By NHI Mgmt Group Editorial TeamBased on SailPoint: “The unbreakable link: Why the future of AI in financial services depends on identity security” (April 9, 2026)

TL;DR: Financial services AI governance is converging on identity security as the control layer that ties together access, auditability, and Separation of Duties across human identities, service accounts, and AI agents, according to SailPoint and the U.S. Treasury’s FS AI RMF. The audit question is no longer theoretical: without identity governance, AI controls lose practical enforceability.


At a glance

What this is: This blog argues that AI governance in financial services only becomes enforceable when identity security governs access across humans, service accounts, and AI agents.

Why it matters: It matters because IAM, IGA, and PAM teams will increasingly be the control point that makes AI governance auditable, least-privileged, and operationally real.


Context

In financial services, AI governance is no longer just a policy discussion. The article frames identity security as the mechanism that determines whether access to data, models, APIs, and privileged workflows can actually be governed across human and machine actors.

The governance gap is practical, not theoretical. As agentic AI expands the number of identities touching regulated systems, traditional security layers can describe risk but still fail to enforce who is allowed to do what, when, and under which separation-of-duties constraints.


Key questions

Q: How should financial services teams govern shared credentials across human and AI access paths?

A: Financial services teams should centralize credential ownership, remove shared passwords where possible, and enforce approval, logging, and periodic review for every human and AI access path. The practical goal is to shrink credential sprawl, preserve audit trails, and make offboarding reliable. A strong governance model should show who accessed what, when, why, and under which control.

Q: Why do AI agents complicate traditional access reviews?

A: AI agents complicate access reviews because they can accumulate permissions across tools and environments faster than manual certification cycles can observe. A review process built for stable human accounts does not fit an executor that can act across systems, create new access paths, and complete work before the next review window begins.

Q: What breaks when separation of duties is enforced only on paper?

A: When SoD exists only as policy, teams can still route sensitive actions through manual exceptions, informal approvals, or incomplete workflows. The result is a control that looks present in documentation but fails during execution. The practical failure is not lack of intent, but lack of enforceable entitlement design, reviewer independence, and audit evidence.

Q: How should financial institutions govern AI use without weakening identity and data protection controls?

A: Financial institutions should treat AI adoption as a governance and security programme, not just a technology upgrade. Focus on data protection, access control, model oversight, and continuous review of how sensitive information enters training or inference workflows. The goal is to capture efficiency gains while limiting exposure from deepfakes, prompt abuse, and unauthorized data use.


Technical breakdown

Why identity becomes the control plane for AI governance

AI governance in regulated finance depends on being able to answer who or what accessed which resources, for what purpose, and with what scope. In practice, that means identity security sits between AI policy and execution because identities authenticate to data stores, model endpoints, and application APIs. If those identities are not governed, then governance statements remain aspirational rather than enforceable. The article’s core point is that AI oversight is only as strong as the access layer that binds action to identity.

Practical implication: treat identity governance as the enforcement layer for AI access, not a downstream audit activity.

How human, service account, and AI agent access differ

Financial services already rely on mixed identity estates, but AI agents add runtime variability that makes access harder to reason about. Human identities are managed through authentication and approval flows, service accounts through lifecycle and secret governance, and AI agents through continuous authorisation, scope control, and activity tracing. The key distinction is that AI agents can initiate actions across systems without the stable patterns IAM teams are used to reviewing. That makes governance questions about purpose, delegation, and duration much harder to answer after the fact.

Practical implication: separate governance rules for humans, service accounts, and AI agents instead of forcing one review model across all three.

Why separation of duties still matters in agentic workflows

Separation of Duties remains relevant because AI systems can combine steps that were previously divided across different roles or control points. If one identity can request, process, and approve in the same workflow, the control objective is undermined even when each step looks individually authorised. The article correctly ties this to deep data context and continuous governance, because risk often emerges from combinations of access rather than single entitlements. In finance, this makes policy conflicts and toxic access paths a central AI governance concern.

Practical implication: model SoD at the workflow and identity-combination level, not just at the individual account level.


Threat narrative

Attacker objective: The objective is to turn authorised AI-enabled access into uncontrolled business action that cannot be cleanly audited or constrained.

