By NHI Mgmt Group Editorial TeamBased on HiddenLayer: “HiddenLayer Releases the 2026 AI Threat Landscape Report, Spotlighting the Rise of Agentic AI and the Expanding Attack Surface of Autonomous Systems” (March 18, 2026)

TL;DR: One in eight reported AI breaches is now linked to agentic systems, while 76% of organisations cite shadow AI as a definite or probable problem and 31% do not know whether they experienced an AI security breach in the past year, according to HiddenLayer’s 2026 AI Threat Landscape Report based on a survey of 250 IT and security leaders. The governance gap is no longer theoretical: controls built for static software cannot reliably contain systems that browse, execute, and act at runtime.


At a glance

What this is: HiddenLayer’s 2026 AI Threat Landscape Report says agentic AI is expanding the AI attack surface, with one in eight reported AI breaches linked to agentic systems.

Why it matters: IAM, PAM, and NHI teams need to treat autonomous runtime behaviour as a governance problem because traditional controls cannot assume stable identity, static privilege, or human-paced review.

By the numbers:

  • 76% of organisations now cite shadow AI as a definite or probable problem.
  • 31% of organisations do not know whether they experienced an AI security breach in the past 12 months.

Context

Agentic AI changes the identity problem because the system is no longer just producing outputs, it is taking actions. When a model can browse, execute code, call tools, and move through workflows, the security boundary shifts from prompt quality to runtime authority and delegated access.

HiddenLayer’s survey of 250 IT and security leaders suggests that governance, inventory, and detection are lagging the rate of adoption. The result is an environment where shadow AI expands faster than control ownership, and where organisations may not even know when an AI security breach has occurred.


Key questions

Q: What breaks when privileged AI agents can read untrusted input directly?

A: Prompt injection risk rises because the agent may treat user content as instruction instead of context. Once that happens, a malicious request can steer approval, reassignment, or data handling decisions without ever changing the agent's authorised role. The safe pattern is to sanitise untrusted input before any privileged step.

Q: Why do agentic AI deployments increase breach risk even when the model is accurate?

A: Accuracy does not remove risk when the system can still take harmful actions. A highly accurate agent can be manipulated through retrieved content, injected instructions, or unsafe tool access, then use legitimate permissions to carry out the wrong operation. The risk comes from delegated authority and connected workflows, not just from model error rates.

Q: How should organisations govern shadow AI without blocking legitimate use?

A: Start with approved-use policy, tool inventory, and data classification. Then require that any AI system handling internal information has named owners, logged access, and defined credential paths. The goal is not prohibition, but visibility and control. If a tool cannot be inventoried or monitored, it should not process sensitive data.

Q: What is the difference between agentic AI risk and ordinary software risk?

A: Agentic AI risk is defined by runtime decision-making and tool use, not by static code paths. Ordinary software executes prebuilt logic, while an agent can select actions, chain tools, and alter its next step based on context. That changes the control model from guarding inputs and outputs to governing authority, delegation, and execution scope.


Technical breakdown

Why autonomous tool use changes the security boundary

Agentic systems differ from conventional software because they can choose actions at runtime rather than only respond inside a fixed workflow. Once an AI system can browse, execute code, and trigger downstream actions, prompt injection becomes an execution-path problem, not just a content-safety problem. That means the real security boundary is no longer the model output. It is the combination of tools, credentials, context, and policy that the agent can reach in a live session.

Practical implication: treat tool access and runtime authorisation as the primary control plane for agentic systems.

Why shadow AI becomes an identity governance problem

Shadow AI is not just an inventory issue. It is an unmanaged population of AI systems that may hold tokens, API keys, service credentials, or access to business workflows without central oversight. In identity terms, that creates ungoverned non-human identities with unclear ownership, unclear offboarding, and unclear review cycles. If teams cannot inventory these systems, they cannot govern privilege, lifecycle, or evidence of access in a meaningful way.

Practical implication: map AI systems to accountable owners and bring their credentials into lifecycle governance.

How prompt injection turns into operational compromise

Prompt injection becomes materially more dangerous when the agent can act on what it reads. In that state, an attacker does not need to break the model to influence outcomes; it is enough to manipulate the context that the agent trusts and then let the system carry out the next step. The risk is amplified when the agent can chain actions across tools, because a single poisoned input can cascade into data access, code execution, or workflow abuse.

Practical implication: test whether an agent can be steered from untrusted input into privileged actions across multiple tools.


Threat narrative

Attacker objective: The attacker wants to turn AI trust in external content and tools into real-world system compromise or breach exposure.

  1. Entry occurs when malicious content is placed in public model repositories, code repositories, or other sources that AI systems consume during development or runtime.
  2. Credential or context abuse follows when an agent or model accepts poisoned instructions, unsafe artifacts, or manipulated context from those sources.
  3. Escalation occurs when the AI system can browse, execute code, access files, or trigger workflows, turning model influence into operational reach.
  4. Impact is realised through system compromise, breach exposure, or broader downstream damage across connected enterprise workflows.
  • DeepSeek database exposure 2025: An unauthenticated DeepSeek ClickHouse database exposed over a million log lines with plaintext chat history and API keys in 2025.
  • Hugging Face Spaces breach 2024: Unauthorised access to Hugging Face Spaces may have exposed secrets users stored for AI apps; tokens were revoked and org tokens removed.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic AI creates an assumption collapse in identity governance: access review assumes privilege persists long enough to be observed, certified, and removed, but autonomous systems can acquire, use, and chain access within a single runtime session. That breaks the review model before it even starts. The implication is that governance has to move from post-hoc certification to issuance-time control and runtime containment.

