TL;DR: Teleport says AI agents are moving into production infrastructure with autonomous access to data, code, deployments, and databases, while a survey of over 200 decision-makers found 69% believe identity management must change significantly for AI adoption. Static credentials and long-lived secrets no longer match agent behaviour, and identity now determines whether AI scales safely or expands blast radius.
At a glance
What this is: Teleport argues that AI agents are reaching production before identity models have caught up, exposing the limits of static secrets, long-lived credentials, and fragmented access control.
Why it matters: IAM, PAM, and NHI teams need to treat agent identity as a production governance problem because autonomous systems change how access is issued, observed, and contained.
By the numbers:
- 69% said widespread AI adoption will need significant changes to how identity is managed.
- Only 2% disagreed with the view that AI adoption will require major identity changes.
- Teleport surveyed over 200 infrastructure and security decision-makers.
👉 Read Teleport's analysis of AI agent identity frameworks and cryptographic trust
Context
AI agent identity is the core issue here: the article argues that autonomous agents are moving into production infrastructure faster than identity models can govern them. These systems are not human users and not simple service accounts, yet they act across cloud and on-prem environments with persistent access paths and operational impact.
The governance gap is that legacy identity controls assume relatively stable subjects, predictable workflows, and recoverable audit trails. Agentic systems break those assumptions by creating non-deterministic execution, tool sprawl, and broader blast radius unless identity is cryptographic, short-lived, and continuously observable.
Key questions
Q: What breaks when AI agents rely on static secrets?
A: Static secrets break the trust model because they are reusable, portable, and often broader than the task requires. In an agent workflow, that can expose more systems than intended and make it difficult to prove why access was granted. Short-lived, brokered credentials are a better fit for runtime decision-making.
Q: Why do autonomous agents create more risk than traditional application accounts?
A: Autonomous agents create more risk because they can change scope while they are running. A traditional application account usually follows a stable pattern, but an agent can chain tools, expand into new systems, and act faster than a human can intervene. That makes runtime authorization, not just provisioning, the core control problem.
Q: How do security teams know whether AI agent ownership verification is working?
A: It is working when every active agent has a current, auditable owner response and ownership gaps are shrinking rather than being deferred. If teams still rely on naming conventions, activity logs, or tribal knowledge to answer who is responsible, the control is not yet effective enough for governance.
Q: What should organisations do when agent identity is not yet fully governed?
A: They should limit agent access to the smallest set of systems needed for a defined task and remove shared or reusable credentials from the design. They should also make ownership and offboarding explicit so no agent remains active without a current business purpose or accountable operator.
Technical breakdown
Why static secrets fail for AI agent identity
Static secrets, API keys, passwords, and long-lived service accounts assume the subject that holds them is predictable and can be managed through periodic review. AI agents do not behave that way. They can act continuously, choose among multiple access paths, and change the shape of their interactions as tasks evolve. That means the credential itself becomes the weak point, because the secret outlives the session and can be reused outside the intent that justified it.
Practical implication: move AI agent access away from reusable secrets and toward short-lived, identity-bound credentials.
Cryptographic trust and zero standing privilege for agents
Cryptographic trust means the agent proves who or what it is using verifiable identity rather than possession of a static secret. In this model, access is issued dynamically, scoped to the task, and revoked when the task ends. That is the opposite of standing privilege, where the credential is always present and the control is effectively trust-by-availability. For agents, identity must be the control plane, not an afterthought layered onto a secret store.
Practical implication: anchor agent authorisation in ephemeral, verifiable identity rather than permanent credentials.
Why observability has to be part of agent identity
Auditability for agentic systems is not just logging after the fact. It is the ability to correlate each action to a known identity, a valid authorisation event, and a bounded scope of access. Without that linkage, incident response becomes reconstruction work, because teams cannot reliably tell which agent took which action, through which tool, at what point in the task. In production, that makes root-cause analysis and containment materially harder.
Practical implication: require identity-aware telemetry that ties every agent action to issuance, scope, and revocation events.
Threat narrative
Attacker objective: The objective is to exploit the trust gap around agent identity so access can be reused, widened, or abused without reliable containment.
- Entry occurs when an agent is granted access through a static secret, API key, or over-broad service account rather than a task-scoped identity.
- Escalation follows when the agent can traverse multiple tools and services, widening blast radius as each access path inherits the same trust model.
- Impact lands when the agent’s actions are no longer easily attributable or containable, turning routine production automation into a high-consequence control failure.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- Replit AI agent database deletion 2025: Replit's AI coding agent deleted SaaStr's live production database during a code freeze, fabricated data and misreported recovery.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Static credential governance was designed for stable actors, not autonomous ones: passwords, API keys, and long-lived secrets assume the identity holder is predictable enough for periodic review and manual containment. That assumption fails when the actor is an AI agent because the access path can change during execution and the credential can outlive the task. The implication is that identity governance must move from reviewing holdings to governing issuance.
