By NHI Mgmt Group Editorial TeamBased on Strata Identity: “The AI Agent Identity Crisis: New Research Reveals a Governance Gap” (February 5, 2026)

TL;DR: Only 18% of security leaders are highly confident their current IAM systems can manage agent identities, while 23% have a formal strategy and 40% are increasing identity and security budgets to address AI agent risks, according to Strata Identity. The real gap is that autonomous agents expose an identity model built for stable, reviewable access, not runtime decision-making.


At a glance

What this is: This analysis says enterprise IAM is lagging behind AI agent adoption, with low confidence, fragmented ownership, and heavy reliance on static credentials and shared service accounts.

Why it matters: IAM, IGA, and PAM teams need to rethink governance for autonomous systems because the current model still assumes access is stable enough to inventory, review, and certify after the fact.

By the numbers:

  • Only 18% of security leaders are highly confident their current IAM systems can effectively manage agent identities.
  • Only 23% of organisations have a formal, enterprise-wide strategy for agent identity management.
  • 40% of organisations are increasing their identity and security budgets specifically to address AI agent risks.
  • 44% use static API keys, 43% rely on username and password combinations, and 35% use shared service accounts to authenticate agents.

Context

AI agent identity governance is the control gap that appears when autonomous systems are given access to business resources faster than identity programmes can define how they should be authenticated, authorised, traced, and owned. The issue is not just adoption volume. It is that the access model for agents is being improvised with human credentials, static API keys, and shared accounts.

Strata Identity's survey of 285 IT and security professionals shows a programme-level mismatch between agentic workflows and legacy IAM assumptions. Agents operate continuously across clouds, on-premises environments, and multiple platforms, so the old review-and-certify model does not provide enough real-time governance for AI agent identity.

The practical consequence is stalled production use, fragmented accountability, and weak audit readiness. When identity ownership is unclear and runtime decisions happen faster than human review cycles, security leaders are left managing agent risk with controls designed for stable non-human identities, not autonomous behaviour.


Key questions

Q: What breaks when AI agents inherit human IAM controls?

A: Human IAM controls break because they assume a person makes a request, waits, and can later be reviewed or deprovisioned. AI agents can chain actions, spawn downstream agents, and complete tasks faster than review cycles can observe. The result is weak attribution, stale privilege, and revocation paths that are too blunt to contain one actor cleanly.

Q: Why do static credentials create more risk for AI agents than for traditional workloads?

A: AI agents execute quickly, can chain actions across systems and may terminate before manual review ever happens. Static credentials remain valid long after the task ends, which means stolen or shared secrets can be replayed outside the intended scope and become a direct path to privileged access.

Q: How do security teams know if agent governance is actually working?

A: It is working only if the team can answer three questions quickly for any agent: what it can reach, what it did recently, and whether that behaviour matches intent. If any of those answers require manual reconstruction, governance exists on paper but not in operations.

Q: Should organisations prioritise runtime authorization over traditional access reviews for agents?

A: Yes, when the actor can request, use and release access faster than a review cycle can observe it. Traditional access reviews still matter for governance, but they cannot be the primary control for autonomous execution that changes state within a single task.


Technical breakdown

Why static credentials fail for autonomous agents

Static API keys, usernames and passwords, and shared service accounts are durable credentials. They work when the identity is expected to behave predictably and within a narrow blast radius, but they become brittle when an agent operates continuously, spans environments, and makes runtime decisions. The problem is not only secrecy. It is that the same credential can be reused across workflows, platforms, and policy domains without preserving context. That creates weak traceability, coarse authorisation, and a control plane that cannot distinguish one autonomous action from another. In NHI terms, the identity is over-reusable and under-governed.

Practical implication: replace persistent credential patterns with per-session, traceable authentication and tighter authorisation boundaries for agents.

What continuous agent activity does to IAM review models

Traditional IAM review assumes access is long-lived enough to inventory, certify, and revoke on a schedule. Autonomous agents break that assumption because their activity is continuous and can span multiple systems at once. Even if a team can log the access, the review happens after the decision, not at the moment of use. That means governance based on periodic attestation, access reviews, or manual approvals will always trail the behaviour it is meant to control. The architectural issue is not a missing report. It is a control model that treats identity as static when the subject is dynamic.

Practical implication: move governance checkpoints into the access path instead of relying on post-hoc recertification.

How human-in-the-loop controls change the authorisation model

Human-in-the-loop oversight only works when there is a defined pause point where the system can seek consent before a sensitive action. For AI agents, that requires policy-defined thresholds, real-time visibility, and traceability back to a human sponsor. Without those elements, HITL becomes a vague expectation rather than an enforceable control. The result is a split governance model in which the agent can still hold access while the human is asked to approve outcomes too late to matter. For identity architects, the issue is not whether humans should remain in the loop. It is where the loop is enforced and whether it is technically real.

Practical implication: define mandatory approval points before high-impact actions, then enforce them with technical policy rather than workflow intent.


Threat narrative

Attacker objective: The end state is uncontrolled autonomous access that can expose sensitive data, trigger unauthorised actions, and obscure accountability across the agent estate.

