By NHI Mgmt Group Editorial TeamBased on 1Password: “The next layer of AI security” (March 19, 2026)

TL;DR: EchoLeak showed that Microsoft 365 Copilot could exfiltrate API keys and internal data through hidden email instructions, even after authentication and authorization succeeded, according to 1Password. The real issue is the access trust gap: identity confirms who the agent is, but not whether a runtime action still makes sense.


At a glance

What this is: This analysis uses EchoLeak to show how an AI agent can authenticate and authorize correctly yet still be manipulated into disclosing sensitive data at runtime.

Why it matters: It matters because IAM teams now have to govern not just access grants, but whether an AI agent’s action remains appropriate once untrusted content enters the execution path.

By the numbers:

  • Microsoft patched EchoLeak in June 2025.

Context

EchoLeak shows that identity controls can be technically correct and still fail at the moment of use. In this case, a hidden instruction embedded in an email was later pulled into Copilot’s context, where it shaped the agent’s behaviour and led to disclosure of sensitive enterprise data.

For IAM and NHI practitioners, the key issue is not whether the agent had a valid identity, but whether runtime use of that identity remained safe once external content entered the workflow. The article frames this as an access trust gap, where permission is necessary but not sufficient.

That is a familiar governance problem in a new form: the control plane can approve the actor, while the execution layer still produces the wrong result. The starting position is increasingly typical for AI-assisted workflows that combine user-level access with untrusted inputs.


Key questions

Q: What breaks when an AI agent can turn untrusted content into privileged actions?

A: The trust boundary breaks because the agent no longer just reads external text. It can convert that text into tool calls, data access, and outbound transmission. Once that happens, classic assumptions about safe ingestion and human review no longer hold, and the control point shifts to pre-action authorisation, content trust, and destination restrictions.

Q: Why do valid authentication and authorization still fail to prevent prompt-injection abuse?

A: Because those controls answer who the actor is and what it may access, not whether the action still makes sense after the agent’s context changes. Prompt injection exploits the gap between allowed access and appropriate use, so the problem is runtime judgement, not login failure.

Q: How can organisations tell whether AI agent governance is actually working?

A: Look for evidence that agent access is ephemeral, traceable, and constrained at the action level. If the organisation cannot show which runtime acted, what it touched, and which endpoint or command it used, then governance is still too coarse. Effective control produces auditable decisions, not just authentication events.

Q: What is the difference between identity verification and runtime authority for AI agents?

A: Identity verification establishes that the agent is legitimate and has an approved caller. Runtime authority determines whether a specific action should happen now, given the current task, content, and destination. For AI agents, the second question is often more important because intent can drift after authentication.


Technical breakdown

How prompt injection changes agent behaviour after authentication

Prompt injection is an execution-layer attack, not a login bypass. The model receives untrusted instructions inside content it is already processing, then treats those instructions as relevant to the task context. If the agent inherits user-level permissions, the malicious instruction can redirect legitimate authority toward disclosure, retrieval, or tool use that the human did not intend. This is why authentication and authorization do not resolve the problem on their own. They answer who the actor is and what it may touch, but not whether a specific action is still valid after context has changed.

Practical implication: Treat untrusted content as a runtime trust boundary, not just an input-filtering problem.

Why standing permission is the wrong mental model for AI agents

Traditional IAM assumes access is granted to a known actor and then used within stable intent boundaries. Agent workflows break that assumption because the actor can move across tools, reuse credentials, and chain actions after the original request has changed shape. That makes standing permission a poor fit for runtime governance. Short-lived credentials, token exchange, and workload identity reduce persistence, but they do not decide whether the agent should act in a given moment. The article’s central point is that identity is only the starting point for runtime authority.

Practical implication: Design access so that credentials are issued for a specific action, not as a durable proxy for intent.

Why deterministic controls matter more than model judgement

The article argues that systems cannot rely on the model to correctly interpret policy in the moment. Once an AI agent is allowed to invoke tools or retrieve credentials, the control must be enforced deterministically at execution time. That means the decision needs to be based on current context, target, and task state, not on the model’s internal reasoning. In practical terms, the agent may be allowed to act, yet still be blocked if the action no longer fits the approved context. That is the governance shift from identity proof to runtime authority.

Practical implication: Enforce sensitive actions with policy checks that sit at the point of execution, not only at sign-in.


Threat narrative

Attacker objective: The attacker wants the agent to convert legitimate user permissions into unauthorised disclosure of sensitive enterprise data.

  1. Entry occurs when an attacker places hidden instructions inside a normal-looking email that later enters the agent’s context.
  2. Credential access happens when the agent, acting with the victim’s permissions, retrieves sensitive data including API keys and internal documents.
  3. Impact follows when the agent discloses enterprise information without human intervention, even though authentication and authorization succeeded.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Access trust is now a runtime problem, not an identity problem: EchoLeak shows that authenticating the actor and authorizing the scope are no longer enough to guarantee safe behaviour. The failure occurs after both controls succeed, when untrusted content reshapes what the agent decides to do. The implication is that identity programmes must govern execution context as well as access grants.

