By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: DescopePublished August 3, 2026

TL;DR: Gartner’s 2026 fraud and financial crime Hype Cycle places CIAM for AI Agents in the On the Rise phase and Journey-Time Orchestration in Early mainstream, with both categories carrying High benefit ratings, according to Descope. The signal is that agent delegation, consent, and journey-level risk controls are becoming core identity problems, not side features.


At a glance

What this is: This is Descope’s analysis of Gartner’s 2026 fraud and financial crime Hype Cycle, with the key finding that CIAM for AI Agents and Journey-Time Orchestration are now central to fraud and financial crime prevention.

Why it matters: It matters because IAM teams now have to govern delegated agent access, customer consent, and continuous risk decisions across both human and software-initiated journeys.

By the numbers:

👉 Read Descope’s analysis of CIAM for AI agents and journey-time orchestration


Context

AI agent identity in fraud prevention means treating software that acts on a customer’s behalf as an identity subject, not just a tool. The governance gap is that traditional CIAM assumes a person is directly present for authentication, consent, and step-up decisions, while agentic flows insert delegation and runtime action on top of that model.

Descope’s article uses Gartner’s 2026 Hype Cycle as the trigger for a broader point: fraud controls are shifting from one-time login checks to journey-level orchestration and delegated-agent governance. For banks and financial services teams, the practical problem is no longer only who logged in, but what an agent was allowed to do, when, and under whose authority.

That is a typical direction of travel for financial institutions experimenting with AI-assisted or agent-assisted customer journeys. The article argues that agentic identity and journey orchestration are moving from adjacent capabilities to core controls, which is consistent with how fraud teams tend to adopt identity controls once transaction speed and automation raise the cost of static checks.


Key questions

Q: How should security teams handle delegated access when AI agents act on behalf of customers?

A: Security teams should treat delegated access as a separate governance layer, not as a normal login session. Define what the agent can do, how much value it can move, which approvals are required, and how delegation is revoked. Without those boundaries, the agent inherits more authority than the customer intended and fraud risk expands quickly.

Q: Why do journey-level controls matter more than a single login check in fraud prevention?

A: Because modern fraud often emerges after the initial authentication event. A session can start clean and later become risky as the user moves through registration, account recovery, payment, or device trust steps. Journey-level orchestration lets teams change the control response as the risk changes, instead of relying on one static checkpoint.

Q: What breaks when an AI agent is not part of identity inventory?

A: When an AI agent is not part of identity inventory, governance breaks at the point of discovery. Teams cannot reliably answer who owns the agent, what credentials it uses, or what systems it can reach. That makes access review, offboarding, and incident response incomplete because the trusted entity was never formally brought under control.

Q: Who is accountable when an AI agent uses delegated access incorrectly?

A: Accountability should follow the delegated authority chain, not stop at the agent label. The relevant owners are the teams responsible for the human identity, the service identity, the workflow, and the policy that allowed the action path. If those responsibilities are not explicit, incident review will be incomplete and remediation will focus on the wrong layer.


Technical breakdown

CIAM for AI agents and delegated identity binding

CIAM for AI agents extends customer identity and access controls to software that transacts on behalf of a customer. The hard part is binding the agent to the customer’s authority without handing over reusable credentials. In this model, authentication, authorization, consent, and revocation must all work at the agent level, not just the human account level. That creates a different control problem from standard CIAM because the actor can initiate actions continuously during a session, and each action may need a different scope. Practical implication: identity teams need a delegated-access model that preserves customer attribution and scope boundaries across every agent action.

Practical implication: identity teams need a delegated-access model that preserves customer attribution and scope boundaries across every agent action.

Journey-Time Orchestration as a control plane for fraud decisions

Journey-Time Orchestration is the coordination layer that lets identity, risk, and user experience decisions happen across the whole digital journey rather than at a single login checkpoint. It ties together identity verification, authentication, account takeover prevention, and step-up logic so the response can change as risk changes. For fraud teams, that matters because static thresholds create blind spots when a session starts clean and becomes risky later. The architectural point is not just centralisation, but sequence-aware decisioning. Practical implication: security teams should design journey logic around event-by-event risk evaluation instead of treating authentication as a single event.

Practical implication: security teams should design journey logic around event-by-event risk evaluation instead of treating authentication as a single event.

Model Context Protocol and agentic session control

The article’s agentic identity discussion also points to the need for controlled tool access when agents interact with systems through structured interfaces such as MCP. MCP is useful because it standardises how agents reach tools and data sources, but that also makes authorisation more consequential. If an agent can use a tool, the question becomes which identity bound that access, what scopes were granted, and how the session is monitored for drift. In practice, the risk is not only account takeover, but delegated misuse inside an approved session. Practical implication: teams should treat tool access, consent, and monitoring as one policy chain.

Practical implication: teams should treat tool access, consent, and monitoring as one policy chain.


NHI Mgmt Group analysis

CIAM for AI agents is the market’s answer to delegated action, but it also exposes how fragile human-centric identity assumptions have become. The article is right to frame agentic identity as a fraud problem because the real issue is not authentication alone, but the binding of a customer to an autonomous or semi-autonomous actor that can keep acting after the initial login. That changes the control surface from session start to session behaviour. Practitioners should treat this as a new identity class with its own lifecycle, consent, and revocation model.