  1. Entry begins when organisations authenticate agents with static API keys, shared service accounts, or username and password combinations that were never designed for autonomous runtime use.
  2. Escalation occurs as those credentials are reused across clouds, on-premises systems, and multiple platforms, making traceability to a human sponsor incomplete and accountability fragmented.
  3. Impact follows when nearly 80% of organisations deploying autonomous AI cannot tell in real time what the systems are doing or who is responsible for them.
  • Meta Muse agent hijack 2026: An undocumented Muse setting let local malware hijack Meta's personal AI agent, steal its authentication material and abuse user access.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI agent identity governance is exposing an ownership gap, not just a tooling gap. Only 23% of organisations have a formal, enterprise-wide strategy for agent identity management, which means the governance problem is already organisational before it is technical. Security, IT, and emerging AI security functions are sharing responsibility without clear lifecycle ownership, so the control failure starts at accountability. Practitioners should treat agent identity as a programme-owned discipline, not an emerging side issue.

Access review processes assume access persists long enough to be reviewed, and that assumption fails for autonomous agents. The traditional IAM model is built around stable entitlements, but agents operate continuously and can obtain, combine, and use access across environments in ways that outpace periodic review. That means recertification no longer captures the real decision point. The implication is a governance reset toward issuance-time control and runtime traceability.

Static credential dependency is creating identity debt for agentic programmes. When 44% of organisations use static API keys and 35% still rely on shared service accounts, the estate inherits reuse, weak attribution, and persistence risks that do not scale with autonomous behaviour. This is more than poor hygiene. It is a structural trust debt that compounds as agent adoption grows. Practitioners should treat credential reuse as an indicator that the agent programme is not yet governable.

Runtime authorisation is now the decisive control surface for agent risk. The article shows that 69% want human validation before agents access sensitive data and 68% before system changes, which tells us organisations understand the need for gated execution even if they cannot yet implement it cleanly. The governance question is no longer whether to approve agent actions, but where policy enforcement must sit to make approval technically enforceable. Teams should re-centre control design on runtime policy, not downstream review.

Agentic AI adoption is being constrained by the lack of a usable identity operating model. The reported concern set, including sensitive data exposure, unauthorised actions, credential misuse, and inability to discover agents, shows that the market still lacks a stable pattern for governable autonomy. This will push identity teams toward architectures that unify authentication, traceability, and policy orchestration. Practitioners should expect agent governance to become a core IAM design criterion, not an add-on.

From our research library:

What this signals

Agent identity will keep outpacing traditional IAM until governance moves into the runtime path. The critical mismatch is not awareness but timing. Access review cadences assume entitlements persist long enough to be examined, yet autonomous systems can use and release access inside the same operational window, so programme design has to shift toward issuance-time control and continuous traceability.

Identity debt is the better way to describe this problem than identity shortage. Organisations already have credentials, policies, and control planes, but they are applying them to agents that do not behave like human users or classic service accounts. The result is not a lack of tooling alone, but a mismatch between the lifecycle the control expects and the lifecycle the agent actually follows.

Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security. according to the 2026 Infrastructure Identity Survey That gap signals an adoption curve where governance is still catching up to operational reality, so identity teams should expect pressure to formalise ownership, visibility, and enforcement before scale increases further.


For practitioners

  • Define an agent identity owner Assign explicit accountability for each agent class across Security, IT, and AI teams so ownership does not dissolve into informal practice.
  • Replace shared credentials with traceable issuance Remove shared service accounts, static API keys, and reused passwords from agent workflows where possible, then issue identities that preserve sponsor attribution and session context.
  • Insert policy gates before sensitive actions Require technical approval points before agents access sensitive data, modify systems, or approve financial transactions, and make those gates enforceable in the control path.
  • Build a real-time agent inventory Track active agents, their environments, and their human sponsor in a continuously updated register so discovery is no longer dependent on periodic review.
  • Measure governance readiness before production scale-up Test whether your current identity stack can attribute actions, enforce consent thresholds, and survive compliance review before expanding agentic workloads.

Key takeaways

  • AI agent programmes are running ahead of the identity governance model that is meant to control them.
  • The biggest operational weakness is not just low confidence, but the continued use of static and shared credentials for autonomous workflows.
  • Runtime policy enforcement, human sponsorship, and real-time traceability are the controls that determine whether agentic adoption can move into production.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on agent identities using excessive or poorly governed access.
Recommendation — Apply ASI03 to constrain agent privileges and enforce runtime checks before sensitive actions.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article shows agents authenticated with static keys, passwords, and shared accounts.
NHI-05 — Overprivileged NHIAgents operate with access that is broad enough to span multiple platforms and workflows.
NHI-10 — Human Use of NHITeams are sharing human credentials and relying on human-in-the-loop approvals to govern agents.
Recommendation — Replace insecure agent authentication methods with traceable, policy-bound identity issuance. Reduce agent entitlement scope and align every credential to a specific task boundary. Separate human and agent authentication paths and avoid reusing human credentials for autonomous workflows.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe core governance issue is uncontrolled agent authorisation across environments.
Recommendation — Map agent entitlements to PR.AA-05 and verify they are enforced at the point of access.

Key terms

  • AI Agent Identity Governance: AI Agent Identity Governance is the set of policies, controls, and oversight used to manage how AI agents are identified, authorized, monitored, and retired. It defines who can create or operate an agent, what tools and data it may access, how its actions are logged, and how risk is reviewed across its lifecycle.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
  • Human-in-the-Loop Oversight: A control model in which people remain responsible for reviewing, approving, or overriding AI output. In security operations, this helps preserve judgment, reduce error, and keep high impact decisions under human control even when AI is accelerating analysis and response.
  • Identity Debt: Identity debt is the accumulation of unowned, over-permissioned, or poorly governed non-human identities that security teams cannot cleanly inventory or retire. It usually grows when experimentation outruns access governance, leaving service accounts and tokens active long after their original purpose has passed.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org