TL;DR: Teleport's 2026 Infrastructure Identity Survey found that 79% of organisations are evaluating or deploying agentic AI, only 13% feel extremely prepared, and 70% grant AI systems more access than humans for the same task. The real gap is governance: identity models built for human-paced review are failing when AI is being promoted into production with broader privilege.
At a glance
What this is: Teleport's survey shows agentic AI adoption outpacing security readiness in infrastructure, with access, visibility, and credential governance emerging as the main identity gaps.
Why it matters: IAM, PAM, and NHI teams need to treat AI systems as governed identities because over-privilege and static credentials are already shaping incident rates and auditability.
By the numbers:
- 79% of organisations are evaluating or deploying agentic AI.
👉 Read Teleport's full report on AI infrastructure identity gaps
Context
Agentic AI in infrastructure means systems that can decide and execute operational changes rather than merely suggest them. The governance problem is that many identity controls still assume a human operator, a stable role, and a review window long enough to catch mistakes before impact.
Teleport's survey frames this as an identity and access issue, not a model-quality issue. Once AI systems are allowed to touch production code, configurations, and sensitive data, the programme question becomes whether access, attribution, and review can keep pace with machine-paced action.
Key questions
Q: What breaks when AI agents are given broad standing access?
A: Broad standing access breaks governance because the agent can move from one task to another without a fresh authorization check. That creates a control gap between intended scope and actual runtime behaviour. The result is weak accountability, limited containment, and audit trails that show activity without explaining why the activity was allowed.
Q: Why do static credentials create more risk for AI agents than for traditional workloads?
A: AI agents execute quickly, can chain actions across systems and may terminate before manual review ever happens. Static credentials remain valid long after the task ends, which means stolen or shared secrets can be replayed outside the intended scope and become a direct path to privileged access.
Q: How do you know if AI access controls are actually working?
A: They are working only if you can answer three questions consistently: which identity accessed the system, which data it touched, and whether that access matched the intended business use. If audit logs cannot produce that chain, the control is partial and the exposure is still active.
Q: Should organisations treat AI agents as NHI or as application automation?
A: They should treat them as governed non-human identities with application behaviour. That framing captures the need for identity, scope, lifecycle, and audit controls while still recognising that agents operate through APIs, tools, and workflows. Pure automation language hides the governance gap.
Technical breakdown
Why agentic AI breaks human-paced access governance
Traditional IAM and PAM controls assume access is requested by a person, approved, and then used within a known business process. Agentic AI changes that pattern because the actor can initiate work, choose actions, and execute changes without waiting for a human in the loop. That creates a timing mismatch: review, certification, and approval controls are designed around slower human decision cycles, while the AI identity may move from decision to action in seconds. In infrastructure environments, that means access policy and operational impact drift apart.
Practical implication: re-evaluate whether your access governance still depends on human review cycles that are too slow for agent-driven execution.
Static credentials and over-privilege amplify AI incident risk
The survey ties AI risk to familiar NHI failure modes such as shared secrets, API keys, passwords, and long-lived tokens. These credentials are easy for AI systems to reuse across workflows, but they also collapse accountability and expand blast radius when the agent is over-privileged. In practice, the problem is not just secret exposure. It is that static credentials let an AI identity operate beyond the narrow task scope that justified the access in the first place.
Practical implication: shift AI access away from reusable secrets and toward tightly scoped, short-lived credentials tied to specific infrastructure tasks.
Identity attribution becomes the control that makes AI governable
A key finding in the survey is that organisations often cannot confidently attribute infrastructure changes to an AI identity. That matters because audit, detection, and accountability all depend on knowing which actor performed the action. Without attribution, teams cannot distinguish human changes from AI changes, cannot measure incident rates accurately, and cannot enforce policy consistently. For infrastructure security, attribution is not a reporting nicety. It is the minimum condition for governance.
Practical implication: instrument AI identities so every configuration change, access event, and tool invocation is attributable to a specific agent instance.
Threat narrative
Attacker objective: The practical objective is to gain enough machine-access and privilege to alter infrastructure, expose secrets, or trigger cascading operational failure with limited detection.
- Entry occurs when AI systems are given production access through static credentials, shared secrets, or over-broad tool permissions.
- Credential access is amplified by long-lived tokens and reusable API keys that allow the agent to keep operating across workflows.
- Escalation follows when the agent is granted more privilege than the task requires, expanding the blast radius of any mistaken or unsafe action.
- Impact appears as faulty configurations, exposed secrets, or infrastructure incidents that are hard to attribute back to a specific AI identity.
Breaches seen in the wild
- JADEPUFFER agentic ransomware 2026: The first documented agentic ransomware used harvested keys, default MinIO credentials and a default Nacos signing key to wipe a database.
- LiteLLM MCP auth bypass 2026: An exploited LiteLLM MCP auth bypass and default sk-1234 master keys let attackers steal AI gateway master and provider API keys.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity governance for AI fails when access is treated as a convenience layer rather than a first-class actor control. Teleport's findings show that organisations are promoting AI into infrastructure faster than they are redesigning the identity model around it. The result is not just more automation, but more unowned access paths, weaker attribution, and privilege granted before governance has caught up. Practitioners should treat AI as an identity problem before they treat it as an operational efficiency problem.