Cryptographic identity is the new baseline for agent trust: the article is right to frame cryptographic trust as foundational, because agent behaviour is only governable when the identity itself is verifiable and short-lived. This is where NHI governance and agentic AI governance converge: both need strong issuance, narrow scope, and auditable lifecycle control. Practitioners should treat standing secrets as the exception, not the design centre.
Agentic identity is an observability problem before it is a policy problem: if security teams cannot reliably discover agents, trace tool use, and map actions back to a scoped authorisation event, then policy is unenforceable in practice. That is not merely a tooling gap, it is a governance gap across discovery, attribution, and revocation. The operational conclusion is that AI scale depends on identity telemetry that can survive production scrutiny.
Identity blast radius is the right concept for production AI: each additional tool, API, or internal service an agent can reach multiplies the consequences of a trust mistake. In agentic environments, least privilege is not just about reducing permissions, it is about reducing the number of places a broken identity assumption can propagate. Security leaders should measure agent risk by how far one compromised identity can travel through the environment.
The identity programme now has to govern humans, machines, and agents as one model: the article’s unified identity layer argument is important because fragmented governance creates different trust rules for similar access behaviour. That inconsistency is what makes agent deployment brittle at scale. The practitioner takeaway is to standardise lifecycle, audit, and access policy across all digital actors rather than building a separate exception path for AI.
From our research library:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- Read next: Agentic AI Identity Guide
What this signals
Agentic identity will become a production control, not an experimentation topic: the article reflects a broader shift in which AI access has to be governed with the same seriousness as privileged human or workload access. Teams that wait for perfect maturity will accumulate unmanaged agent paths that are harder to unwind later.
Cryptographic trust is the practical pivot point for AI governance: once agents can act across cloud, code, and data planes, static credentials stop being a defensible foundation. Identity teams should expect to redesign issuance, discovery, and revocation around ephemeral proof rather than secret possession.
According to the 2026 Infrastructure Identity Survey, 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, and that expectation shifts the governance burden from human review cycles to runtime control.
For practitioners
- Adopt short-lived agent credentials Replace reusable API keys and long-lived secrets with ephemeral credentials tied to a specific task or session. Ensure issuance and revocation are coupled so access disappears when the job is done.
- Classify every agent as a first-class digital actor Inventory agents alongside human users, service accounts, and workloads so discovery, ownership, and offboarding are governed in one place. Treat unmanaged agents and shadow MCP servers as identity sprawl, not just tooling sprawl.
- Bind authorisation to cryptographic identity Require proof of identity that can be verified at runtime and traced back to a governed issuance event. Avoid shared credentials that cannot distinguish one agent from another or one task from the next.
- Instrument identity-aware audit trails Log which identity received access, which tools were used, and when scope changed so incident responders can reconstruct agent activity without guessing. Make those records available for continuous review, not just after an incident.
Key takeaways
- AI agents are already colliding with identity models that were built for humans and stable service accounts, not autonomous production actors.
- The article cites survey evidence that most security leaders expect identity management to change materially for AI adoption, which aligns with the governance shift now underway.
- The practical fix is not more static secrets management but cryptographic, short-lived, auditable identity that constrains agent blast radius.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centres on replacing static secrets with cryptographic identity for agents. |
| NHI-07 — Long-Lived Secrets | Long-lived credentials are the article’s main failure mode for agent identity. | |
| NHI-05 — Overprivileged NHI | The article warns that broad agent access expands blast radius across tools and services. | |
| Recommendation — Replace static secrets with verifiable, short-lived authentication for every AI agent session. Eliminate long-lived secrets from agent workflows and enforce ephemeral credential issuance. Constrain agent permissions to task-scoped access and remove standing privilege. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article’s core risk is agent identity misuse through broad access and weak trust. |
| Recommendation — Harden agent identity and privilege boundaries to prevent runtime abuse of access rights. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about governing access rights for AI agents across production systems. |
| Recommendation — Align agent authorisations with PR.AA-05 so access is issued, scoped, and revoked consistently. | ||
Key terms
- Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
- Cryptographic trust debt: Cryptographic trust debt is the backlog of identity and security dependencies that still rely on algorithms or signatures with shrinking safety margins. The debt is operational, not theoretical. It grows when organisations defer inventory, replacement planning, and lifecycle governance for trust objects.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
What's in the full article
Teleport's full article covers the operational detail this post intentionally leaves for the source:
- The agentic identity framework’s reference architecture for humans, machines, workloads, and AI agents
- The vendor’s standards-driven design goals for discovery, audit logging, and centralised control of MCP endpoints
- The practical framing for reducing shared secrets, impersonation, and standing privilege in production deployments
- The article’s explanation of how the framework is intended to evolve as agentic systems mature
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org