TL;DR: AI agent security conversations at Identiverse 2026 showed a widening gap between discovery and runtime enforcement, with attendees focused on visibility while access decisions, tool use, and approval logic remained unresolved, according to Aembit. The real risk is that teams keep accumulating agents, credentials, and exceptions before they have a governance model that can enforce access at runtime.
At a glance
What this is: This analysis argues that AI agent security is moving past inventory and into runtime enforcement, with Aembit highlighting visibility as necessary but insufficient.
Why it matters: IAM, PAM, and NHI teams need to treat agent access as a live authorization problem, because discovery without enforcement leaves credential sprawl and approval gaps intact.
Context
AI agent security is the problem of deciding what an autonomous software actor may access, use, or trigger at runtime. The article argues that the current market focus on visibility leaves a governance gap, because seeing agents and mapping connections does not stop unsafe access decisions.
That gap matters to NHI and IAM programmes because agent access is already being treated like a discovery exercise when it is really an authorization problem. As agents move into production, teams need controls that can enforce least privilege at the moment of access, not only report on it after the fact.
Key questions
Q: What breaks when agentless visibility is missing in AI infrastructure?
A: Without agentless visibility, ephemeral training jobs, GPU clusters, and short-lived inference services can disappear before traditional tools observe them. Security teams lose the ability to connect identity, network, and storage signals into a complete risk path, which leaves shadow AI and cross-cloud movement underreported.
Q: Why do AI agents create risk even when they stay within approved permissions?
A: AI agents can be authorised correctly and still produce harmful outcomes because permission is not the same as intent or behavioural appropriateness. If an attacker manipulates the session mid-flight, the agent may keep acting inside scope while exfiltrating data, taking destructive steps, or chaining actions that no human would have approved.
Q: How can security teams tell whether agent access is actually under control?
A: Look for evidence that the team can trace every tool call, secret use, and cross-system action back to a named owner and a valid approval path. If an agent can reach messaging, browser, and infrastructure tools without a revocation chain, access is not truly governed. Control exists only when the runtime can be stopped as fast as it can act.
Q: Should organisations treat AI agents like human users in IAM?
A: No. Human IAM assumes a person logs in, works within a session, and can be reviewed later as a stable identity holder. Agents can act at machine speed, across multiple systems, and with changing runtime context, so they need identity governance built around execution and delegation rather than human authentication patterns.
Technical breakdown
Why visibility does not equal runtime enforcement
Visibility tells you which AI agents exist, what they connect to, and what they have touched. Runtime enforcement is different: it evaluates each request before access is granted and can block, filter, or require approval based on policy. In agentic environments, that distinction matters because the agent may choose tools, actions, and timing in ways that cannot be safely assumed in advance. Discovery produces an inventory; enforcement produces a control point. Without enforcement, the organisation can describe the problem in detail while still allowing the same access paths to remain open.
Practical implication: move from agent inventory to decision-time authorization before production use expands.
Why human IAM and workload identity do not fully fit agents
Human IAM assumes a person has a durable identity, a stable access relationship, and an auditable trail tied to known privileges. Workload identity assumes deterministic software with predictable call patterns and bounded scope. AI agents break both assumptions because they can alter actions based on runtime context and should not inherit broad human rights across sessions. That is why the article’s blended identity framing matters: the agent needs a verified identity, but its authority must be narrower, shorter-lived, and context-aware rather than borrowed wholesale from the user or application.
Practical implication: review where human or workload identity patterns are being stretched to cover agent behaviour they were not built for.
What blended identity changes at the control plane
Blended identity combines user context with agent context and applies authorization at the moment of access. In practice, that means the control plane can issue short-lived credentials only when the requested tool, resource, and action align with policy. This is the key technical shift in the article: the control is not simply who the agent is, but what the agent is allowed to do on behalf of a user, in a specific moment, with a specific task. That makes runtime policy the operative security boundary rather than static account provisioning.
Practical implication: design agent access around task-scoped issuance and policy evaluation, not persistent standing permissions.
