TL;DR: AI agents are being connected to data, tools, and decisions faster than security teams can assess them, and Akto’s guide argues that point controls fail unless they are joined into a program with discovery, ownership, risk management, validation, and operations. The real governance gap is not just detection, but accountable control of delegated identity and autonomous behavior.
At a glance
What this is: This is a guide to building an AI agent security program, with the core finding that AI agents need a governed lifecycle because point controls alone cannot manage discovery, ownership, risk, validation, and operations.
Why it matters: It matters because IAM, PAM, and NHI teams are now being asked to govern agent identities that are linked to tools and data without the same intake, review, and accountability patterns used for human access or traditional workloads.
👉 Read Akto's guide to building an AI agent security program
Context
AI agent security program work fills the gap between traditional IAM, app security, and cloud controls. AI agents can be connected to internal tools, data, and browser workflows in a few clicks, which means identity governance has to account for delegated access, ownership, and ongoing validation from the start. The relevant question is no longer whether an agent exists, but whether the organisation can govern it as an identity-bearing actor.
The first failure mode is organisational, not technical. When no one owns the agent, alerts are ignored, inventories decay, and risk reviews never become operational. That is why the guide treats discovery, ownership, policy, and validation as a single operating model rather than as separate point solutions. For teams building this capability, the policy and lifecycle patterns in the Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs are the closest adjacent governance model.
Key questions
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
Q: When does AI governance become an IAM and NHI problem?
A: It becomes an IAM and NHI problem as soon as autonomous systems use credentials, APIs, or delegated access to perform actions. At that point, the quality of identity assignment, privilege scope, logging, and lifecycle control determines whether the system can be governed and audited responsibly.
Q: What breaks when an organisation only uses point controls for AI agents?
A: Point controls can reduce a single risk, but they do not solve ownership, inventory, policy scope, or response. If no one knows the agent exists, a prompt filter or guardrail may never be applied. That is why agent security needs an operating model, not a collection of isolated controls.
Q: Who should be accountable for AI agent security incidents?
A: Accountability should sit with the team that owns the agent's business function and permission model, not with a single security tool owner. If the organisation cannot name who approved the agent's scope, who can revoke it, and who reviews runtime exceptions, the governance model is incomplete.
Technical breakdown
Why point controls fail for AI agents
AI agents create a control problem because they sit between application governance and identity governance. A prompt filter, data-loss rule, or single-app guardrail may reduce one attack path, but it does not answer basic questions about discovery, ownership, or policy scope. If an agent can be created quickly and connected to tools before security sees it, the control surface is already too late. Security has to treat the agentic estate as an inventory problem first and a protection problem second, because no control can be reliably enforced against an unknown population.
Practical implication: build a discovery-first operating model before adding specialised guardrails.
Ownership and approval gates for agent identities
The guide separates business ownership, technical ownership, and security ownership because AI agents are not self-governing systems. Business owners decide whether the agent is worth the risk, technical owners manage prompts, tools, authentication, and change, and security owners assess exposure over time. An approval gate matters because ownership created after deployment does not prevent shadow growth. This is an identity lifecycle issue as much as a governance issue: if the agent goes live without accountable ownership, the programme has already failed its first control point.
Practical implication: require named owners and an intake step before any agent reaches production.
Why continuous validation matters in the agentic attack surface
Validation must test behaviour, not just configuration. AI agents change as models update, prompts are rewritten, and tools evolve, which means a one-time review cannot prove ongoing safety. Red teaming, automated prompt-injection testing, privilege-escalation checks, and data-exfiltration attempts are the right mechanism because they examine how the agent behaves under adversarial pressure. That shift is important for IAM and NHI teams because authority can be delegated cleanly on paper while runtime behavior still drifts into unsafe tool use or data access.
Practical implication: schedule recurring behavioural testing for critical agents and retest after any material change.
Threat narrative
Attacker objective: The attacker objective is to abuse weak governance around agent identities so that delegated access can be used for data exposure, tool misuse, or unauthorised action.
- Entry occurs when an employee connects an AI agent to internal systems, tools, or browser workflows with minimal review, creating an unmanaged delegated identity.
- Escalation follows when the agent inherits broad tool access, with prompts, integrations, or over-permissioned credentials expanding what it can reach and influence.
- Impact is realised when an unowned or unvalidated agent makes unsafe decisions, exposes data, or executes actions that were never explicitly intended by the organisation.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI agent security is becoming an identity governance problem before it becomes a tooling problem. The guide is right to move beyond point controls because discovery, ownership, policy, validation, and operations only work when they are treated as one programme. For IAM and NHI teams, the key insight is that an agent with delegated identity is not just another application asset. It is a runtime identity that needs lifecycle control, accountability, and repeatable review.
Shadow AI is the agentic version of shadow IT, but the blast radius is larger. The guide’s inventory sections describe approved, internal, third-party, and shadow agents, which is the right taxonomy for operational control. The named concept here is agentic visibility gap: the state where organisations cannot reliably enumerate agents, their tool connections, or their owners. That gap makes policy enforcement and incident response reactive instead of preventive, which is why discovery has to precede policy precision.
