By NHI Mgmt Group Editorial TeamBased on SailPoint: “EIC 2026” (April 29, 2026)

TL;DR: AI agents are being treated as first-class digital actors, but human-centric identity models still struggle to validate intent, ownership, and accountability across autonomous actions, according to SailPoint’s EIC 2026 session agenda. The practical issue is not whether agents exist, but whether governance can keep up with their evolving access patterns and synthetic identity risks.


At a glance

What this is: This is a conference session agenda centred on AI agent governance, with the key finding that human-centric identity models do not cleanly fit autonomous actors.

Why it matters: It matters because IAM, IGA, and PAM teams will need to govern intent, ownership, and accountability for AI agents as distinct identity subjects, not as repackaged service accounts.


Context

AI agent governance is the set of controls used to decide what an autonomous actor is allowed to do, who owns it, and how its actions are trusted. In this article, the problem is not raw automation, but the mismatch between agent behaviour and identity models built for people and static service accounts.

SailPoint frames the topic through two conference sessions at EIC 2026 in Berlin on May 19 to 22. The underlying governance gap is broader than a single event agenda: once agents can act across systems on their own, identity programmes need a way to validate purpose, ownership, and operational scope continuously.

The article also uses a space-debris analogy to show how uncontrolled launches create accumulated risk when intent is unclear. That analogy is typical of the broader AI agent governance debate, where the same questions now apply to synthetic actors inside enterprise identity estates.


Key questions

Q: What breaks when AI agents are treated like standard human users?

A: You lose visibility into effective permissions, expected behaviour, and real blast radius. Human-centric controls can misclassify normal agent activity as compromise, or miss policy violations that happen entirely within legitimate access. The failure is not only technical, it is governance design that assumes a person is always behind the action.

Q: Why do autonomous AI systems create accountability problems for IAM teams?

A: Autonomous AI systems create accountability problems because they can initiate actions, chain tools, and make decisions without a stable human operating moment behind each step. Traditional IAM assumes the actor, the request, and the decision can be linked cleanly. When that chain becomes machine-paced, accountability has to be designed into identity, logging, and policy enforcement.

Q: How should security teams handle synthetic identities in hiring and access workflows?

A: Security teams should treat synthetic identities as a trust-issuance problem, not just a hiring fraud problem. Pre-hire checks can reduce obvious falsehoods, but they do not stop commodity attackers who can iterate documents and interview scripts. Pair hiring verification with a separate access approval step and post-hire behavioural monitoring.

Q: What is the difference between agent identity and service account access?

A: Service account access identifies a technical credential, while agent identity should identify the autonomous actor, its owner, and its permitted intent. If multiple agents share the same service account, you lose attribution and containment. A real agent identity model makes each action traceable and each privilege boundary enforceable.


Background and context

Why intent becomes the hard control point for AI agents

Agent governance starts with intent because autonomous behaviour can no longer be treated as a simple extension of the human request that initiated it. If an AI agent can perform tasks, make decisions, and interact across systems, then purpose, ownership, and current control all affect whether the action should continue. That is different from classic IAM, where authentication proves who the subject is and authorization decides what it may do. Here, the subject’s behaviour can change within the session. The governance challenge is not just identity binding, but proving that the current action still matches the approved purpose.

Practical implication: align approval, logging, and policy evaluation to the agent’s current purpose, not only to its original provisioning record.

Synthetic identities need more than authentication

The article’s “machines with identities” framing reflects a basic shift: an AI agent is not just a workload calling an API, but a digital actor whose actions may be autonomous and multi-step. That means authentication alone is insufficient if the system cannot distinguish a legitimate synthetic identity from an agent acting outside its intended role. Identity assurance for agents has to account for origin, ownership, delegated scope, and runtime behaviour. In practice, that pushes teams toward stronger lifecycle controls, tighter attestation of agent provenance, and policy decisions that are aware of the actor type rather than assuming all non-human access is equivalent.

Practical implication: treat agent authentication as one control in a broader identity model that also covers provenance, ownership, and behavioural scope.

Why human-centric governance breaks under autonomous decision-making

Human-centric governance assumes a stable person behind each access path, with accountability anchored in employment, role, and review cycles. Autonomous agents break that premise because the actor can initiate, sequence, and complete actions without a human making each step. That turns standard review models into lagging controls that may never observe the risky behaviour in time. For AI-native environments, identity governance has to move closer to issuance and runtime policy enforcement, because the usual assumptions about predictable access patterns no longer hold. This is where agentic identity diverges from ordinary machine identity.

Practical implication: redesign governance around runtime policy and delegated scope, not around periodic review of static access lists.