  1. Entry begins when human identities, service accounts, or AI agents receive access to finance data, models, or APIs without sufficiently bounded purpose or scope.
  2. Escalation occurs when those identities can combine actions across workflows, allowing agentic behaviour to move from routine retrieval into privileged decision or execution paths.
  3. Impact follows when governance cannot produce a defensible audit trail for who accessed what, which prevents reliable enforcement of policy, SoD, and accountability.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity security is no longer adjacent to AI governance in finance, it is the governance substrate. The article is right to collapse the distinction between AI policy and access control because financial institutions cannot govern data use, model interaction, or API invocation without identity as the enforcement point. That aligns with the practical reality of regulated environments where auditability, authorization, and accountability must be provable, not assumed. The implication is that AI governance programmes now succeed or fail on identity control design.

Agentic AI turns access review into a weaker control unless governance moves to the point of issuance. Access review models were built for identities whose privileges persist long enough to be certified. When an AI agent can act across systems in short-lived, task-specific bursts, retrospective review is a poor substitute for preventive scope control. The implication is that finance teams need to rethink whether periodic review is enough for identities that operate at machine speed.

Separation of Duties becomes a cross-identity property, not a single-account rule. The article’s strongest operational insight is that SoD can fail even when no single identity appears overprivileged, because a human, a service account, and an AI agent can collectively recreate a toxic access path. That means governance must look at composite workflows and entitlement combinations, not just individual role design. The implication is that finance teams need to model privilege conflicts across the full execution chain.

Continuous governance is the only credible answer to mixed identity estates in regulated finance. The combination of humans, workloads, and AI agents creates a control environment where static approval models age quickly. Identity security becomes the mechanism that keeps access decisions, activity evidence, and policy checks aligned as the environment changes. The implication is that financial services teams should treat identity governance as an always-on operational control, not a compliance overlay.

From our research library:

What this signals

Identity governance is becoming the practical control point for AI risk in regulated finance. The article’s deeper signal is that governance programmes can no longer separate policy language from access enforcement. If an AI system can touch data, model logic, and APIs, identity determines whether the control exists in practice or only on paper.

Auditability now depends on mixed-identity traceability. Financial institutions should expect regulators and internal assurance teams to ask not only what the AI did, but which identity performed each step in the chain. That pushes IAM, IGA, and PAM teams into a shared operational model for human, workload, and agent access.


For practitioners

  • Map AI access paths across all identity types Inventory which human users, service accounts, and AI agents can reach regulated data, model endpoints, and APIs, then document the exact entitlement path for each one.
  • Model separation of duties across workflows Review whether any AI-enabled workflow lets one identity request, transform, and approve the same business action, especially in finance operations and model oversight.
  • Shift controls to issuance time Prefer task-scoped access rules and continuous authorisation checks where AI agents can act faster than periodic access review cycles can validate their privileges.
  • Build audit trails that survive mixed execution Capture who initiated the task, which identity executed it, what data or API was touched, and where any delegated approval occurred so auditors can reconstruct the full path.

Key takeaways

  • AI governance in finance fails when identity is treated as a peripheral control instead of the mechanism that binds policy to execution.
  • The article’s central risk is not AI in the abstract, but the way human users, service accounts, and AI agents can all reach sensitive systems through governed or unguided access paths.
  • Financial institutions need identity-centric controls that combine least privilege, separation of duties, and audit trails across every identity type involved in AI workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centers on AI agents using access in ways governance must constrain.
Recommendation — Map AI agent workflows to ASI03 and restrict delegated privileges to task-specific scope.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIAI agents and service accounts are governed here as non-human identities with access scope risk.
Recommendation — Review non-human identities for overprivilege and remove access that exceeds the task boundary.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about governing AI risk through accountable controls and oversight.
Recommendation — Use GOVERN to assign ownership for AI access, approval, and audit accountability.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsIdentity permissions are the central control described for AI governance.
Recommendation — Apply PR.AA-05 to enforce least-privilege access across human and machine identities.
CSA MAESTROAgentic AI Threat ModelingThe article discusses agentic AI workflows and the need to model their security impact.
Recommendation — Model AI workflows with MAESTRO to identify delegation, privilege, and control failures.

Key terms

  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Identity Security: Identity security is the discipline of governing who and what can access systems, data, and tools, then proving those decisions are enforced. In practice it spans human users, service accounts, tokens, certificates, and AI agents across the full access lifecycle.
  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org