TL;DR: AI security is shifting faster than defenders can absorb it, with mean time-to-exploitation falling from 2.3 years in 2018 to 1.6 days in 2026 and open-weight models lagging frontier systems by four to seven months on cyber tasks, according to AccuKnox and Irregular’s analysis. The buying test is no longer whether a control finds issues, but whether it helps defenders more than it helps attackers with the same output.
At a glance
What this is: This is an evaluation guide arguing that AI security purchases should be judged by whether they accelerate defense more than they enable attackers.
Why it matters: It matters to IAM, PAM, NHI, and AI security teams because AI systems increasingly behave like credentialed actors, so discovery, containment, and identity controls must be evaluated together.
By the numbers:
- Mean time from disclosure to exploitation fell from 2.3 years in 2018 to 1.6 days in 2026.
👉 Read AccuKnox's evaluation guide on buying AI security for the transition period
Context
AI security buying is becoming a governance problem, not just a tooling decision. As discovery accelerates and offensive use cases improve, controls that only generate findings can help both defenders and attackers. That creates a real identity and containment question for teams managing AI systems that can access tools, data, and credentials.
The article argues that the transition period matters more than the eventual equilibrium. That is a useful frame for IAM and NHI practitioners because AI agents, service accounts, and privileged workflows now overlap in the same execution path, which means runtime authorization and containment matter as much as detection.
Key questions
Q: What breaks when AI tools create more AppSec findings than teams can triage?
A: Teams lose the ability to separate exploitable issues from harmless noise, so remediation slows and real risk can sit in the queue behind lower-value alerts. The failure is not detection itself. It is prioritisation based on context, including exposure, privilege, data sensitivity, and whether the affected component is actually reachable.
Q: Why do AI agents increase non-human identity risk?
A: AI agents increase non-human identity risk because they can execute many actions quickly once they inherit a credential or tool permission. That speed expands blast radius, shortens attacker dwell time, and makes weak delegation more dangerous. The remedy is tighter scoping, continuous verification, and strict separation between observation and execution privileges.
Q: How do organisations know whether controls for AI-generated code are actually reducing risk?
A: They should look for fewer vulnerable patterns reaching the repository, blocked attempts to introduce unsafe configuration, and a lower volume of remediation work in review and production. Strong controls also surface existing exposure across the codebase so teams can measure how much risk was already present. If security only reports alerts but not reduced insecure output, the control is not effective.
Q: Should organisations prioritise containment or discovery in AI security?
A: Containment should come first when AI systems can reach sensitive tools, secrets, or production actions. Discovery is still necessary, but it is not enough when exploitation can happen in hours or days. The right sequence is visibility, then runtime enforcement, then deeper optimisation.
Technical breakdown
Why the transition period matters more than the end state
The end-state fallacy is the mistake of judging present controls by the eventual equilibrium instead of the current threat balance. In AI security, that matters because attackers can exploit new capability immediately, while defenders must integrate controls into live environments, prove safety, and preserve business function. A control that improves discovery but does not change execution risk may be useful later, yet still be a red-end tool today. In practice, the buying question is whether the capability compresses attacker advantage now, not whether it sounds defensible in a future mature state.
Practical implication: evaluate AI security controls by current attacker-defender asymmetry, not by long-run theory.
AI as target and actor changes identity governance
AI systems are no longer only models that answer prompts. They are also actors that can call tools, read secrets, traverse workflows, and execute chained actions through delegated access. That makes identity governance central: if an AI agent can access a token, invoke a service, or trigger a privileged workflow, it behaves like a non-human identity with runtime consequences. Conventional detection still matters, but it cannot substitute for per-action containment, scoped credentials, and explicit approval boundaries for irreversible operations.
Practical implication: govern AI systems as privileged non-human identities with constrained tool and secret access.
Discovery without containment is an incomplete control loop
The article’s core mechanism is the gap between finding a weakness and stopping its use. Discovery tools surface flaws, misconfigurations, and exposure paths, but attackers benefit from the same knowledge unless the control loop continues into containment or enforcement. That is why AI red teaming, stateful prompt firewalls, vault-based secret handling, and kernel-enforced runtime policy are framed as different classes of control, not interchangeable features. A findings list is intelligence; a containment path is security.
Practical implication: insist on controls that can block or constrain action at runtime, not only report risk.
Threat narrative
Attacker objective: The attacker wants to turn AI-enabled access paths into durable infrastructure control, credential theft, or unauthorized execution at scale.
- Entry occurs when attackers use exposed AI-related credentials, model access, or workflow weaknesses to reach a live environment.
- Escalation follows when the AI system, agent, or surrounding service account can chain actions, invoke tools, or inherit broader permissions than intended.
- Impact is achieved when the attacker uses that delegated access to move through infrastructure, steal credentials, or trigger unauthorized code execution.
NHI Mgmt Group analysis
AI security buying is now a red-versus-blue allocation problem. Controls that only help a defender after a problem is found do not change the attacker’s economics fast enough. The useful question is whether the same output gives the attacker equal value, or whether it meaningfully improves containment for the defender. That is where differential defensive acceleration becomes a practical lens for procurement and architecture decisions.