NHI Mgmt Group analysis

AI agent governance fails first at the level of identity assumptions, not just control coverage. Human-centric models assume a stable person, a stable role, and a reviewable action trail. Once the actor can decide and act autonomously, that model no longer describes the system accurately. The implication is that agent governance must be treated as a distinct identity discipline, not a cosmetic extension of IAM.

Purpose is becoming the new policy object for agentic identity. The article’s space-orbit analogy is useful because it shows how uncontrolled launch decisions create lasting downstream risk when intent is unclear. In AI environments, purpose, creation, ownership, and operation all need to remain attached to the actor as it executes. Practitioners should think of purpose drift as an identity problem, not only a workflow problem.

Machine identities and AI agents are converging, but they are not governed the same way. A service account usually follows a bounded pattern of access, while an AI agent can alter how it uses that access as the task unfolds. That means the control issue is not only privilege scope, but behavioural elasticity. The implication is that governance programmes must distinguish between static machine access and autonomous execution rights.

Accountability for AI agents will not be solved by human review cycles alone. If an agent can act, hand off, retry, and chain actions before a reviewer intervenes, then accountability has to be enforced in the control plane that issues and constrains those actions. This is where the field moves from access certification to action certification. Practitioners need governance models that can attribute decisions to the current agent state, not just to the sponsoring human.

Adaptive identity will become the market default for AI-native estates. The conference sessions point toward a future where identity systems must continuously reassess trust rather than preserve it once granted. That direction is consistent with the broader shift from static provisioning to runtime control across autonomous systems. Identity leaders should expect AI agent governance to merge lifecycle, policy, and behaviour into one operational model.

From our research library:

What this signals

Adaptive identity is becoming the governance layer for autonomous actors. AI agent programmes cannot rely on the same review cadence used for people, because the actor can change actions faster than certification cycles can observe. That pushes practitioners toward purpose-aware policy, continuous validation, and lifecycle controls that follow the agent through its runtime decisions.

Purpose drift will matter as much as privilege creep. In agentic environments, the risk is not only that access becomes too broad, but that the task itself mutates while the system is still executing. Teams should expect identity architecture to absorb this new control problem by tying authorisation to current intent, ownership, and execution context.

70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey. That gap shows why agent governance must be built as a separate discipline rather than a human IAM exception.


For practitioners

  • Define agent ownership and purpose records Record who sponsors each AI agent, what task boundary it is meant to operate within, and which systems it may touch. Keep that record tied to policy evaluation so changes in purpose trigger review.
  • Separate agent identities from human users Do not let synthetic actors inherit human assumptions from access reviews, recertification, or delegated approvals. Model them as distinct identity subjects with their own lifecycle and control boundaries.
  • Apply runtime controls to autonomous actions Enforce policy at execution time, not only at provisioning, so the agent’s current behaviour is checked against its approved scope before it reaches sensitive systems.
  • Instrument agent activity for audit and response Capture action traces, ownership changes, and system interactions so governance teams can investigate what the agent did and why it was allowed to do it.

Key takeaways

  • AI agents expose a governance gap because identity models built for humans do not adequately describe autonomous behaviour or changing intent.
  • The article’s space-orbit analogy is really about accumulated control debt, where unmanaged purpose creates lasting risk across an identity estate.
  • Practitioners need runtime policy, explicit ownership, and separate lifecycle treatment for synthetic actors if they want accountability to hold.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI agents needing distinct identity and privilege controls.
Recommendation — Apply ASI03 to separate agent privileges from human roles and enforce autonomous access boundaries.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article discusses authenticating synthetic actors and validating their trust state.
NHI-10 — Human Use of NHIHuman-centric governance assumptions are the core gap in the article's argument.
Recommendation — Use NHI-04 controls to validate synthetic identities before granting agent access to systems. Prevent human governance shortcuts by assigning each agent its own identity, ownership, and lifecycle.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about governance and accountability for autonomous AI actors.
Recommendation — Establish AI governance roles and accountability checkpoints for every agentic deployment.
NIST Zero Trust (SP 800-207)Section 3 — Continuous VerificationThe article argues for runtime trust decisions instead of static access assumptions.
Recommendation — Shift agent trust decisions to continuous verification rather than one-time provisioning.

Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.
  • Permission Drift: Permission drift is the gradual expansion of access beyond what was originally intended. It happens when roles, tokens, and service accounts accumulate unused rights over time, making cloud identities harder to review and more dangerous to compromise.
  • Adaptive Identity: An identity governance approach that changes access decisions as context changes. Instead of relying only on fixed review cycles, it uses current risk, role, behaviour, and application sensitivity to decide whether access should continue, be reduced, or be revoked.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on May 14, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org