By NHI Mgmt Group Editorial TeamBased on Defakto Security: “Your AI Agents Aren’t Hidden. They’re Ungoverned. It’s time to Act” (December 15, 2025)

TL;DR: AI agents are already operating in enterprise environments with excessive access, static API keys, and weak oversight, according to Defakto Security. Waiting for perfect discovery before governing them only extends exposure and leaves legacy controls blind to runtime behaviour.


At a glance

What this is: This is an analysis of why AI agent governance fails when teams wait for complete discovery instead of governing the agents already visible in their environment.

Why it matters: It matters because identity teams need to treat AI agents as governed non-human identities with runtime access controls, not as a visibility problem that can be solved later.


Context

AI agent governance is the discipline of controlling non-human systems that act on behalf of a business process, whether those systems are copilots, scripted automations, or API-driven workloads. The failure mode in this article is not hidden activity. It is unmanaged activity that security teams can already see but have not brought under identity governance.

The article argues that discovery-first thinking creates a false comfort loop. In practice, organisations already have enough signal from logs, API portals, code repositories, and secret stores to begin governing the highest-risk agents. The problem is not the absence of visibility, but the absence of control over AI agents that already exist in the estate.


Key questions

Q: What breaks when AI agent discovery is incomplete?

A: When discovery is incomplete, the organisation cannot know which agents exist, what they are connected to, or what they can access. That leaves policy enforcement, enrichment, and review operating on a partial inventory, which is the same as governing only part of the environment. Hidden agents become hidden access paths.

Q: Why do static API keys create risk for AI agent access?

A: Static API keys create risk because they are long-lived, reusable, and difficult to tie to a specific action. In an agentic environment, that means the same secret can be replayed across tools, sessions, or workloads long after the original task is complete. Short-lived delegated credentials give teams a much better chance of limiting scope and preserving accountability.

Q: When does AI model governance usually fail in practice?

A: It usually fails when documentation begins after deployment. At that point, model inventories are already stale, relationships to use cases are missing, and engineering teams have moved on to newer versions. Governance is weakest when it depends on manual follow-up instead of capturing model details at the moment the asset is created.

Q: How should organisations contain AI agents in legacy environments?

A: Treat legacy systems as high-risk by default and narrow each agent to the minimum resources required for the workflow. Broad inherited permissions let agents overreach, even when the original intent was benign. The practical goal is to constrain blast radius before the agent can chain calls across systems.


Technical breakdown

Why static API keys create AI agent exposure

Most AI agents in the article authenticate with static API keys, which means the identity is not bound to a runtime session and cannot be constrained by context once issued. That makes the credential itself the control point, and when the key is copied into CI/CD pipelines, config repos, or secret stores, the blast radius expands across environments. This is a classic non-human identity problem: the same secret can authorize repeated actions long after the original task or owner has changed. The technical weakness is not just leakage, but the lack of runtime attestation and per-action authorisation.

Practical implication: Replace reusable API keys for high-risk agent workflows with identities that can be authenticated and authorised per action.

How overpermissioned legacy systems let AI agents overreach

Legacy environments were built for human users with bounded workflows, not for autonomous or semi-autonomous software that can probe interfaces and chain calls at machine speed. When those environments expose broad permissions and weak segmentation, an AI agent can exceed the task it was intended to perform even without malicious intent. The issue is privilege scope, not just access volume. Fine-grained controls matter because agent behaviour is dynamic at runtime and can expand into adjacent systems if the policy boundary is too coarse. In identity terms, the agent inherits more capability than the business process requires.

Practical implication: Scope AI agent access to narrowly defined resources and remove broad inherited permissions from legacy platforms.

Why governance blindness appears when reviews are static

Manual review cycles and static policies do not keep pace with AI agents that are created, modified, and reused across scripts, SaaS copilots, and cloud workflows. Once the agent count rises, the organisation faces an audit problem: it may know keys exist, but not what each agent is actually doing at runtime. Identity-based telemetry is therefore more than logging. It becomes the mechanism for turning partial discovery into an actionable control plane that ties usage, access, and accountability together. Without that link, visibility remains descriptive instead of governable.

Practical implication: Move from periodic reviews to continuous identity telemetry that shows what each agent accessed and when.