Runtime authority must be treated as a separate control boundary: The article’s core distinction is between access that is valid and action that is appropriate. That distinction matters because AI agents can move across tools, reuse permissions, and chain operations in ways traditional IAM never had to model. Practitioners need to recognise that the authority exercised at runtime is not the same thing as the authority granted at login.

Ephemeral credentials reduce exposure, but they do not solve intent drift: Short-lived tokens, token exchange, and workload identity narrow the window of abuse, yet the article makes clear that the harder question is whether the action should occur at all. The governance gap is not only standing privilege, but the assumption that access grants imply current intent. Teams should reframe controls around context-aware execution.

Prompt injection is an identity governance issue when the agent holds real permissions: The article is effectively describing a trust failure in delegated identity, where external content can steer an authorized actor into misuse. That makes AI agent governance a sibling discipline to NHI governance, not a separate novelty. The practitioner conclusion is that runtime policy must be able to override otherwise valid credentials.

Identity establishes who the agent is, but not what the agent should do next: That is the access trust gap in one sentence, and it is why conventional IAM cannot be the last word on agent security. Once the execution path includes untrusted content, the system needs controls that evaluate action fitness continuously. The field should expect runtime governance to become a core requirement for AI agents.

From our research library:

What this signals

Access trust gap: AI agent programmes should assume that valid identity and valid intent can diverge after authentication. That means governance has to move closer to the moment an agent invokes a tool, retrieves a credential, or discloses data, because post-authentication context is where the failure emerges.

Security teams should prepare for a broader pattern: any workflow that lets an AI agent consume external content and then use delegated permissions can become a runtime governance problem. The practical question is no longer whether the agent can log in, but whether the next action should be allowed under the current context.

The article reinforces a shift that IAM programmes will need to absorb across human, NHI, and autonomous workflows. Access decisions are becoming necessary but insufficient, and the real control question is whether authority remains valid at the moment of execution.


For practitioners

  • Map runtime trust boundaries Identify every place where an AI agent can consume untrusted content and then act with inherited permissions. Treat those transitions as control points for policy enforcement, logging, and step-up verification.
  • Reduce standing permission Replace durable access with short-lived credentials, token exchange, and task-scoped authority wherever an agent can touch sensitive systems or data.
  • Enforce deterministic action checks Place controls at the moment of tool use or data retrieval so that the action is evaluated against current context, not just initial authentication.
  • Review delegated access paths Trace how an agent inherits user permissions across email, browser, document, and API workflows, then remove routes that let untrusted input steer privileged operations.

Key takeaways

  • EchoLeak demonstrates that an AI agent can pass authentication and authorization checks while still being manipulated into unsafe runtime behaviour.
  • The article’s core finding is an access trust gap, where the control that matters most is the one applied at execution time.
  • Runtime governance, not just identity issuance, is the control layer that determines whether an AI agent should proceed with a sensitive action.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on an agent using valid permissions in the wrong context.
ASI02 — Tool MisuseEchoLeak turns contextual manipulation into inappropriate tool use and data disclosure.
Recommendation — Apply ASI03 controls to evaluate whether an agent may misuse granted identity or privilege at runtime. Constrain tool invocation so context changes cannot silently redirect agent actions.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article argues authentication alone does not answer whether an agent’s current action is safe.
NHI-05 — Overprivileged NHIUser-level permissions gave the agent enough reach to disclose sensitive data after injection.
Recommendation — Use NHI-04 to ensure identity proof does not become the sole control for delegated agent actions. Reduce overprivileged access so delegated agents cannot expose sensitive assets through broad scopes.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article shows entitlement checks must be paired with runtime context validation.
Recommendation — Review access permissions so authorizations are evaluated against current execution context, not only initial login.

Key terms

  • Prompt Injection (Agentic): An attack where malicious instructions are embedded in content that an AI agent reads, causing the agent to execute unintended actions using its own legitimate credentials. A primary vector for agent goal hijacking and identity abuse.
  • Access-trust gap: The gap between having a policy and actually enforcing it when access is requested. It appears when compliance, HR, or training data sits in separate systems from the access decision, allowing users to reach resources even though a required condition has not been met.
  • Runtime Governance: Runtime governance is the set of controls that verify what a system or agent is actually doing after deployment. It combines monitoring, authorization checks, and access validation so teams can detect drift, misuse, or excessive privilege in motion rather than assuming build-time policy still holds.
  • Delegated Identity: Delegated identity is when one actor acts on behalf of another with explicit permission and bounded authority. In AI-assisted commerce, it requires clear consent, limited scope, and traceable records so the retailer can distinguish authorised delegation from unauthorised automation.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org