By NHI Mgmt Group Editorial TeamBased on Delinea: “Mythos: Five Best Practices for Identity Security Leaders” (June 2, 2026)

TL;DR: AI-driven attacks are compressing the time from vulnerability discovery to exploitation while AI agents expand privileged identity exposure, according to Delinea. Standing privilege, unmanaged secrets, and weak runtime authorisation now define the practical attack surface, making just-in-time access and tighter identity discipline urgent.


At a glance

What this is: This is Delinea's analysis of how AI agents and faster AI-driven attacks are combining to expose standing privilege, unmanaged secrets and weak runtime authorisation.

Why it matters: It matters because identity teams now have to govern machine and agent access with the same discipline they apply to human admins, or privileged exposure will outrun review cycles.


Context

AI agent identity risk is no longer a future-state concern. When autonomous software can authenticate, hold secrets and act without direct human pacing, the identity model shifts from managing access requests to governing runtime privilege exposure. That changes the security problem from a static permissions question to a live authorisation and secrets-control problem.

Delinea's on-demand session frames the issue as a practical identity governance gap: standing privilege still exists in many environments, and AI agents increase the number of identities that can be abused if access is persistent. The article's core claim is that faster attacker capability and broader agent deployment are converging on the same weak point, namely privileged credentials.


Key questions

Q: What breaks when standing privilege is left in place for AI-driven systems?

A: Standing privilege breaks the basic assumption that access can be reviewed before it is used. AI-driven systems can act, chain actions, and complete work within the same runtime window, so durable entitlements create unnecessary exposure and remove the ability to evaluate intent at execution time.

Q: When do AI agent credentials create more risk than they reduce?

A: They create more risk when they are long-lived, over-scoped, hard to revoke, or copied into code and prompts. At that point the credential becomes a standing trust asset with unclear ownership. Security teams should reject any pattern that cannot be traced to a specific agent, environment, and revocation process.

Q: How do security teams know if just-in-time access is actually working?

A: Look for short-lived sessions, automatic revocation, and complete request-to-access logs. If approvals are still creating durable permissions, or if teardown depends on manual cleanup, then the programme is only partially ephemeral. Effective JIT should leave little or no reusable privilege behind after the task ends.

Q: How should organisations govern privilege for AI systems that can issue commands?

A: They should govern those systems as privileged actors with bounded authority, not as ordinary applications. That means defining what actions the system may initiate, what data it may reach, and how access is revoked when the task ends or the context changes. If the system can act independently, privilege policy must operate at runtime, not only at provisioning.


Background and context

Why standing privilege becomes the first target in AI agent environments

Standing privilege is persistent access that remains available until someone removes it. In environments with AI agents, that model becomes fragile because agents can hold credentials, trigger actions and interact with tools continuously rather than only when a human opens a session. An attacker does not need to wait for a human to approve a risky step if the agent already has broad entitlement. The practical problem is not just access scope, but access duration and reuse. Once privilege is always on, it becomes a standing opportunity for misuse, escalation or session abuse.

Practical implication: remove persistent privileged access where AI agents can reach it and replace it with task-scoped, time-bounded entitlement.

Secrets, sessions and runtime authorization are the real control boundary

Secrets are the credentials, tokens, keys and certificates that let an identity authenticate. Sessions are the active state in which those credentials can be used, while runtime authorisation determines whether the requested action is allowed at the moment of use. In agentic environments, these three controls matter more than static provisioning because the risk appears when the agent is running, not when it is created. If secrets remain reusable and runtime checks are weak, the attacker can move from initial access to privileged execution very quickly. Identity governance has to follow the execution path, not just the onboarding record.

Practical implication: govern secrets, sessions and runtime decisions as a single control plane rather than separate point controls.

Why faster attacker capability changes identity defence timing

The article's key shift is temporal: the attacker now reaches working exploitation faster than many identity programmes can detect and respond. That compresses the time available for credential theft, privilege escalation and lateral movement. It also weakens control assumptions that depend on lengthy review cycles, because a reused secret or overprivileged session may be abused before a team can see the issue in a report or audit trail. The technical consequence is that identity control points must move earlier in the execution flow, close to issuance and authorisation, not only to review and remediation.

Practical implication: shift detection and enforcement toward issuance time and runtime policy enforcement, not end-of-month review.


NHI Mgmt Group analysis

Standing privilege is becoming an AI agent exposure amplifier: persistent access was already a weak governance pattern for human admins, but AI agents multiply its reach because they can hold and use credentials continuously. Once the identity subject is software that acts on its own schedule, persistent privilege stops being a convenience and becomes an exposure multiplier. The practitioner conclusion is that privilege persistence now matters more than privilege size alone.

