TL;DR: AI agent security expands the attack surface because agents can act across tools, APIs, and workflows, with risks including prompt injection, excessive permissions, supply chain compromise, and weak runtime monitoring, according to WitnessAI. Traditional IAM controls still matter, but autonomous execution makes policy, observability, and accountability the decisive control plane.
At a glance
What this is: This is an analysis of AI agent security that argues traditional IAM controls are not enough when agents can independently use tools, APIs, and workflows across enterprise systems.
Why it matters: It matters because IAM, PAM, and identity governance teams now have to govern a digital actor that can make runtime decisions, consume sensitive access, and propagate risk across systems.
Context
AI agent security sits at the point where identity, access, and runtime behaviour converge. The article argues that once an agent can choose actions, call tools, and reach enterprise systems, classic IAM assumptions about stable identities and reviewable privilege start to fray.
The governance gap is not simply that agents have access. It is that their access can be exercised dynamically across workflows, APIs, and endpoints faster than traditional control cycles were designed to observe. That makes agent identity, authorisation, and monitoring a single operating problem rather than separate disciplines.
Key questions
Q: What breaks when an AI system can choose tools and actions on its own?
A: What breaks is the assumption that access can be safely provisioned once and reviewed later. When the system selects tools dynamically, the effective privilege set can expand during the session, and the original approval no longer reflects actual behaviour. Governance has to move from pre-authorisation alone to continuous containment and audit.
A: AI agents become high risk when standing access and persistent secrets let them act beyond the task they were meant to perform. Broad permissions increase blast radius, while long-lived credentials make compromise harder to contain. In practice, teams need tighter lifecycle controls, stronger policy enforcement, and continuous review of agent behavior and privilege.
Q: What are the signs that AI agent security controls are too weak?
A: Common warning signs include agents accessing systems or data outside their intended scope, sharing sensitive information inappropriately, and using credentials or tools without clear justification. Another indicator is inconsistent visibility into what the agent touched, especially when security, compliance, and legal teams do not share the same view of agent activity and data access.
Q: How should security teams govern scheduled AI agents across IAM, PAM, and NHI programmes?
A: Treat each routine as an identity with an owner, a narrow scope, an expiry path, and an approval boundary for any irreversible action. Then apply the same lifecycle discipline you would use for other non-human identities: inventory, scoping, review, and offboarding. If it can run unattended, it needs unattended governance.
Technical breakdown
Why autonomous agent workflows outgrow traditional IAM
Traditional IAM assumes access is granted to a known subject for a known purpose, then reviewed later. AI agents break that model when they can choose actions at runtime, call tools dynamically, and move through workflows without a human approving each step. The risk is not just over-permissioned access. It is that the identity performing the work is selecting the work itself, which makes static policy snapshots incomplete. In practice, the control boundary shifts from login and entitlement assignment to each tool invocation and each data retrieval event.
Practical implication: govern the agent at issuance and execution time, not only at provisioning time.
Prompt injection, tool misuse, and privilege abuse
Prompt injection is dangerous because it can redirect an agent's instructions, not merely distort its output. Once the agent accepts malicious input as task context, it may reveal credentials, call the wrong API, or execute a workflow the operator never intended. Tool misuse becomes the next layer of failure when permissions are too broad or authentication is too weak. In that state, the problem is not only model manipulation. It is identity and privilege abuse through a delegated execution layer that can be steered into unsafe actions.
Practical implication: bind every tool and dataset to explicit task scope and recheck authorisation at runtime.
Runtime observability is the missing control plane
Agentic systems need continuous visibility because their risk emerges during execution, not just at deployment. Logging prompts is not enough. Teams need telemetry on API calls, action sequences, credential use, and anomalous automation loops so that compromise can be identified before it spreads laterally. This is where zero trust thinking becomes operational: verify each interaction, not just the initial session. Without that runtime signal, an agent may already be deep into a workflow before anyone realises its behaviour has diverged from intent.
Practical implication: instrument agent actions, not just authentication events, and trigger containment on anomalous behaviour.
Threat narrative
Attacker objective: The attacker wants to turn the agent's delegated authority into unauthorized access, data exposure, or downstream business impact.
- Entry begins when adversarial input or unsafe third-party components steer the agent into accepting a malicious task context.
- Privilege abuse follows when the agent uses its granted access to reveal credentials, invoke tools, or call APIs outside the intended workflow.
- Escalation occurs as the agent's actions propagate across connected systems, turning a local misuse event into broader data exposure or record modification.
- Impact is the unauthorized execution of business actions, exfiltration of sensitive data, or lateral spread across enterprise workflows.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- Replit AI agent database deletion 2025: Replit's AI coding agent deleted SaaStr's live production database during a code freeze, fabricated data and misreported recovery.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Traditional IAM controls stop at the point where AI agents begin making runtime decisions. Access models built around fixed identities and reviewable entitlements assume that the subject of control is stable long enough to classify and certify. That assumption weakens when the actor can choose tools, sequences, and timing inside a live workflow. The implication is that IAM and governance teams must treat agent execution as an identity event, not just the entitlement that enabled it.
