By NHI Mgmt Group Editorial TeamBased on Vorlon: “Black Hat” (August 4, 2026)

TL;DR: Security teams still cannot see what AI agents are actually doing in many environments, and legacy tools were built for human-speed browser interactions rather than agent-to-SaaS chains, according to Vorlon's 2026 CISO report. The governance gap is architectural: identity programmes now need to track behaviour, data flow, and delegated access together, not separately.


At a glance

What this is: This is a Black Hat 2026 event page and Vorlon analysis arguing that AI agent identity risk is outpacing legacy IAM assumptions built for human browser sessions.

Why it matters: It matters because IAM teams now have to govern agent behaviour, delegated SaaS access, and data movement together, not as separate control problems.


Context

AI agent identity risk is a governance problem, not just a detection problem. Legacy IAM and SIEM workflows were built around human users, stable sessions, and browser-based interactions, while agentic systems can authenticate, call tools, and move data across SaaS boundaries within a single task flow.

Vorlon's point is that the risky activity happens in the operational path between apps, tokens, integrations, and non-human identities. That means security teams need visibility into what agents do, what data they touch, and which delegated relationships they exercise, because an inventory of agents alone does not explain exposure.


Key questions

Q: What breaks when AI agents are treated like standard human users?

A: You lose visibility into effective permissions, expected behaviour, and real blast radius. Human-centric controls can misclassify normal agent activity as compromise, or miss policy violations that happen entirely within legitimate access. The failure is not only technical, it is governance design that assumes a person is always behind the action.

Q: Why do AI agents increase the blast radius of SaaS compromises?

A: AI agents increase blast radius because they often inherit broad delegated permissions and can execute many actions across connected applications in a short time. If one agent or integration is compromised, the attacker can reuse that trust to reach multiple systems, move data quickly, and escalate from one app to an ecosystem.

Q: What signals show that an AI governance programme is not working?

A: Warning signs include disconnected models built by different teams, repeated disputes over data ownership, inconsistent approvals and outputs that cannot be explained to stakeholders. If the organisation cannot trace which data supported a decision or who approved the model, governance is already failing at the operating level.

Q: Should security teams treat agent inventory as enough for risk governance?

A: No. Inventory tells you what exists, but not which SaaS accounts, integrations, or data categories each agent can reach. A useful programme links inventory to delegated access, sensitive data flow, and runtime behaviour so you can see the actual exposure path rather than a static list.


Background and context

Why legacy IAM misses agent-to-SaaS execution chains

Legacy IAM was designed to answer who authenticated, from where, and with what entitlements. AI agents change that model because the security-relevant unit is no longer a user session but a chain of actions across Salesforce, MCP-connected tools, and downstream SaaS workflows. That chain can include OAuth tokens, dormant integrations, and service-level permissions that never look risky in isolation. The control gap is architectural: traditional identity products see identities and permissions, but not the data and operations that occur between them.

Practical implication: model and monitor the execution chain, not just the issued credential.

Why inventorying AI agents is not enough

A directory of agents tells you what exists, but not what they can reach, what data they can process, or how they can combine tools at runtime. In agentic ecosystems, the risk comes from dynamic behaviour across trusted identities and connected services. That is why posture questions must extend to sensitive data touchpoints, integration scope, and third-party paths. This is the difference between asset discovery and governable identity behaviour.

Practical implication: tie agent inventory to data-flow mapping and delegated access review.

How behavioural detection changes for autonomous and semi-autonomous agents

Behavioural detection for agents has to operate at the data layer because risky actions may look legitimate at the identity layer. An AI agent can use valid credentials and still create excessive exports, abnormal tool chaining, or privilege escalation across connected systems. The useful signal is not whether the login was allowed, but whether the agent's observed activity matches its approved operating context. That requires alerting that joins identity, action, and data classification in one view.

Practical implication: tune detections around abnormal data movement and cross-tool behaviour, not login success alone.


NHI Mgmt Group analysis

Legacy IAM breaks when the governed object is an action chain, not a user session. Human-centric controls assume a person authenticates, performs a bounded set of actions, and exits. AI agents collapse that sequence into rapid tool use across multiple systems, so the identity programme has to govern behaviour, delegation, and data movement together. The practitioner conclusion is simple: session-centric IAM no longer describes the real control surface.

