TL;DR: AI agents are moving faster than workforce IAM can govern: long-lived credentials, session-only authorization and weak delegation tracking leave organisations exposed, according to Aembit’s analysis. The governing assumption is breaking, because many identity controls still assume access is stable long enough to be reviewed, certified or revoked after the fact.
At a glance
What this is: This analysis argues that legacy IAM is poorly matched to AI agents because static credentials, session-based authorization and weak delegation tracking cannot govern machine-speed, autonomous access patterns.
Why it matters: Identity teams need to treat AI agents as a governance problem now, because the controls built for human logins do not reliably manage ephemeral access, recursive delegation or runtime policy decisions.
By the numbers:
- The non-human-to-human identity ratio can reach 144:1, and the article cites that figure as a 44% year-over-year increase.
Context
AI agent identity governance is the problem space here: identity controls designed for human users are being asked to govern autonomous software that acts at machine speed. The mismatch is not just operational. It changes how access should be issued, evaluated and revoked when the actor can spawn subagents, call tools and complete tasks without a person sitting in the loop.
Legacy IAM assumes a stable session, a known role and a credential that lasts long enough to be reviewed later. AI agents undermine those assumptions because their access can be transient, delegated across chains and consumed across multiple systems inside a single task. The result is a governance gap, not merely a tooling gap.
Key questions
Q: What breaks when AI agents are treated like standard human users?
A: You lose visibility into effective permissions, expected behaviour, and real blast radius. Human-centric controls can misclassify normal agent activity as compromise, or miss policy violations that happen entirely within legitimate access. The failure is not only technical, it is governance design that assumes a person is always behind the action.
Q: Why do short-lived credentials matter more for agentic AI than for ordinary apps?
A: Agentic systems can request, use, and discard access inside a narrow runtime window, so long-lived credentials create unnecessary exposure between actions. Short-lived credentials reduce the time available for misuse and make revocation meaningful at task completion. They matter because the control problem is runtime access, not only initial authorisation.
Q: How do you know if agent delegation is becoming ungoverned?
A: The warning signs are missing hop-by-hop attribution, shared service accounts across multiple agents and logs that show actions without the initiating user or top-level agent. If you cannot reconstruct who authorised each step, the delegation chain is already too opaque.
Q: Should organisations prioritise runtime authorization over traditional access reviews for agents?
A: Yes, when the actor can request, use and release access faster than a review cycle can observe it. Traditional access reviews still matter for governance, but they cannot be the primary control for autonomous execution that changes state within a single task.
Technical breakdown
Why legacy IAM breaks for AI agents
Legacy IAM was built around human logins, persistent accounts and periodic review cycles. That model works when access lives long enough to be certified, but AI agents can request, use and discard privileges inside one task. The architectural mismatch is that the identity subject is no longer a person with a stable role, it is a transient workload that may act across several systems before the first audit checkpoint. In practice, that means human-centred controls such as SSO, MFA and static RBAC do not describe the real access behaviour of an autonomous agent.
Practical implication: identity programmes need a governance model that is anchored in runtime access issuance, not retrospective review.
Ephemeral credentials and workload-level identity
The article contrasts long-lived static secrets with ephemeral credentials that are generated for a brief period and then automatically revoked. That distinction matters because bearer tokens, API keys and service account passwords become reusable attack surfaces the moment they persist beyond the task they were meant to support. A workload-level identity model assigns each agent or workload a cryptographically verifiable identity for a specific interaction, rather than letting many actors share one standing credential. This is the core shift from secret management to identity governance for non-human actors.
Practical implication: replace shared long-lived secrets with per-workload identities and short-lived credentials wherever the agent context allows.
Delegation chains and continuous authorization
AI agents can act on behalf of a user and then spawn subagents to finish the job. That creates recursive delegation, where the security question is not just who logged in, but who authorised each handoff and what scope was inherited at each step. Traditional OAuth and RBAC patterns can represent parts of that flow, but they were not designed for continuous, multi-hop agent delegation with dynamic tool use. When authorization is only checked at session start, it misses scope drift that happens after the first action. Runtime enforcement is therefore a governance requirement, not an optional hardening step.
Practical implication: move from session-only approval to continuous scope checks across every delegated hop.
Threat narrative
Attacker objective: The attacker aims to convert one exposed reusable credential into broad administrative control before defenders can detect or revoke it.
- Entry begins with exposed static IAM credentials, such as keys left in a public S3 bucket or similar reusable secrets that can be replayed without reauthentication.
- Escalation follows once the stolen credential is accepted as legitimate access and is used to assume broader permissions or administrative rights.
- Impact occurs when the attacker reaches full control of the environment, enabling persistence, data access or further abuse from within trusted identity paths.
Breaches seen in the wild
- Amazon AWS Hacked Accounts Crypto-Mining: Compromised IAM credentials across multiple AWS accounts fuel large-scale crypto-mining campaign.