Static credential dependency is the wrong foundation for agentic infrastructure. Passwords, shared secrets, API keys, and long-lived tokens give AI systems broad reach, but they also make scope, revocation, and accountability difficult to enforce. That combination turns a single agentic workflow into a persistent access surface. The practitioner conclusion is straightforward: if the credential can outlive the task, the task can outlive the control.
Least privilege remains the decisive control, but only if it is enforced at issuance time. The survey's 4.5x incident reduction finding is a reminder that privilege scope, not model sophistication, is the variable that changes outcomes. The governance lesson is that AI adoption does not justify broader access by default. Practitioners should constrain the access path before the agent is allowed to act.
Access attribution is the named concept infrastructure teams now need to operationalise. When an AI system can make changes without a stable human operator behind it, audit trails must identify the agent instance, the tool used, and the privilege consumed. Without that chain, review and accountability degrade into guesswork. The practitioner implication is that attribution must be built into the control plane, not reconstructed after an incident.
The access gap between humans and AI signals a broader identity boundary shift. Granting AI more access than humans for the same task shows that many programmes still define trust by convenience rather than by actor type. That weakens zero trust assumptions and complicates both NHI governance and human IAM design. Practitioners should re-check whether their identity architecture distinguishes between who asked, what acted, and what was actually authorised.
From our research library:
- AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.
- Read next: AI Infrastructure Workload Identity Guide
What this signals
Access review is not enough when the actor can move from decision to execution in one session. AI systems that acquire and release privilege quickly can leave little durable state for recertification to inspect. That means identity programmes need stronger issuance-time controls, not just periodic reviews.
Least privilege for AI becomes a boundary-setting discipline rather than a permissions exercise. If an agent can touch production code, data, and infrastructure with the same credential shape, the programme has already expanded the trust boundary too far. The practical question is whether access is being constrained to the task or merely monitored after the fact.
For practitioners
- Reclassify AI systems as governed identities Map every production-capable AI workflow to an identity owner, privilege scope, and review path so it is governed like any other actor that can change infrastructure.
- Replace static secrets with short-lived access Reduce passwords, shared secrets, and long-lived tokens for AI systems by issuing short-lived, task-scoped credentials wherever the workflow allows.
- Tighten least-privilege boundaries for agentic workflows Review whether AI systems have broader access than the human role they assist, then narrow the tool and resource scope to the minimum required for each task.
- Instrument AI attribution in the audit trail Log which agent instance, tool, and credential performed each infrastructure change so incident review can separate human action from AI action.
- Test agentic workflows against incident scenarios Red-team the paths where AI can create confident but wrong configurations, leak secrets, or trigger chained failures before those workflows are promoted to production.
Key takeaways
- Agentic AI in infrastructure is exposing a governance gap between machine-paced action and human-paced identity controls.
- Teleport's survey shows the gap is not theoretical, with 70% of organisations granting AI more access than humans and 79% already evaluating or deploying agentic AI.
- The control that changes the outcome is narrow, attributable, task-scoped access, not broader review after the fact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | AI systems in the article rely on static secrets and long-lived credentials. |
| NHI-05 — Overprivileged NHI | The survey highlights AI systems receiving more access than humans for the same task. | |
| NHI-07 — Long-Lived Secrets | The article links AI incident rates to passwords, shared secrets, API keys, and tokens. | |
| Recommendation — Replace reusable AI credentials with short-lived authentication tied to task scope. Review AI permissions against task scope and remove standing privilege above human equivalent access. Eliminate long-lived secrets from agentic workflows wherever a short-lived credential can replace them. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about how AI access is authorised and limited in production. |
| Recommendation — Apply PR.AA-05 to narrow AI entitlements to the minimum access needed for each workflow. | ||
Key terms
- Agentic AI Identity: The complete set of credentials, permissions, and governance controls applied to an autonomous AI agent, covering authentication, authorisation, action logging, and access revocation. Distinct from traditional NHI because agent identities are often ephemeral, delegated, and multi-hop.
- Access Attribution: Access attribution is the ability to link a data action to a specific human, service account, workload, or agent. It is essential for auditing, investigations, and policy enforcement because controls lose precision when the acting identity cannot be reliably identified.
- Static Credential: A static credential is a long-lived secret such as an API key, password, token, or certificate that exists outside the moment of use. It creates persistent attack surface because it can be copied, stored, reused, and exposed across code, pipelines, configuration files, and third-party environments.
- Privilege Scope: Privilege scope is the set of actions, data, and tools an identity is allowed to use. For AI agents, scope must be defined around the task and the acceptable blast radius, because broad or persistent privileges can turn a small mistake into a production-level incident.
What's in the full report
Teleport's full report covers the operational detail this post intentionally leaves for the source:
- Industry-by-industry incident-rate breakdowns for AI-enabled infrastructure
- Survey methodology and leader sentiment data behind the preparedness findings
- Practical guidance on secretless authentication and short-lived credentials
- Teleport's full discussion of its Agentic Identity Framework and related access patterns
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on May 26, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org