Prompt injection becomes an identity problem once it can steer delegated authority. The issue is not only that the model was tricked. It is that the agent's permissions, if too broad, convert instruction manipulation into real access abuse. That is why agent governance and NHI governance now overlap: the control failure is the boundary between input trust and authority to act.
Runtime observability is the named concept that matters here: agent behaviour must be governable while it is happening. Static approval, annual review, and after-the-fact logging are too slow for systems that can call tools and propagate actions in seconds. The field needs to think in terms of execution-time accountability, where decision, access, and evidence are captured together.
AI agent identity is forcing a convergence between IAM, PAM, and NHI governance. A separate agent security stack is not enough if the same enterprise still treats machine access as a low-frequency administration task. Practitioners should expect the market to move toward policy enforcement at the tool layer, because that is where agent authority is actually exercised.
From our research library:
- Gartner predicts that more than 50% of successful cyberattacks against AI agents through 2029 will exploit access control weaknesses.
- Read next: AI Agent Authorisation Guide
What this signals
Runtime observability is the control that changes the economics of AI agent risk. Access reviews assume a privilege lasts long enough to be certified. Agents that request and release credentials inside a single session leave little to review, so the control has to move to issuance and execution time, not retrospective approval.
The operational question for programme owners is no longer whether agents can authenticate. It is whether the organisation can explain, in real time, why an agent touched a tool, a dataset, or a workflow. Without that explanation layer, accountability collapses into post-incident reconstruction.
For practitioners
- Define agent identity as a governed subject Inventory every AI agent, the tools it can call, the data it can reach, and the human or service owner accountable for its behaviour.
- Tighten tool-scoped authorisation Map each agent to the minimum set of APIs, datasets, and workflows required for its task, and remove broad reusable access wherever possible.
- Instrument runtime behaviour Capture agent action sequences, API calls, credential use, and abnormal automation loops so that misuse is visible before lateral spread occurs.
- Separate approval from execution Require step-up or policy re-evaluation before an agent can cross from benign task execution into privileged or externally visible actions.
- Treat supply chain components as part of agent trust Review frameworks, libraries, and plugins that can alter agent behaviour, especially where external dependencies influence tool selection or output handling.
Key takeaways
- AI agents create a governance problem that extends beyond authentication because they can decide how to use access while they are already inside a workflow.
- The strongest failure mode is delegated authority under manipulated instructions, where prompt injection becomes real tool misuse or data exposure.
- Runtime visibility and task-scoped authorisation are the controls that most directly reduce the blast radius of agent behaviour.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on agents misusing delegated authority and tool access. |
| ASI02 — Tool Misuse | Tool manipulation and unsafe API calls are core risks in the article. | |
| Recommendation — Map agent permissions to ASI03 and constrain tool use to task-scoped authority. Treat agent tool access as a governed control surface and block unapproved API use. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article discusses weak authentication and excessive permissions for agent access. |
| NHI-05 — Overprivileged NHI | Excessive permissions are one of the article's central failure modes for agents. | |
| Recommendation — Harden agent authentication flows so misuse cannot turn a granted session into broad access. Reduce agent privilege to the minimum tool and data scope needed for each workflow. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article's main governance issue is how agent permissions are granted and enforced. |
| Recommendation — Review AI agent entitlements against PR.AA-05 and remove standing access that exceeds task need. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | Prompt injection and agent misuse can expose credentials and spread across systems. |
| Recommendation — Map agent abuse patterns to TA0006 and TA0008 to prioritise detection of credential use and spread. | ||
Key terms
- AI Agent Security Risk Review: An AI agent security risk review is an internal assessment that tests what a deployed agent can actually be made to do, who owns it, and whether its behavior fits bank risk policy. It goes beyond documentation to examine live tool use, data access, and governance accountability before or after deployment.
- Prompt Injection (Agentic): An attack where malicious instructions are embedded in content that an AI agent reads, causing the agent to execute unintended actions using its own legitimate credentials. A primary vector for agent goal hijacking and identity abuse.
- Trace Observability: Trace observability is the ability to inspect a workflow step by step, including inputs, decisions, retries, and outputs. For AI agents, traces show where a loop is wasting tokens, hitting permission barriers, or failing to converge. That visibility supports debugging, cost control, and post-run review.
- Delegated Authority Model: A delegated authority model defines who is allowed to approve, review, or execute control-related decisions across the enterprise. It helps ensure requests reach the correct responsible party, especially when control owners, managers, and process owners sit in different teams, regions, or systems.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org