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI agent identity governance is a separate discipline from workforce IAM. Workforce IAM assumes human-paced logins, stable role assignment and review after the fact. AI agents break that model because their access is task-scoped, transient and often delegated across multiple systems. The implication is that identity governance for agents cannot be treated as a variant of employee IAM.
Standing credential exposure window: The control assumption that access will exist long enough to be reviewed was designed for human and service accounts that persist across days or weeks. That assumption fails when an autonomous actor can acquire, use and discard access within a single session. The implication is not just faster rotation, but a different governance premise about when identity exists.
Recursive delegation is now an identity governance problem. When an agent can spawn subagents or call tools on behalf of a user, each hop expands the audit and authorisation surface. Legacy IAM can record the first login, but it struggles to represent the chain of authority after the first delegation event. Practitioners need to treat delegation lineage as part of identity itself, not as an application log artifact.
Ephemeral workload identity is becoming the baseline for machine-speed access. Long-lived shared credentials collapse accountability because they make many actors look like one identity. A named concept here is identity blast radius: the amount of access exposed when a single credential is reused across tasks or actors. Smaller blast radius is now a governance objective for both NHI and agentic AI programmes.
Runtime policy will matter more than provisioning-time policy. Static access decisions made at token issuance cannot keep pace with prompt-influenced behaviour, tool chaining or subagent delegation. The more autonomous the actor, the less useful after-the-fact certification becomes as a primary control. Practitioners should expect identity programmes to shift toward continuous authorization and richer attribution.
From our research library:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.
- Read next: Agentic AI Identity Guide
What this signals
Identity governance must move closer to task execution. Access review cadences were built for identities that remain visible long enough to be certified, but autonomous agents can complete work before any scheduled review occurs. The practical change is to govern issuance, scope and revocation at the moment of action, not after the fact.
Identity blast radius is now the metric that matters. When multiple agents or subagents reuse a credential, one compromise can create broad cross-system exposure. Reducing reuse and narrowing scope are the levers that shrink the blast radius, regardless of whether the actor is a service account or an AI agent.
For practitioners
- Map agent access paths first Inventory the production databases, APIs, CI/CD systems and SaaS tools that AI agents can already reach, then identify where standing credentials or shared service accounts are still in use.
- Issue short-lived credentials per interaction Replace reusable API keys and persistent tokens with short-lived, task-scoped credentials so each agent action has a narrow exposure window and a clear expiry boundary.
- Track delegation lineage in logs Record the initiating user, the top-level agent, any subagents, the resource touched and the permission scope at each handoff so incident response can reconstruct the chain of authority.
- Move authorization checks into runtime Use contextual policy evaluation at the moment of request rather than relying only on role assignment at token issuance, especially where an agent can change tasks mid-session.
- Treat AI agents as governed identities Define ownership, review cadence and revocation triggers for agents the same way you would for service accounts, but extend the model to account for recursive delegation and task-level scope changes.
Key takeaways
- AI agents expose a structural mismatch in legacy IAM because human-centred controls do not govern machine-speed delegation and short-lived execution cleanly.
- The article links that mismatch to breach conditions already visible in the field, including eight-minute escalation from exposed IAM credentials and broader machine-identity compromise.
- Practitioners should shift controls toward short-lived credentials, runtime authorization and delegated identity attribution so autonomous access stays governable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on autonomous agents exceeding human IAM assumptions through delegated access and privilege scope. |
| Recommendation — Apply ASI03 to govern agent identity boundaries, delegation scope and runtime privilege use. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article focuses on static credentials, token replay and the need for cryptographically verifiable identity. |
| NHI-07 — Long-Lived Secrets | Long-lived API keys and service account tokens are described as the core exposure problem. | |
| Recommendation — Replace reusable secrets with verifiable, short-lived authentication for every non-human actor. Eliminate long-lived secrets wherever an agent or workload can use a short-lived credential instead. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Authenticator lifecycle controls directly map to rotation, revocation and short-lived credential management. |
| Recommendation — Use IA-5 to enforce credential lifecycle controls and revoke standing authenticators quickly. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Continuous authorisation and entitlement scoping are central to the article's control model. |
| Recommendation — Apply PR.AA-05 to verify entitlements at request time rather than only at issuance. | ||
Key terms
- Agent Identity: An agent identity is the set of attributes, credentials and permissions assigned to an autonomous software entity. It is treated as a non-human identity because it can authenticate, act on systems and accumulate access over time, which creates governance, audit and lifecycle obligations similar to other production identities.
- Recursive Delegation: A delegation pattern where one agent passes authority to another agent or subagent to complete part of a task. The governance challenge is that each hop expands the trust chain, so attribution, scope attenuation and revocation must follow the full path, not just the original user request.
- Ephemeral Credentials: Ephemeral credentials are short-lived access artefacts issued for a limited task or session. They reduce the window for abuse, but they only improve security when paired with strong scope limits, telemetry, and automatic revocation at task completion.
- Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org