By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: AktoPublished December 31, 2025

TL;DR: Enterprise AI crossed from copilots into production infrastructure in 2025, with agents, MCP, and governance moving into core systems as firms operationalised execution, control, and accountability, according to Akto. The central issue is no longer whether AI is used, but whether organisations can see, scope, and govern what these systems can do before they act.


At a glance

What this is: This is a year-in-review analysis showing that AI shifted from assistive tooling into enterprise infrastructure, with governance and runtime control becoming the central problem heading into 2026.

Why it matters: It matters because IAM, NHI, and security teams now have to govern AI systems that behave like production identities, reach tools dynamically, and execute work inside real enterprise workflows.

By the numbers:

👉 Read Akto's 2025 AI yearbook on enterprise AI infrastructure and governance


Context

AI became enterprise infrastructure when agents started reaching production systems, not just answering prompts. The primary governance gap is that most identity programmes were built for users and service accounts that act within explicit, pre-scoped workflows, while AI agents now combine tools, data, and execution paths dynamically across enterprise environments.

This 2025 yearbook uses that shift to frame the 2026 control problem for AI agent identity, MCP exposure, and runtime governance. The right question is no longer whether AI is in the stack, but which actions it can take, how those permissions are approved, and what is revoked when the system changes role or scope.

That is a materially different operating model from assistive copilots. It is also why identity, policy enforcement, and lifecycle control now sit at the centre of AI security rather than beside it.


Key questions

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.

Q: Why do AI agents complicate existing IAM and PAM controls?

A: AI agents complicate IAM and PAM because they often inherit delegated credentials, operate across multiple systems, and keep acting after the initial approval moment has passed. Human session assumptions, periodic reviews, and static privilege models do not reflect that behaviour. The result is a governance gap between what was granted and what the agent can actually do.

Q: What do security teams get wrong about ASPM in agentic environments?

A: They often treat ASPM as a reporting layer instead of a decision layer. In agentic workflows, the problem is not finding more issues, but connecting findings to the context that determines business impact, ownership, and urgency. If posture data cannot drive prioritisation, the programme becomes noise management rather than risk management.

Q: How do organisations know if AI agent governance is actually working?

A: Look for three signals: every production agent has a named owner, access decisions are enforced during runtime, and audit trails show when requests were allowed, denied, or escalated. If teams can only describe agent behaviour in hindsight, governance is still incomplete.


Technical breakdown

AI agents and MCP created a new identity surface

AI agents are not just consumers of APIs. When they can dynamically connect to MCP servers, browse tools, and execute multi-step workflows, they become runtime identities with active access paths. MCP is an integration layer, but in practice it expands the trust boundary because the agent can reach external systems through a tool interface that may change over time. That makes permissions, tool registration, and approval scope part of identity governance, not just application design. The key technical issue is that access can be assembled at runtime from multiple components, which makes static entitlement models incomplete.

Practical implication: Model each agent-to-tool connection as governed access and review who can register, modify, or revoke those tool paths.

Governance must move from model oversight to runtime control

The article's central shift is from judging model capability to controlling execution. Governance becomes meaningful only when it can constrain when an agent may act, what tools it may reach, and which actions require approval. That is a different problem from content moderation or prompt filtering. Runtime controls sit closer to PAM, NHI governance, and zero standing privilege thinking because the risk is not just what the system knows, but what it can do at the moment of execution. Once agents are embedded in ERP, engineering, and data systems, control has to be enforced where action occurs.

Practical implication: Place approval, scoping, and logging controls at execution time, not only at provisioning or design review.

Agent identity lifecycle now matters as much as human lifecycle

When AI systems become production infrastructure, they need lifecycle treatment comparable to other non-human identities. That includes creation, ownership, scope review, rotation of supporting credentials, offboarding, and change control when the workflow or business purpose changes. The article makes clear that the real challenge is not adoption alone but governance at scale across environments and third-party integrations. For identity teams, this means AI agents should no longer be treated as feature flags or experiments. They are operational identities with access that must be continuously governed.

Practical implication: Bring AI agents into the same lifecycle and recertification discipline used for other non-human identities.


Threat narrative

Attacker objective: The objective is to use trusted AI access paths to execute actions inside enterprise systems without triggering the controls applied to traditional users.

  1. entry: The actor enters through legitimate AI agent exposure, typically via connected tools, MCP servers, or delegated enterprise access.
  2. escalation: The agent expands reach by chaining permitted tools and workflows across systems that were never scoped as one identity boundary.
  3. impact: Execution occurs inside production systems, creating business-process manipulation, data exposure, or unauthorized operational change.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI infrastructure is now an identity problem, not just a model problem. The article shows that the decisive shift in 2025 was execution, not experimentation. Once agents, MCP, and workflow embedding became normal, the security question moved from model behaviour to who and what can act in production. That is a governance change, not a tooling trend, and practitioners should treat AI systems as governed identities.

Runtime control is the new control plane for enterprise AI. Static policy written at procurement or deployment time cannot keep pace with tools that are assembled dynamically at runtime. Access review, approval gates, and logging only matter if they follow the action path into the environment where the agent actually executes. The implication is that identity teams must focus on runtime authorisation, not just inventory.