AI systems should be treated as governed non-human identities when they can take actions. Once an AI agent can call tools, access secrets, or trigger workflows, it sits inside the identity plane whether teams label it that way or not. That means IAM, PAM, and NHI governance need to extend to per-agent permissions, runtime approvals, and secret handling rather than stopping at model monitoring. Practitioners should govern the agent, not just the model.
Discovery-only security creates false confidence in fast-moving AI environments. Visibility matters, but visibility without containment still leaves the organisation exposed to the same exploit path. This is the security equivalent of inventorying a problem while the attack path remains open, and it is why the article’s critique maps cleanly to AI governance debt. Practitioners should treat closed-loop enforcement as the decisive control.
Container and kernel-level enforcement matter because AI abuse is an execution problem, not only a detection problem. If an agent can make thousands of unscripted decisions before a human reviews an alert, then the control has to fail closed at runtime. That aligns with broader control thinking in NIST CSF and NIST SP 800-53, where prevention and enforcement matter as much as monitoring. Teams should design for refusal at the point of action.
Named concept: transition asymmetry. The article’s central insight is that security controls are being judged during a period when offensive capability is compounding faster than defensive deployment. That creates a temporary but material asymmetry between what can be discovered and what can be safely contained. Practitioners should buy for the transition they are in, not the equilibrium they hope to reach.
What this signals
Transition asymmetry will shape AI procurement for the next cycle. Teams that buy discovery-heavy tools without a containment path will create report volume, not risk reduction. The more an agent can act, the more security decisions have to move from dashboards into enforcement, especially where credentials, tool calls, and production access intersect.
Per-agent identity governance will become a baseline expectation. The article points to a future where AI controls are judged by how tightly they bind actions to identity, scope, and approval. That means IAM and PAM teams need to prepare for agent inventories, delegated privileges, and runtime policy enforcement as part of normal programme design.
Our research shows why this matters now: 91.6% of secrets remain valid five days after notification, according to Ultimate Guide to NHIs. In a faster attack cycle, stale credentials and delayed containment create a window attackers can repeatedly exploit. Teams should expect AI-driven abuse to expose every lifecycle weakness in secret handling and access revocation.
For practitioners
- Score controls for defensive asymmetry Rank AI security capabilities by whether they improve defender containment more than attacker reconnaissance, exploitation, or reuse of the same output. Put discovery-only tools below controls that block execution, scope credentials, or force approval for irreversible actions.
- Map every AI system to an identity boundary Inventory models, agents, datasets, tool connections, and secrets as governed identities and dependencies. Tie each agent to a specific permission set, approval path, and secret source so that access is explicit rather than inherited from surrounding infrastructure.
- Separate detection from containment in design reviews Require each AI control to answer two questions: what it finds and what it can stop. If the answer ends at a findings list, add runtime enforcement through vault mediation, egress policy, or per-tool-call limits before approving deployment.
- Test agentic workflows for unscripted action chains Red-team the exact paths where an AI system can chain tool calls, read secrets, and reach production systems. Use the test to verify that each boundary still holds when the agent behaves unpredictably or tries to escalate through delegated access.
Key takeaways
- AI security is being judged in a transition period where attackers can exploit new capability faster than defenders can safely operationalise controls.
- When an AI system can access tools and credentials, it must be governed like a privileged non-human identity, not treated as a passive model.
- The buying decision now turns on closed-loop containment, because discovery without runtime enforcement still leaves the attack path open.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | MANAGE | The article centres on managing AI risk through containment and deployment choices. |
| OWASP Agentic AI Top 10 | AGENT-07 | Agent tool misuse and containment failures are central to the article's AI actor risk. |
| NIST CSF 2.0 | PR.AC-4 | The post emphasises access scoping and containment for AI systems with delegated privileges. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege directly supports the article's argument for scoped AI and agent permissions. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0004 , Privilege Escalation; TA0008 , Lateral Movement | The article discusses AI-driven attack chains involving credentials, escalation, and movement. |
Apply agentic AI controls to constrain tool use, secrets access, and irreversible action paths.
Key terms
- End-State Fallacy: The mistake of assuming a future stable security balance describes the current operating environment. In AI security, it means judging controls by how the market might look later rather than how quickly attackers can exploit present gaps.
- Differential Defensive Cyber Acceleration: A buying and architecture approach that favours controls improving the defender more than the attacker who gains the same information. It prioritises containment, enforcement, and scoped access over discovery-only capabilities that can be reused offensively.
- Transition Asymmetry: The period in which offensive capability advances faster than safe defensive deployment. It describes a temporary imbalance where discovery and exploitability move quicker than integration, approval, and operational containment.
- Per-instance agent identity: A per-instance agent identity is a distinct credential and governance record assigned to one running agent instance, not to the whole agent type. It allows security teams to revoke, audit, and scope access at the level where action actually occurs, which is essential when agents can spawn or delegate.
What's in the full article
AccuKnox's full article covers the operational detail this post intentionally leaves for the source:
- Side-by-side evaluation logic for finding versus containment controls in AI security
- The DDCA framework applied to real purchasing decisions and control selection
- AccuKnox's mapping of AI-SPM, red teaming, and runtime containment to the transition problem
- The detailed reasoning behind per-tool-call scoping and kernel-enforced refusal paths
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners translate identity controls into safer access, lifecycle, and containment decisions across modern environments.
Published by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org