Ownership without validation is a false sense of control. A named owner tells you who is responsible, but not whether the agent is currently safe after a model, prompt, or tool change. That distinction matters because agent behaviour is dynamic, and the control you approved last month may not describe today’s runtime reality. The programme implication is that AI governance cannot stop at approval and inventory; it has to measure whether behaviour still matches the intended access model.
The maturity model is useful because it shows that AI agent governance is an operating discipline, not a project. The progression from ad hoc response to operational excellence mirrors how strong identity programmes mature across human users, service accounts, and now agents. That continuity matters: the discipline is familiar, but the actor is new. Practitioners should therefore extend established IAM and NHI lifecycle thinking rather than inventing a separate security universe for every agentic use case.
Agentic access review assumptions are already being stretched by autonomous workflows. Access review processes were designed for stable entitlements that persist long enough to be observed and certified. That assumption fails when an agent can be created, connected, modified, and retired faster than a review cycle closes. The implication is not merely to add more review cadence; it is to rethink what evidence of access even looks like in an agentic environment.
From our research:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- For a broader lifecycle lens, see Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs for provisioning, rotation, and offboarding patterns that now need to extend to agents.
What this signals
Agentic visibility gap: security programmes will increasingly be judged on whether they can enumerate agents, owners, and tool connections in near real time. If inventories lag the rate of agent adoption, policy enforcement and incident response will always arrive too late. The governance pattern now looks closer to continuous identity hygiene than periodic review, and the NHI lifecycle model is the nearest operational analogue.
With 72% of organisations already reporting or suspecting an NHI breach in our research, the control gap is no longer theoretical. Agent programmes need to assume that undocumented access paths already exist, then prove otherwise through continuous discovery and behavioural validation. That is where the discipline aligns with the NIST Cybersecurity Framework 2.0: identify, protect, detect, respond, and recover must all cover agents as well as humans.
The practical signal for IAM leads is that ownership and validation metrics will matter more than raw agent counts. If the organisation can say how many agents are approved, owned, revalidated, and retired, it can govern the estate. If it cannot, then shadow AI is already shaping access decisions outside the programme.
For practitioners
- Build a live agent inventory Track approved, internal, third-party, and shadow agents in one maintained inventory, including owner, purpose, connected tools, data access, risk tier, and last validation date.
- Require named ownership before production Assign business, technical, and security owners during intake, and block production use until the approval gate records responsibility and risk review.
- Classify agents by exposure and impact Use a risk register to prioritise critical agents that can reach sensitive systems, influence consequential decisions, or expose material data and funds.
- Test behaviour continuously Run recurring red teaming, prompt-injection tests, privilege checks, and exfiltration attempts on critical agents, then repeat validation after prompts, models, or tools change.
- Tie agent governance to incident operations Define how to disable affected agents quickly, preserve relevant logs, and feed lessons back into policy, controls, and leadership reporting.
Key takeaways
- AI agent security fails when discovery, ownership, and validation are treated as separate tasks instead of one operating model.
- Agent inventories and named accountability are now baseline controls, because unaudited access can move from creation to impact faster than review cycles can respond.
- The right maturity target is continuous behavioural assurance, not just approval, because agent runtime behaviour changes after deployment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | The guide addresses AI agent discovery, ownership, and runtime validation. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Agent identities need lifecycle and access governance like other NHIs. |
| NIST CSF 2.0 | PR.AC-4 | Agent access governance depends on managed permissions and review. |
| NIST AI RMF | GOVERN | The programme is about AI governance, accountability, and oversight. |
| NIST Zero Trust (SP 800-207) | Agent access should be continuously verified and least-privileged. |
Use agentic AI risk patterns to govern discovery, tool use, and validation across agent workflows.
Key terms
- AI Agent Authentication: The method an autonomous software agent uses to prove identity and obtain access to systems, APIs, and data. In enterprise settings, this is an NHI control point because the authentication choice determines scope, revocation speed, and whether access can be governed as part of the identity lifecycle.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Agentic Identity Gap: The mismatch between legacy identity governance and AI agents that make access decisions at runtime. It appears when controls assume the actor is stable, predictable, and reviewable after the fact, while the system can create ephemeral identities and change tool use mid-session.
- Continuous validation: Continuous validation is the practice of re-checking user, device, or session risk after login instead of trusting access indefinitely. It recognizes that identity assurance can drift during a session, especially when endpoint state or user context changes after authentication.
What's in the full article
Akto's full guide covers the operational detail this post intentionally leaves for the source:
- Step-by-step five-pillar operating model for agent discovery, ownership, risk management, validation, and operations
- Maturity model with level-by-level indicators for moving from ad hoc response to operational excellence
- Practical inventory fields for approved, internal, third-party, and shadow agents
- Security review and incident workflow guidance for AI agent governance teams
👉 Akto's full guide covers the five pillars, maturity model, and operational checklist in detail.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM, PAM, or identity governance programme, it is worth exploring.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org