Agent identity lifecycle needs the same discipline as other non-human identities. The article repeatedly points to production integration, third-party tools, and cross-system execution. That combination creates identity sprawl unless agents are owned, reviewed, and retired like any other workload identity. The practical conclusion is that lifecycle management is now part of AI governance, not a separate programme.

Ephemeral trust debt: access granted to AI systems today can outlive the workflow it was designed for. The article's own examples show enterprise teams embedding agents into systems faster than governance models can adapt. That creates a trust debt where permissions, tool access, and delegated execution remain in place after the original use case has changed. Practitioners should read that as a warning about accumulated, unmanaged AI privilege.

MCP is becoming the identity bridge layer for agentic systems. When an agent can connect to tools through a common protocol, the risk is no longer only the model or the endpoint. The concern is the trust relationship between agent, tool, and enterprise data source. Identity programmes need to govern that bridge explicitly because otherwise the protocol becomes the easiest way to multiply access without equivalent control.

From our research:

  • Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems, according to The 2026 Infrastructure Identity Survey.
  • Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
  • That governance gap reinforces the case for OWASP Agentic AI Top 10 as a working reference for runtime risk and tool-abuse control.

What this signals

Ephemeral trust debt: the more quickly enterprises embed AI into production workflows, the more they accumulate access that outlives the original use case. With 69% of security leaders already saying identity management must fundamentally shift for agentic AI, the next programme gap will be operational rather than conceptual.

The practical signal is that AI governance cannot stay inside innovation teams. It now belongs with identity, platform, and security operations because agent permissions, tool trust, and lifecycle control are becoming production access issues rather than experimentation issues.

Teams should expect increasing demand for policy coverage around NIST Cybersecurity Framework 2.0 functions that map AI identity ownership, access scoping, and change control into accountable operating processes.


For practitioners

  • Inventory AI agents as governed identities Create and maintain a registry of agents, the tools they can reach, the data they can touch, and the owners responsible for revoking access when scope changes.
  • Bind approvals to runtime execution Require approval gates for high-risk actions such as repository changes, infrastructure updates, payment flows, and data export, rather than relying on design-time trust.
  • Extend lifecycle control to AI systems Apply joiner-mover-leaver style thinking to AI agents by reviewing ownership, purpose, connected tools, and revocation events whenever the workflow changes.
  • Treat MCP endpoints as access boundaries Review which external MCP servers or tool connectors are allowed, how they are authenticated, and what monitoring exists for changes in available actions.
  • Separate experimentation from production privilege Keep pilot agents away from persistent access to enterprise systems until logging, scoping, and revocation processes are in place for the production path.

Key takeaways

  • AI moved into enterprise infrastructure, which turns governance into an access-control problem rather than a model-selection problem.
  • The biggest operational risk is over-privileged AI behaviour, especially where agents can reach multiple tools and data sources at runtime.
  • Identity teams should govern agents as production non-human identities, with ownership, scoped access, and revocation built into the lifecycle.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10A2The article centres on agent execution, tool use, and runtime governance.
OWASP Non-Human Identity Top 10NHI-03The post repeatedly highlights over-privileged AI and delegated access.
NIST CSF 2.0PR.AC-4Access permissions and least privilege are central to the article's governance theme.
NIST AI RMFGOVERNThe article is fundamentally about AI governance becoming operational.
NIST Zero Trust (SP 800-207)The control question is continuous verification of agent access paths.

Map agent workflows to agentic application risks and control tool reach before production rollout.


Key terms

  • Agent Identity: An agent identity is the set of attributes, credentials and permissions assigned to an autonomous software entity. It is treated as a non-human identity because it can authenticate, act on systems and accumulate access over time, which creates governance, audit and lifecycle obligations similar to other production identities.
  • MCP: Model Context Protocol, an open way for AI agents to connect to tools and data sources. It improves interoperability, but it also introduces a shared integration layer that must be governed carefully because the protocol can widen access across many systems at once.
  • Runtime control: Controls that enforce policy while an AI system is operating, rather than after the fact. For healthcare chatbots, runtime control includes data masking, output filtering, access scoping, and immutable logging so the organisation can defend the interaction itself.
  • Ephemeral Credential Trust Debt: Ephemeral credential trust debt is the hidden risk that appears when short-lived tokens create a false sense of safety while permissions remain broad. The credential expires quickly, but the underlying blast radius stays large unless identity scope, revocation, and audit controls are also tightened.

What's in the full article

Akto's full blog post covers the operational detail this post intentionally leaves for the source:

  • The article's full yearbook-style walkthrough of major platform announcements and what they imply for agent governance.
  • Specific examples of enterprise AI adoption across cloud, data, ERP, and workflow systems that show where execution is already happening.
  • The source's framing of MCP, agent runtime control, and governance as the main operating issues heading into 2026.
  • Akto's own discussion of the AI Agent Identity Security Maturity Model and how it maps to control depth.

👉 Akto's full post includes the platform examples, MCP shift, and control questions behind the yearbook view.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org