By NHI Mgmt Group Editorial TeamBased on Astrix Security: “Astrix Named in Gartner’s Emerging Tech Impact Radar for Agentic Identity Security” (September 25, 2025)

TL;DR: Gartner’s Emerging Tech Impact Radar places agentic identities in the 1 to 3 year adoption ring with very high mass, according to Astrix Security, while Gartner also projects that 40% of enterprise apps will integrate task-specific AI agents by 2026 and 61% of organisations are already piloting or scaling them. Identity review cycles assume stable principals; autonomous agents break that assumption in-flight.


At a glance

What this is: This is Astrix Security’s commentary on Gartner’s Emerging Tech Impact Radar, which treats agentic identities as a near-term, high-impact enterprise issue and frames identity as the control plane for AI agents.

Why it matters: It matters because IAM, IGA, and PAM teams now have to govern AI agents as first-class principals, with lifecycle, privilege, and audit controls that match their runtime behaviour.

By the numbers:

  • Gartner projects that 40% of enterprise apps will integrate task-specific AI agents by 2026.
  • 61% of organisations are already piloting or scaling AI agents.
  • By 2028, at least 15% of day-to-day work decisions will be made autonomously through agentic AI.

Context

Agentic identities are the identities assigned to AI agents that can perceive, reason, and act inside enterprise workflows. The security problem is that these identities do not behave like static service accounts or like human users, so IAM controls built around stable ownership and predictable review cycles start to lose precision.

Astrix Security’s summary of Gartner’s Radar argues that agentic identities are moving from experimentation into mainstream enterprise planning. For identity teams, that means the control plane has to shift from periodic review of access state to continuous governance of delegated action, scope, and lifecycle.

The practical question is no longer whether AI agents need access, but how that access is scoped, observed, and revoked when the principal can act dynamically at runtime. That is a governance problem for NHI, AI agent, and PAM programmes at the same time.


Key questions

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.

Q: Why do traditional access reviews struggle with agentic systems?

A: Traditional access reviews assume access persists long enough to be observed, certified, and removed on a schedule. Agentic systems can be created dynamically, act continuously, and complete work before a review cycle ever sees a stable entitlement. The result is a governance gap between review cadence and execution speed.

Q: When should organisations move from role-based control to task-based control for agents?

A: Shift when a role no longer predicts the agent’s real behaviour across tools, systems, or data. If the same agent can follow different paths in different sessions, task-based scoping and session-bounded authorisation become more reliable than broad role assignment.

Q: What is the difference between human IAM and machine identity governance?

A: Human IAM assumes a known person, a predictable lifecycle, and interactive authentication. Machine identity governance deals with software credentials that operate continuously, often lack clear ownership, and can be copied or reused across systems. The control model must therefore emphasize discovery, privilege scope, and behavior monitoring.


Technical breakdown

Why agentic identities stress existing IAM models

An agentic identity is a governable identity assigned to software that can make runtime decisions and take actions on behalf of a workflow or user. Unlike a conventional workload identity, the agent may change what it does from one session to the next, which means entitlement design cannot rely only on a static role definition. That creates a mismatch between identity governance and execution reality. Review, certification, and approval models assume access remains stable long enough to be observed and attested. Practical implication: identity teams need to treat the agent’s effective permissions, not just its assigned role, as the governance object.

Practical implication: Model and govern the agent’s effective permissions, not only the assigned role.

How least privilege changes for AI agents

Least privilege for agents is not just about reducing scope. It has to account for task-specific access, short-lived credentials, and whether the agent can chain tools or actions in ways the original approver did not explicitly foresee. That is why identity-first controls increasingly pair JIT access with session-bounded authorisation and action logging. The challenge is not simply volume of access, but how access is composed during execution. Practical implication: IAM and PAM teams should assess whether the agent can expand its own practical reach through delegated actions even when the nominal role looks narrow.

Practical implication: Check for delegated action chains that expand reach beyond the nominal role.

Why lifecycle governance matters for autonomous access

Agentic identity governance depends on provision, rotation, revocation, and offboarding working as a complete lifecycle rather than a one-time setup. If an agent can be created quickly but not revoked cleanly, or if its permissions are never revalidated against current use, the governance model becomes stale almost immediately. This is especially important where agents operate across SaaS, IaaS, and internal systems, because the permission surface is fragmented. Practical implication: lifecycle management for agents must be continuous and system-aware, not limited to onboarding controls.

Practical implication: Make revocation, revalidation, and offboarding part of the agent lifecycle from day one.


NHI Mgmt Group analysis

Agentic identities are not just another NHI category. They are a governance forcing function that exposes where identity programmes still assume predictable human or service-account behaviour. Once an identity can decide and act at runtime, the control plane has to shift from static assignment to continuous authorisation and observation. The implication is that agent governance becomes a core IAM design problem, not a side project for emerging technology teams.

