TL;DR: AI agents, MCP, ephemeral clients, and API access across trust domains are drawing growing focus, according to Curity’s recent how-to and article set, underscoring how identity controls are being stretched by dynamic, non-human execution paths. The gap is no longer theoretical: governance built for stable credentials and human-paced review cannot fully model runtime agent behaviour.
At a glance
What this is: Curity examines how AI agents and ephemeral clients expose a widening governance gap in non-human identity controls, especially where runtime behaviour and cross-domain access outpace stable credential models.
Why it matters: IAM and NHI teams need to reassess how they govern dynamic, short-lived access paths, because review-based controls and static trust assumptions break down when execution and authorisation move at runtime.
Context
AI agents and ephemeral clients change the basic assumptions behind identity governance. When access is created, used, and discarded within fast-moving runtime sessions, controls designed around stable accounts, predictable renewal, and human review no longer model the real behaviour of the actor.
For NHI and IAM teams, the issue is not simply that there are more non-human identities. The deeper problem is that trust is now being negotiated dynamically across API boundaries, trust domains, and orchestration layers, which means governance has to understand intent, scope, and lifecycle at the moment access is exercised.
Key questions
Q: What breaks when AI agents and ephemeral clients are governed like stable accounts?
A: The control model breaks because stable-account governance assumes access persists long enough to be reviewed, certified, and later revoked. Ephemeral clients and AI agents can create and consume access inside a much shorter runtime window, so the real control point becomes issuance, scope, and trust-domain containment rather than post-use review.
Q: Why do short-lived non-human credentials create more governance risk across APIs?
A: Short-lived credentials reduce persistence, but they can increase risk when they cross multiple APIs or trust domains without shared context. Each system may only see part of the delegation chain, which makes revocation, accountability, and scope validation harder. The risk is not the short lifetime itself, but the distributed trust path it creates.
Q: How can teams tell if non-human access is outgrowing their identity model?
A: Look for signs that access decisions are happening faster than review, that tokens are accepted across more systems than governance tracks, and that revocation does not propagate cleanly through the full chain. If the programme can describe identities but not the runtime trust path they travel, the model is already behind.
Q: How should security teams handle delegated access when AI agents act on behalf of customers?
A: Security teams should treat delegated access as a separate governance layer, not as a normal login session. Define what the agent can do, how much value it can move, which approvals are required, and how delegation is revoked. Without those boundaries, the agent inherits more authority than the customer intended and fraud risk expands quickly.
Technical breakdown
Why ephemeral clients break credential-centred governance
Ephemeral clients are identities whose value comes from short-lived, task-specific use rather than persistence. That sounds safer than long-lived credentials, but it also means the governance object changes from a durable account to a transient access event. Traditional IAM expects an identity to exist long enough for registration, review, and revocation. Ephemeral clients compress that lifecycle into runtime execution, so the control point shifts toward issuance, token scope, and trust metadata rather than later inspection. In practice, this exposes a mismatch between static policy design and dynamic access behaviour.
Practical implication: move governance focus from post-issue review to issuance-time constraints, scope control, and lifecycle metadata.
How AI agents widen the runtime trust boundary
AI agents are not just automated clients. When they choose actions, tools, or call sequences during execution, the trust boundary expands beyond a single request and into the full task flow. That matters because authorisation is no longer a one-time decision about a known path. The access pattern can shift as the agent evaluates context, selects tools, and proceeds through chained operations. The result is a governance problem that looks like identity, but behaves like workflow plus identity. Curity’s topic set points to that shift in the way AI agents and human oversight now interact with federated access patterns.
Practical implication: treat agent runtime behaviour as part of the authorisation surface, not as a separate orchestration detail.
What cross-domain API access changes for NHI governance
Cross-domain API access is where governance gaps become visible. Each trust domain often assumes the caller has already been authenticated, authorised, and bounded elsewhere, but that assumption weakens when access is stitched together across services, OAuth flows, and ephemeral clients. The technical problem is not simply more APIs. It is that the chain of trust becomes distributed, with different systems carrying partial context about the same non-human actor. That produces blind spots in accountability, delegation, and revocation, especially where access spans partner systems or separate administrative domains.
Practical implication: map end-to-end trust chains across domains so delegated access and revocation can be governed as one lifecycle.
Breaches seen in the wild
- Taiwan autonomous AI agent cyberattack 2026: Up to eight autonomous AI agents cracked 85 Taiwanese government accounts, pivoted through SSO and exfiltrated 2,564+ personnel records.
- Salesloft OAuth token breach: hackers stole OAuth tokens to access Salesforce data via Salesloft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Ephemeral trust is now a governance object, not a transport detail. Curity’s topic shows that short-lived clients are changing what identity teams must govern. When access exists only briefly, the control problem is no longer whether a credential can be reviewed later, but whether the access boundary was correct at issuance. That shifts authority from after-the-fact certification toward runtime trust decisions, which many programmes still do not model. Practitioners should treat ephemeral trust as a first-class governance domain.
Human-paced review assumptions collapse when runtime behaviour becomes agent-paced. Access review processes were designed for identities that remain stable long enough to be observed, certified, and remediated. That assumption fails when an AI agent can obtain and use access within a single task cycle, or when an ephemeral client disappears before the next review window. The implication is not simply faster tooling, but a different governance model for non-human execution. Practitioners need to recognise that review cadence is no longer the primary control boundary.