Journey-Time Orchestration is becoming the practical control layer for fraud because identity decisions now need to follow the user journey, not just the login event. Traditional CIAM stacks often segment verification, authentication, and ATO prevention into separate tools that do not share state well enough to respond to changing risk. JTO matters because it turns those separate checks into a policy sequence. The implication is straightforward: fraud teams need orchestration that can react to context shifts without forcing every decision through a fixed authentication checkpoint.

Agentic identity makes the delegation chain itself the security problem, not just the endpoint account. Once a customer authorizes an AI agent, the meaningful unit of control becomes the customer-agent binding, the agent’s scopes, and the tool permissions inside the session. That is where account takeover, data exposure, and unauthorized action can emerge even when the human account remains intact. IAM teams should evaluate whether their current controls can represent that chain clearly enough to govern it.

Identity and fraud teams are converging on the same governance model because both now need continuous authorisation, not static access decisions. Fraud prevention has always cared about risk signals, but agentic AI turns risk into a runtime identity question. The named concept here is delegated-action binding: the requirement to prove which customer authorised which agent, for which action, under which limits. Practitioners should recognise that this is becoming a core design pattern for customer identity, not a niche agent feature.

From our research:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
  • The governance lesson extends beyond fraud journeys: review Ultimate Guide to NHIs , 2025 Outlook and Predictions for the broader NHI risk trajectory.

What this signals

Delegated-action binding: the next identity control problem is proving which customer authorised which agent, with what scope, and for how long. Once teams accept that boundary, CIAM, consent, and fraud telemetry stop being separate projects and start becoming one policy system. That is the architecture shift practitioners should prepare for.

With 92% of organisations already exposing NHIs to third parties, the challenge is no longer only customer identity, but the trust chain behind every delegated action. For financial services teams, that means agent identity, third-party access, and revocation discipline need to be designed together rather than managed in separate programmes.


For practitioners

  • Define delegated-agent identity classes Create a separate policy model for AI agents acting on behalf of customers so their scopes, consent, and revocation rules do not inherit human-user defaults. Use customer-agent binding as the unit of audit and offboarding.
  • Map journey-level risk checkpoints Identify where identity verification, authentication, ATO prevention, and step-up checks occur today, then document where those controls fail to share state across the digital journey. Rework the sequence so risk can change the response mid-session.
  • Separate tool access from account access When agents reach back-end tools or APIs, make sure tool scopes are explicitly tied to the agent identity and not only to the underlying customer account. That reduces the chance that delegated access becomes reusable privilege.
  • Test consent and revocation in live flows Validate that user consent can be narrowed or revoked after an agent has already begun acting, and confirm that the enforcement path actually blocks further actions. The control is only real if revocation is effective during the active session.

Key takeaways

  • CIAM for AI agents is turning delegated software action into a first-class identity problem for fraud teams.
  • Journey-Time Orchestration matters because risk now changes during the session, not only at login.
  • Practitioners should govern customer-to-agent binding, scope, and revocation as one control chain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10Agent identity binding and tool access are central to the article's threat model.
NIST AI RMFGOVERNThe article concerns governance of AI-enabled identity and fraud controls.
NIST CSF 2.0PR.AC-4Delegated access and least privilege are central to CIAM for AI agents.
NIST Zero Trust (SP 800-207)Continuous verification and dynamic access decisions match the journey orchestration model.
NIST SP 800-53 Rev 5IA-5Agent credentials and tokens need explicit lifecycle control.

Use continuous verification for agent-driven journeys instead of relying on a single login decision.


Key terms

  • CIAM for AI Agents: Customer identity and access management extended to software agents that act on a customer’s behalf. The model must bind the agent to the customer, define scopes, support consent, and make revocation effective across the full session.
  • Journey-time orchestration: Journey-time orchestration is the ability to change authentication and access flows while the user session is in motion, without rewriting application code. It lets identity teams adjust methods, risk checks, and branch logic based on context, which is especially useful in CIAM environments.
  • Delegated-Action Binding: The governance link that proves which customer authorised which agent, for which actions, and under what limits. It is the identity control that preserves attribution when software, not a person, is carrying out part of the journey.
  • Agentic Session: A session in which an AI agent can perform actions on behalf of a user within defined boundaries. Unlike a normal login session, the meaningful control point is the combination of consent, scope, and runtime monitoring rather than the initial authentication alone.

What's in the full article

Descope’s full article covers the operational detail this post intentionally leaves for the source:

  • Gartner category breakdowns for CIAM for AI Agents and Journey-Time Orchestration in the 2026 Hype Cycle.
  • The article’s own examples of how Descope structures agent registration, consent, and per-agent scope control.
  • The journey orchestration details behind risk-aware user flows, including the role of third-party risk signals.
  • The specific product mapping between the Gartner categories and the Agentic Identity Hub architecture.

👉 Descope’s full post covers the Gartner category details, agent identity model, and fraud-control implications.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org