Identity review cycles built for stable principals break under agentic execution. Access certification assumes that privilege persists long enough to be reviewed, challenged, and recertified. AI agents can acquire and discard access within the same task path, which means the review artefact may never exist in a useful form. The implication is that governance has to move closer to issuance time and session boundaries.

Agentic identity creates a new form of privilege elasticity. A single agent may touch multiple systems, tools, and data sets through delegated actions that look narrow on paper but expand in practice. That makes effective access harder to reason about than assigned access. The implication is that organisations need to govern transitive permission paths, not just the initial entitlement record.

Managed agent identity is becoming a prerequisite for scaling AI safely. Gartner’s framing shows the market moving toward first-class treatment of AI agents as governed principals, not informal automation. That pulls IAM, PAM, and security engineering into the same operating model. The implication is that teams should expect agent identity control to become part of standard enterprise architecture, not an optional overlay.

Ephemeral credential trust debt: the core design problem is that short-lived access only helps when the surrounding governance can still explain who approved it, what it was used for, and when it ended. Agentic systems make that chain harder to reconstruct because action can be both delegated and autonomous. The implication is that auditability must be built into the identity model, not bolted on after deployment.

From our research library:

What this signals

Agentic identity governance will shift control from review to issuance. Governance programmes built on access review cadences assume that privilege persists long enough to be certified. When the actor is autonomous or semi-autonomous in practice, that window collapses to within-session, so the control has to move closer to provisioning and runtime observation.

AI agent adoption is now an architecture issue, not an innovation experiment. Gartner’s projection that 40% of enterprise apps will integrate task-specific AI agents by 2026 means identity teams should expect more delegated access paths, more acting-on-behalf chains, and more pressure to prove who authorised what.

Identity blast radius becomes the new design variable. As agentic workloads spread, practitioners should assume that the most important control question is no longer whether access exists, but how far it can travel once an agent begins to act across systems. That is where IAM, PAM, and audit discipline intersect.


For practitioners

  • Define agent identities as governed principals Inventory AI agents as distinct identities, not as unnamed automation, and record ownership, purpose, tool scope, and revocation authority for each one.
  • Bind access to task scope and session duration Use JIT access, short-lived scopes, and explicit session boundaries so an agent cannot accumulate standing privilege across unrelated work.
  • Log effective permissions and acting-on-behalf chains Capture what the agent actually touched, which delegated actions it took, and which upstream identity authorised the chain for audit and forensics.
  • Rework recertification for non-stable principals Move from periodic recertification of assigned roles to continuous checks on whether the agent still needs each permission for its current task and system context.
  • Apply layered guardrails to high-risk actions Add policy constraints, data-level controls, and human approval gates around destructive or irreversible actions even when the agent has valid identity and scope.

Key takeaways

  • Agentic identities force IAM teams to govern software principals that can decide and act at runtime, not just authenticated users and static service accounts.
  • The article frames AI agents as moving quickly from pilot to production, which makes lifecycle, privilege, and audit design an immediate programme issue.
  • Controls that stop at role assignment will miss effective access paths unless teams also govern task scope, delegated actions, and revocation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI agents gaining and using delegated access beyond static IAM assumptions.
ASI02 — Tool MisuseThe post discusses agents acting through tools and guardrails that constrain those actions.
Recommendation — Map agent access paths to ASI03 and restrict delegated privilege to task-scoped authorisation. Limit tool access and validate each tool invocation against task scope before execution.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article repeatedly warns against standing access and broad entitlements for AI agents.
NHI-07 — Long-Lived SecretsAstrix recommends short-lived scopes and JIT controls to avoid persistent credentials for agents.
Recommendation — Review agent entitlements for overprivilege and remove any standing access that exceeds task need. Replace long-lived agent secrets with short-lived credentials and revoke them when tasks end.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governing AI systems that can act in enterprise workflows.
Recommendation — Establish governance roles, accountability, and approval boundaries for agent identity use.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe post focuses on permissions, entitlements, and authorization boundaries for agent identities.
Recommendation — Continuously verify agent entitlements and remove excess permissions that are not needed for current tasks.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementStanding or overbroad agent access can enable credential abuse and movement across systems.
Recommendation — Hunt for agent access patterns that enable credential access and lateral movement across connected systems.

Key terms

  • Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
  • Effective Permissions: Effective permissions are the access an identity can actually use after role inheritance, scope, and policy are applied. In Azure AI environments, they often matter more than the assigned role name because inherited rights can widen access to data, logs, and secret stores.
  • Acting-on-behalf-of chain: An acting-on-behalf-of chain is the sequence of identities and delegated permissions that lets one principal act through another. For AI agents, this chain matters because it determines who is actually responsible when access is reused, expanded, or misapplied during runtime execution.
  • Session-bound authorisation: Authorisation that follows a verified runtime session rather than a process name or static allowlist. In agentic environments, it means the actor must prove identity at execution time before tool use or network access is granted, which is stronger than trusting the binary path alone.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org