Agent inventory is a starting point, not a control boundary. Knowing that an agent exists says nothing about the SaaS accounts it can reach, the integrations it can invoke, or the sensitive data it can touch. The more important governance question is which agents can combine valid access paths into material exposure. That shifts the programme from cataloguing identities to supervising relationships and runtime use.

Identity blast radius is now shaped by connected systems, not just privilege assignment. One compromised token or abused integration can propagate across SaaS-to-SaaS relationships faster than traditional review cycles can react. That makes blast-radius analysis a core identity function, not just an incident response exercise. Practitioners should treat delegated access paths as the unit of risk.

Access review processes assume access persists long enough to be reviewed; autonomous behaviour can invalidate that assumption. When an agent can authenticate, execute, and hand off work within a short runtime window, review cadences miss the relevant event entirely. The implication is not simply to add more reviews, but to rethink whether review is the right control point for machine-timed behaviour.

What this signals

Agentic governance has to move from entitlement review to runtime supervision. The decisive question is not whether an agent has an assigned role, but whether its observed behaviour stays inside the business context that role implies. When tool selection and data movement happen at machine speed, the control point shifts to issuance, delegation, and data-path visibility.

Identity teams should expect blast-radius analysis to become a standard operating requirement. When connected SaaS systems and trusted integrations are the propagation path, responders need to know which identities, data classes, and third-party paths are affected before they know the full incident story. That makes containment planning part of identity governance, not a separate SOC concern.


For practitioners

  • Map agentic execution paths Track how AI agents authenticate, what SaaS systems they reach, which MCP or API calls they can trigger, and where output is written. Treat the end-to-end chain as the asset you govern, not just the credential or app.
  • Link agent inventory to data flow Maintain a live inventory of sanctioned and unsanctioned agents, then connect each one to the sensitive data categories it can touch, including PII, PCI, and PHI. This turns discovery into governance instead of a static list.
  • Review delegated SaaS access regularly Identify dormant integrations, trusted OAuth tokens, and service accounts that let agents reach customer records or write into downstream tools. Revalidate those relationships against current business need and remove unused paths.
  • Detect behaviour at the data layer Tune monitoring for mass exports, privilege escalation, anomalous cross-tool actions, and third-party access patterns that are legitimate in syntax but abnormal in context. Join identity events with data classification so alerts show what was touched.
  • Prepare blast-radius containment playbooks Define which identities, integrations, and data categories are affected first when a connected vendor or token is compromised. Make token revocation, integration quarantine, and SIEM or SOAR containment actions available from the same workflow.

Key takeaways

  • AI agents expose the limits of legacy IAM because they act through chained SaaS relationships that traditional user-session controls do not describe well.
  • Vorlon cites 99.4% of organisations with at least one SaaS or AI security incident in 2025 and says 86% of teams still cannot see what their AI agents are doing.
  • Practitioners need to govern execution paths, delegated access, and data movement together if they want identity controls to keep pace with agentic systems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationAgents rely on OAuth tokens and trusted integrations that authenticate into SaaS.
NHI-05 — Overprivileged NHIThe article centres on delegated access that can reach too many apps and datasets.
NHI-10 — Human Use of NHIHuman-centric IAM assumptions fail when people rely on machine identities to act on their behalf.
Recommendation — Audit agent authentication paths and remove any trust relationships that cannot be tied to a business owner. Reduce agent and integration privileges to the minimum SaaS scopes required for each task. Separate human approvals from machine execution paths so delegated work stays governable.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article describes agents abusing valid identity paths and delegated privilege across tools.
Recommendation — Map agent privilege abuse paths and alert on cross-tool actions that exceed approved context.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe governance issue is whether permissions and entitlements still match how agents actually operate.
Recommendation — Revalidate agent entitlements against live access paths and revoke permissions that are no longer justified.

Key terms

  • Agentic ecosystem: The connected set of AI agents, SaaS applications, integrations, and non-human identities that can act together in production. It matters because risk emerges from how these components combine at runtime, not from any one component in isolation.
  • Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Runtime Supervision: Continuous observation of what an identity or agent actually does while it is operating. For NHI governance, runtime supervision helps detect scope creep, unusual tool chaining, and behaviour that is technically permitted but operationally unsafe.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 5, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org