prompts and one-time approvals do not survive model updates, tool expansion, or chained actions across sessions.
For practitioners
- Define task boundaries in policy Specify which tools, data sources, write paths, and escalation conditions each agent is allowed to use, and enforce them outside the prompt layer.
- Issue dedicated identities per agent role Remove shared credentials across workflows and bind each agent role to a unique service identity with narrow, task-specific access.
- Convert broad tokens to time-bounded access Replace persistent credentials with short-lived tokens for sensitive operations so access expires with the task instead of persisting across sessions.
- Build behavioural baselines for every agent Track normal tool order, data sources, and output patterns per agent so deviation can be flagged before a harmful action completes.
- Inventory shadow agents before production use Create a central registry of agents built by engineering, operations, and business teams, including low-code systems that never passed security review.
Key takeaways
- Agentic AI introduces a non-human identity problem because agents can plan, choose tools, and execute actions at runtime inside enterprise systems.
- Static IAM models struggle because agent behaviour changes with memory, tool access, and session context, which breaks assumptions behind provisioning-time governance.
- Security teams need policy-bound task scope, least-privilege identities, and continuous behaviour tracing to keep agentic AI within controllable limits.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | The article focuses on agents invoking tools outside intended scope. |
| ASI03 — Identity & Privilege Abuse | Over-scoped agent identities are a central risk in the article. | |
| Recommendation — Restrict agent tool access to approved actions and monitor for misuse at runtime. Scope each agent identity to the minimum privileges needed for its role. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Agent access depends on how service identities and tokens are authenticated. |
| NHI-05 — Overprivileged NHI | The article repeatedly warns about broad, inherited permissions for agents. | |
| Recommendation — Harden authentication for agent identities and remove shared credentials. Reduce agent blast radius by replacing broad permissions with task-specific access. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes credentialed proxies and chained actions across systems. |
| Recommendation — Map agent abuse patterns to credential access and lateral movement techniques. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article’s main control theme is runtime access scoping for agents. |
| Recommendation — Continuously validate that agent entitlements match current task scope. | ||
Key terms
- Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
- Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
- Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org