Dynamic trust exposes an identity blast radius problem across trust domains. When non-human access crosses APIs, identity providers, and partner boundaries, the governance question becomes how far a single trust decision can propagate. That broadens blast radius beyond the token itself and into the connected systems that accept its claims. The article’s theme reinforces that federated identity for non-human actors is only as safe as the narrowest trust domain in the chain. Practitioners should assess where delegated trust expands more quickly than revocation can contain it.
Runtime authorisation for agents needs a named concept: identity blast radius. This is the distance between the access decision and the systems a non-human actor can reach before governance can intervene. In AI agent and ephemeral client flows, that radius can grow inside the same session, especially when tools, APIs, and trust domains are chained together. The implication is that identity programmes should measure how far access can travel after issuance, not just whether a credential was valid at the start.
OWASP-NHI and Zero Trust thinking both become more relevant when access is disposable. Ephemeral clients narrow the lifetime of credentials, but they do not remove the need to govern offboarding, scope, and trust domain separation. The real issue is whether the control model can follow a non-human actor whose permissions are real only for a narrow execution window. Practitioners should align governance to the actor’s runtime behaviour, not to assumptions borrowed from human identity.
From our research library:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to the Ultimate Guide to NHIs.
- 64% of valid secrets leaked in 2022 are still valid and exploitable today, proving that detection alone is not enough without automated revocation, according to the State of Secrets Sprawl 2026.
- Read next: NHI Authentication Guide
What this signals
Identity blast radius will become a planning metric for NHI programmes. Teams can no longer think only in terms of token lifetime or credential hygiene. They need to understand how far a runtime trust decision can travel before containment catches up, especially when ephemeral clients traverse multiple services and trust domains.
Assurance must move closer to issuance. Access review is still useful, but it is no longer the primary control for fast-moving non-human actors. The programme question becomes whether trust can be bounded at the moment of issuance and whether downstream systems can enforce that boundary consistently.
Federated non-human access needs a narrower trust contract. The more systems infer trust from shared identity claims, the more likely governance becomes fragmented. Practitioners should expect future NHI architecture work to focus on reducing delegated scope, not just reducing credential lifetime.
For practitioners
- Map ephemeral client lifecycles end to end Document how ephemeral clients are created, scoped, used, and retired across identity providers, APIs, and downstream services. Identify every point where trust is assumed rather than verified, especially when access crosses administrative boundaries.
- Bind runtime authorisation to task scope Limit non-human access to the smallest practical action set for each execution path, and ensure tokens or assertions expire with the task rather than with a generic session timer. Use explicit trust metadata so downstream systems know what the actor was allowed to do.
- Rework access review assumptions for agents Stop assuming that review cycles can validate access that may only exist for minutes or seconds. Shift governance checks toward issuance criteria, trust-domain boundaries, and whether the actor can still be meaningfully recertified after execution.
- Track cross-domain revocation paths Verify that revocation of an ephemeral credential actually propagates through all connected systems that accepted the original claims. Where delegation chains exist, define who can cut access and how quickly that action is enforced across domains.
Key takeaways
- AI agents and ephemeral clients expose a mismatch between dynamic runtime access and governance models built for stable identities.
- The main risk is not merely shorter credential lifetime, but trust decisions that travel farther and faster than identity teams can review.
- Practitioners should move governance toward issuance-time scope, trust-domain boundaries, and end-to-end revocation paths.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST Zero Trust (SP 800-207) sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Ephemeral clients and AI agents depend on runtime authentication that must stay trustworthy across short-lived sessions. |
| NHI-05 — Overprivileged NHI | Cross-domain API access raises the risk that non-human actors accumulate broader scope than governance intended. | |
| NHI-08 — Environment Isolation | The article focuses on trust boundaries across domains, which depends on keeping non-human execution isolated. | |
| Recommendation — Validate runtime authentication paths for ephemeral non-human actors and remove any trust assumptions that outlive the session. Reduce non-human scope to the minimum set of claims and permissions required for each execution path. Separate trust domains so ephemeral clients and agents cannot carry assumptions or permissions across boundaries unchecked. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | AI agents that select actions at runtime can expand privilege use beyond static governance expectations. |
| Recommendation — Constrain agent privileges to the narrowest approved action set and monitor runtime privilege use continuously. | ||
| NIST Zero Trust (SP 800-207) | Continuous verification and least privilege | Dynamic trust across APIs aligns with zero trust principles for ongoing verification of non-human access. |
| Recommendation — Apply continuous verification so each API call is evaluated against current trust, context, and scope. | ||
Key terms
- Ephemeral Client: An ephemeral client is a short-lived application or service client that should receive credentials only for the duration of a specific task or runtime window. These clients reduce standing privilege, but they still require registration, ownership, and revocation controls to avoid orphaned access.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Runtime Trust: Runtime trust is the idea that access should remain valid only while current context justifies it. Instead of trusting a setup decision indefinitely, teams continuously re-evaluate whether a workload or agent still deserves privilege. This approach is especially important for AI agents that can change behaviour mid-task.
- Delegation Chain: A delegation chain is the sequence of identities, credentials, and tool calls an agent uses to complete a task across systems. It matters because each step may appear acceptable on its own while the combined path produces an outcome no reviewer would have approved directly.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org