NHI Mgmt Group analysis

Perfect discovery is the wrong governance threshold for AI agents. Security teams already have enough signal to start governing visible agents through logs, API portals, repository scanning, and secret-store inspection. The discipline changes from finding every agent to reducing the risk of the agents already in production, which is where exposure actually lives.

Static API keys are the wrong trust model for agentic systems. A reusable secret assumes the same authority remains valid across repeated actions, environments, and owners. That assumption breaks when an AI agent can act across sessions and workloads, which is why runtime authentication and authorisation become the real control surface.

AI agents expose the limits of human-designed privilege boundaries. Legacy systems often grant broad access because they were designed around trusted people rather than machine-paced execution. When an agent can chain calls, probe interfaces, and reuse credentials at scale, the organisation discovers that overpermissioned access is a structural weakness, not a tuning issue.

Identity creates visibility only when it is tied to action, not inventory. Listing agents is useful, but the higher-value outcome is an audit trail that shows what each identity did in the environment. That shifts governance from one-time discovery to continuous control, which is the only model that scales as agent counts grow.

Ephemeral discovery without governance is a dead end for agentic AI programmes. The article points to a broader market shift: AI governance is moving from passive inventory toward active runtime control. Practitioners should treat AI agents as governed non-human identities from the start, because that is where the security model now begins.

From our research library:

What this signals

Runtime control will outlast inventory-driven governance: AI programmes that begin with identity and access controls establish a usable security baseline sooner than programmes that wait for complete discovery. Once an agent is identified, it can be scoped, observed, and constrained even if the wider inventory is still incomplete.

That shift matters because AI agents behave like non-human identities that need continuous oversight, not one-time classification. The security programme is moving from naming every instance to governing the access paths, credentials, and runtime behaviour that make the instance dangerous.

According to the 2026 Infrastructure Identity Survey, 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems. For practitioners, that is a signal that the control model, not just the tooling, is being rewritten.


For practitioners

  • Prioritise the AI agents you already know about Rank visible agents by data sensitivity, production exposure, and whether they reuse static keys across multiple systems.
  • Eliminate static API key sprawl first Replace copied and shared API keys with short-lived, verifiable identities for the highest-risk LLM and agent workflows.
  • Instrument runtime identity telemetry Track what each agent actually accessed, which endpoints it called, and whether the actions matched the approved workload.
  • Tighten access boundaries in legacy systems Remove broad inherited permissions and apply fine-grained policies so agents can only reach the systems required for the task.

Key takeaways

  • AI agents become a governance problem when they are left operating with static credentials and broad access in environments built for human users.
  • Discovery helps, but it does not reduce risk on its own if the organisation already knows where the highest-risk agents are running.
  • Identity-bound runtime control is the practical step that turns partial visibility into enforceable security.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article is about AI agents using excessive access and static credentials beyond intended scope.
Recommendation — Apply ASI03 to constrain agent identity, privilege, and runtime authorisation before deployment.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationStatic API keys and weak runtime identity checks are the core access pattern in the article.
NHI-05 — Overprivileged NHIThe article repeatedly highlights excessive access in legacy environments.
NHI-07 — Long-Lived SecretsCopy-pasted API keys and shared secrets are presented as a central risk.
Recommendation — Replace static API keys with verifiable NHI authentication for agent workflows. Reduce agent permissions to the minimum required for each task and environment. Eliminate long-lived secrets for AI agents and use short-lived credentials instead.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing entitlements for AI agents already in the environment.
Recommendation — Apply PR.AA-05 to review and constrain AI agent access rights continuously.

Key terms

  • AI Agent Governance: AI Agent Governance is the set of policies, controls, and oversight practices used to direct how autonomous software agents behave. It defines allowed actions, approval paths, identity boundaries, logging, monitoring, and accountability so agent decisions remain traceable, constrained, and aligned with business, security, legal, and ethical requirements.
  • Static API Key: A static API key is a long-lived secret used to identify and authorize a client when calling an API. It is usually issued once and reused until manually rotated or revoked. Because it does not expire quickly, it creates persistent access risk and requires strong storage, monitoring, and lifecycle control.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org