Runtime authorisation is where AI agent governance actually fails or succeeds: the article points to a control problem that cannot be solved by onboarding alone. Agents may be provisioned safely and still become risky if session use, secret reuse and action approval are not controlled at execution time. That shifts the governance question from who received access to what the identity can do right now, which is the only point that still changes the outcome.

The old assumption that access can be reviewed after it exists is breaking: access review processes were designed for identities whose privilege persists long enough to be observed, sampled and certified. That assumption fails when AI agents can create, use and discard privilege within compressed attack windows. The implication is that identity governance has to stop treating review as the primary control for agentic privilege.

AI agents should be governed with the same admin-grade discipline as privileged humans: the article correctly places agents in the privileged identity model, not in a lightweight automation category. When an agent can authenticate, store secrets and execute actions, the governance bar has to match that of a high-risk human administrator. That means lifecycle, session and entitlement controls must converge across human and machine access.

Ephemeral access is only useful if secrets do not outlive the task: just-in-time access can shrink exposure, but the article's broader point is that the secret lifecycle must be shorter than the attacker window. If credentials remain reusable after the task, the control has not removed privilege exposure, only delayed it. The practitioner implication is to treat secret persistence as part of the attack surface, not just a storage issue.

From our research library:

What this signals

Ephemeral access only works when secret reuse is curtailed: identity teams should not treat just-in-time access as a complete answer if tokens, keys or sessions survive beyond the work they were issued for. The control boundary has moved to runtime, which means persistent privilege and reusable secrets now belong in the same risk conversation.

AI agent governance is starting to converge with privileged human governance: the same accountability questions apply when software can authenticate, act and persist access across tasks. NHI Mgmt Group's view is that organisations still underestimating this convergence are building review processes that arrive after the risky action has already happened.

Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey 2026 Infrastructure Identity Survey cited by Delinea. That gap shows why identity programmes need to move from ad hoc access review to explicit runtime governance for agentic identities.


For practitioners

  • Define where standing privilege still exists Inventory privileged accounts, service credentials and AI agent access paths that remain valid across sessions, tasks or workflows. Prioritise the identities that can reach production systems, secrets stores or admin interfaces without fresh approval.
  • Move privileged access to just-in-time issuance Require task-scoped entitlement for administrative actions so that agents and humans receive elevated access only when the work begins and lose it as soon as the session ends.
  • Bind secrets to short-lived runtime sessions Separate secret storage from persistent usage by restricting token reuse, tightening session duration and ensuring the credential cannot outlast the workflow that requested it.
  • Treat AI agents as privileged identities Apply the same approval, session oversight and revocation discipline to AI agents that you already expect for high-risk human administrators, especially where the agent can authenticate and trigger actions autonomously.
  • Trace runtime authorisation to the point of execution Review whether policy decisions are enforced when the action is taken rather than only at provisioning time, because persistent permissions can still be exploited before a later review cycle notices them.

Key takeaways

  • AI agents expand the number of privileged identities that can be abused, but the deeper issue is that standing privilege leaves those identities available long enough to be exploited.
  • The article's core warning is about timing as much as scope: faster attacker capability shortens the window in which secrets, sessions and runtime actions can be contained.
  • Identity teams should focus on issuance-time and runtime controls, because post-hoc review alone cannot keep pace with agentic access and reusable credentials.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on persistent privilege exposure for AI agents and privileged identities.
NHI-07 — Long-Lived SecretsReusable secrets and standing access are the main exposure problem described here.
NHI-04 — Insecure AuthenticationAgents authenticating with persistent credentials are the entry point for the risk described.
Recommendation — Reduce agent and service access to the minimum scope needed for each task. Shorten credential lifetimes and eliminate secrets that remain valid across sessions. Harden authentication paths so agent credentials cannot be reused outside approved runtime conditions.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article describes agents using identity and privilege in ways attackers can exploit.
Recommendation — Constrain agent privilege pathways so runtime actions cannot exceed authorised identity scope.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article focuses on secrets, sessions and the lifecycle of credentials used by privileged identities.
AC-6 — Least PrivilegeStanding privilege is the central exposure pattern, making least privilege directly relevant.
Recommendation — Apply authenticator management to rotate, expire and revoke privileged credentials promptly. Enforce least privilege so agents and admins cannot retain broad access outside the task scope.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about who can act, under what entitlement, and for how long.
Recommendation — Review entitlements continuously and remove persistent permissions that outlive the business need.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe attacker objective is to reach privileged credentials and use them before containment catches up.
Recommendation — Map agent credential exposure to credential access and lateral movement detections.

Key terms

  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
  • Secret Reuse: Secret reuse is the practice of using the same password, token, or credential across multiple systems or functions. It multiplies the impact of any single dump because one compromised secret can authenticate to several environments, creating a much larger blast radius.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 2, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org