Shadow AI is now a non-human identity problem, not just an inventory problem: unmanaged AI systems can hold secrets, touch workflows, and interact with other agents without a reliable ownership chain. When ownership is unclear, offboarding is unclear and accountability becomes probabilistic rather than enforceable. Practitioners need to treat discovery as the first governance control, not a visibility nice-to-have.

Prompt injection becomes operational security once agents can act: the threat is no longer confined to model behaviour because the model can now influence tools, files, and downstream systems. That makes trust boundaries around context, retrieval, and tool invocation materially more important than model accuracy alone. Security teams should evaluate which runtime actions an attacker could trigger through manipulated input.

Identity blast radius: autonomous systems increase damage potential because authority, context, and action can be chained faster than human review cycles can respond. This is not a call for narrower AI adoption, but for stronger scoping of what an agent can reach at runtime. The practical conclusion is that privilege should be designed around bounded action paths, not broad assumptions about model behaviour.

Governance ownership is becoming the deciding control: the report’s conflict over who owns AI security controls shows that technical risk is now being amplified by organisational ambiguity. Where no team owns the identity, monitoring, and breach-response obligations for AI systems, the control environment will always trail adoption. Practitioners should align AI security governance with the same accountability discipline used for other non-human identities.

From our research library:

What this signals

Autonomous AI governance is now an inventory and authority problem at the same time: teams need to know where agents exist, who owns them, and what they can do before they can claim control over the environment. Without that baseline, even well-intentioned policy will miss the systems most likely to create breach exposure.

Shadow AI demands NHI-style lifecycle discipline: if an AI system can obtain credentials, call APIs, and operate outside normal approval flows, it needs ownership, offboarding, and review like any other non-human identity. The difference is that the execution window may be far shorter than human review cycles assume.

Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey. That gap signals a governance race condition: the organisations moving fastest are often the least able to explain what their agents can access or alter.


For practitioners

  • Define agent runtime boundaries Limit which tools, files, and workflows each AI system can reach, and separate read, write, and execute permissions so a compromised agent cannot move freely.
  • Inventory shadow AI and assign owners Create a live register of all AI systems, their credentials, approved use cases, and accountable business owners so offboarding and review are possible.
  • Move controls to issuance time Require approval and policy checks before an agent receives access, rather than relying on later review cycles that may never see the risky action.
  • Test for prompt injection across tool chains Simulate poisoned inputs that attempt to push an agent from content ingestion into file access, code execution, or workflow actions.
  • Separate detection for model risk and identity risk Track AI security incidents alongside identity events so teams can tell whether a failure came from model behaviour, access abuse, or both.

Key takeaways

  • Agentic AI turns runtime tool use into the main security boundary, which means identity and authorisation controls matter more than prompt quality alone.
  • The report links one in eight reported AI breaches to agentic systems and shows that shadow AI and ownership ambiguity are rising together.
  • Practitioners should inventory AI systems, bound their tool access, and move governance to issuance time before autonomous behaviour expands the breach surface.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI02 — Tool MisuseThe report focuses on agents browsing, executing code, and triggering workflows.
ASI03 — Identity & Privilege AbuseThe core problem is autonomous systems using delegated authority in unsafe ways.
ASI09 — Human-Agent Trust ExploitationPrompt injection and manipulated context are central to the report’s threat model.
Recommendation — Restrict tool permissions so agent actions cannot escalate beyond the intended workflow. Scope and monitor delegated privileges for every agent that can act on enterprise systems. Test whether untrusted input can steer an agent into privileged actions.
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIPublic repositories and external model sources create supply-chain-like exposure for AI identities.
NHI-10 — Human Use of NHIShadow AI often reflects unmanaged human-created AI identities and credentials.
Recommendation — Inventory external model and code dependencies that can influence AI runtime behaviour. Assign owners and lifecycle rules to every AI system before it reaches production.
NIST AI RMFMANAGE — AI Risk Management and MonitoringThe article is about governing AI risk, monitoring, and organisational accountability.
Recommendation — Establish continuous AI risk governance with explicit ownership for monitoring and response.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe report highlights excessive access and runtime authority as the key exposure.
Recommendation — Apply least-authority controls to agent permissions and review them continuously.

Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Runtime authority: Runtime authority is the permission an AI system has while it is actively deciding and acting, not just when it is approved. In governance terms, it is the point where access, tool use, and action scope become operational, which is why build-time review alone cannot prove safety.
  • Prompt Injection (Agentic): An attack where malicious instructions are embedded in content that an AI agent reads, causing the agent to execute unintended actions using its own legitimate credentials. A primary vector for agent goal hijacking and identity abuse.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org