NHI Mgmt Group analysis
Visibility without enforcement is not an identity control. The market can discover AI agents, map connections, and still leave the real decision point untouched. That creates a governance illusion: teams believe they understand the environment while access remains governed only after the fact. For identity programmes, the lesson is that runtime authorization is now the control plane, not a reporting layer.
The agent security problem exposes an assumption collapse in human IAM. Human access governance was designed for identities whose rights are durable enough to review and recertify. That assumption fails when an AI agent’s useful authority must be task-scoped, conditional, and short-lived. The implication is not just a tighter policy model, but a rethink of what “access” means when the actor is not a person.
Workload identity alone cannot describe agent behaviour. Deterministic service-to-service access assumes predictable call paths and stable purpose. AI agents can vary their tool selection and timing at runtime, which means the access decision must evaluate context, not just identity. Practitioners should stop treating agent access as a special case of workload identity and treat it as its own governance boundary.
Blended identity is a control concept, not a branding concept. The useful insight is the separation of user context from agent context, with policy deciding whether the requested action is allowed. That preserves attribution while preventing wholesale inheritance of the user’s access rights. For the field, this is where agent security starts to look like real governance instead of identity expansion.
Runtime authorization gap: The article names the real market defect correctly: organisations can list agents without being able to govern them at the moment of access. That gap will widen as more business workflows depend on agent decisions. The practitioner conclusion is simple: if access cannot be decided in real time, it is not yet governed.
From our research library:
- Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.
- Read next: AI Agent Authorisation Guide
What this signals
Runtime authorization gap: Agent security programmes will keep underperforming if they remain discovery-led. The control question has shifted from what is running to what is allowed to happen at the moment a request is made, and that means policy enforcement must move closer to the access decision.
Visibility-first tooling will still matter for inventory and investigation, but it will not close the governance gap on its own. Teams should expect the next phase of agent security to look more like access policy engineering than dashboard expansion, especially where task-scoped credentials and human context both matter.
For practitioners
- Define runtime authorization for agents Set policy to decide each agent request at the moment of access, using agent identity, user context, requested action, and target resource as separate inputs.
- Separate agent rights from user rights Do not let an agent inherit the full access scope of the human session it supports. Scope permissions to the task and expire them when the task ends.
- Inventory where visibility stops short Review current agent-discovery tools to see whether they only describe connections and logs, or whether they can actually block disallowed access paths.
- Replace static credentials with short-lived issuance Use credentials that are issued only for the specific request and withdrawn after completion so access does not accumulate across sessions.
Key takeaways
- AI agent security becomes an authorization problem once agents can choose tools and actions at runtime, not just an inventory problem.
- Visibility can describe agent activity, but it cannot by itself prevent overbroad access, inherited rights, or approval bypass.
- The practical shift is toward task-scoped, short-lived access decisions that combine user context with agent context at the control plane.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on agent access decisions and overbroad inherited rights. |
| ASI02 — Tool Misuse | The core risk is agents using tools without runtime enforcement. | |
| Recommendation — Apply ASI03 to prevent agents from inheriting permissions that exceed task scope. Map agent tool access to ASI02 and block requests that fall outside policy. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Agent identities are being granted more access than they need across sessions. |
| NHI-07 — Long-Lived Secrets | The article warns about credentials persisting in workflows and exceptions. | |
| Recommendation — Audit agent permissions for overprivilege and reduce standing access to task scope. Replace persistent agent credentials with short-lived issuance and explicit expiry. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle control is central to short-lived agent access. |
| Recommendation — Use IA-5 to govern issuance, expiry, and revocation of agent authenticators. | ||
Key terms
- Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
- Blended Identity: Blended identity occurs when an autonomous system acts partly on behalf of a person and partly under its own machine authority. This creates split accountability because one actor may initiate the task while another identity performs the privileged action across different systems.
- Visibility Without Enforcement: Visibility without enforcement means an organisation can see what identities are doing but cannot stop or constrain those actions in real time. It produces logs, dashboards, and inventories, but it does not itself prevent misuse, overreach, or policy bypass.
- Task-Scoped Credential: A task-scoped credential is a secret or token limited to one specific job, workflow, or short time window. It reduces the chance that an AI agent or automation process can reuse access outside its intended purpose, which is essential when the system can operate continuously or autonomously.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org