By NHI Mgmt Group Editorial TeamBased on Clutch Security: “The Agentic AI Security Paradox: AWS AgentCore Gets It Right—But It's Not Enough” (July 21, 2025)

TL;DR: AWS AgentCore adds session isolation, identity controls, secure token vaults, VPC-only networking, and Zero Trust verification for AI agents, but the article argues that runtime governance still breaks once developers start building and scaling agentic systems, according to Clutch Security. The unresolved problem is not platform hardening, but the assumption that credentials and privilege remain reviewable and predictable after independent agent decisions begin.


At a glance

What this is: This is an analysis of AWS AgentCore and the wider governance gap in agentic AI identity, arguing that platform controls alone do not solve runtime oversight once AI agents begin making independent decisions.

Why it matters: It matters because IAM, PAM, and NHI programmes must govern AI agents as runtime identities, not just approve a secure platform configuration at deployment time.

By the numbers:

  • Early adopters are seeing 300-500% annual growth in non-human identities.
  • Organizations could see 82 NHIs for every human user as agentic AI becomes mainstream.
  • Before agentic AI, organizations typically managed about 45 NHIs per human identity.

Context

Agentic AI identity describes the credentials, tokens, service accounts, and access paths that autonomous or semi-autonomous software uses to act inside enterprise systems. The issue in this article is not whether a platform can provide security primitives, but whether governance can still keep up once agents begin selecting tools and using credentials dynamically at runtime.

Clutch Security frames AWS AgentCore as a sign that enterprise deployment of AI agents is moving from experimental to production use. The governance gap appears after deployment, where developers, not the platform vendor, decide how credentials are issued, constrained, monitored, and revoked across the agent lifecycle.

The article also shows why traditional automation assumptions do not carry over cleanly to agentic systems. Predictable workflows can be governed through static rules, but AI agents can combine tools and consume credentials in ways that make access review, least privilege, and behavioural monitoring harder to sustain in practice.


Key questions

Q: How should organizations manage credentials for AI agents?

A: Organizations should transition from hard-coded credentials to runtime-fetched credentials that enhance security by ensuring that tokens are not stored permanently. Utilizing solutions like the MCP Secret Wrapper can help eliminate the risks associated with static credentials.

Q: Why do AI agents complicate least-privilege design?

A: AI agents complicate least-privilege design because their tool use can change dynamically while the underlying permissions remain persistent. The system may need broad enough access to complete a task, but that same access can overshoot if scope is not tightly controlled. The fix is task-scoped authorisation with clear boundaries, not wider standing access.

Q: What are the signs that AI governance is failing in the enterprise?

A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk. Another indicator is weak visibility into who is using which tools and what data they are sending. If teams cannot answer those questions, governance is not working as intended.

Q: What should organisations do when AI agent security is changing faster than review cycles?

A: They should shift from periodic approval to continuous governance. That means automated pre-deployment red teaming, runtime guardrails, change-triggered retesting, and access recertification for tools and data sources. The goal is to govern the agent as a live identity with evolving scope, not as a one-time software release.


Technical breakdown

Why agentic AI identity breaks traditional NHI governance

Agentic AI systems do not behave like fixed automation. They can choose tools at runtime, decide when to act, and consume multiple credentials across a single task, which makes the identity subject dynamic rather than static. That matters because conventional NHI controls often assume a stable, reviewable entitlement pattern. When the identity can alter its own execution path, the control problem shifts from provisioning alone to runtime governance, behavioural monitoring, and session-scoped authorisation. In practical terms, the security model has to follow the agent’s decisions, not just its initial registration.

Practical implication: Treat AI agents as runtime identities whose access patterns must be monitored continuously, not as ordinary service accounts with a fixed workflow.

How session isolation and token vaults help, and where they stop

Session isolation, secure token vaults, VPC-only networking, and Zero Trust verification reduce exposure by narrowing where credentials can be used and how far an agent can move if something goes wrong. These controls matter because the blast radius of an agent is often created by credential reuse, not by the model itself. But they are still infrastructure controls. They do not tell you whether the agent’s tool use is appropriate, whether its scope has drifted, or whether it is acting consistently with the original governance intent. The gap is runtime policy enforcement and oversight, not just secure transport or storage.

Practical implication: Use platform controls to reduce exposure, then add runtime governance to validate what the agent actually does with its credentials.

Why credential lifecycle becomes the real control plane

Every autonomous action an AI agent takes depends on an underlying NHI such as a token, API key, certificate, or service account. As agents scale, credential lifecycle management becomes the practical control plane for identity governance. The article’s core point is that this is where secret sprawl, over-privilege, and unpredictable access paths multiply. If the enterprise cannot inventory which agent used which credential, when, and for what purpose, it cannot meaningfully enforce least privilege or offboarding. In other words, the identity problem is not only the agent, but the entire credential chain that gives the agent power.

Practical implication: Build lifecycle controls around the credentials agents use, including inventory, scope, revocation, and ownership tracking.


Threat narrative

Attacker objective: Use legitimate agent credentials to expand system access and trigger harmful downstream actions across connected services.

  1. Entry begins when an AI agent receives legitimate credentials such as tokens, API keys, or service accounts to perform a task inside enterprise systems.
  2. Escalation occurs when the agent combines tools or propagates credentials in ways that were not anticipated in the original access design.
  3. Impact follows when a misconfigured or malicious agent uses its write permissions to trigger cascading actions across interconnected systems faster than human operators can intervene.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic AI identity is not just a new workload type, it is a governance break from the assumptions behind traditional NHI control. Traditional NHI programmes assume credentials are issued to support a known workflow. That assumption fails when the identity can decide which tools to use and when to use them at runtime. The implication is that identity governance for AI agents must be built around execution behaviour, not just credential inventory.

Session isolation reduces blast radius, but it does not solve privilege drift inside an autonomous workflow. A secure platform can constrain where a token works, yet still cannot determine whether the agent should have combined two tools, opened a new path, or retained access longer than intended. That boundary is where runtime governance becomes distinct from platform security. Practitioners should treat control design as a layered problem, not a vendor feature checklist.

Credential lifecycle is becoming the decisive control plane for agentic AI programmes. The more agents scale, the more the enterprise depends on visibility into issuance, reuse, and revocation across tokens, service accounts, and secrets. This is the same lifecycle discipline IAM teams already apply to humans and NHIs, but with far less predictability in the agentic layer. The practitioner conclusion is clear: governance must follow the credential chain, not just the application stack.

Access review models built for stable identities do not survive autonomous action loops. Access review assumes a subject remains in a reviewable state long enough for entitlement certification to matter. That assumption fails when an agent can acquire, combine, and discard access inside one session. The implication is that organisations must rethink where the control point lives, because after the fact review is too late for many agentic behaviours.

AgentCore signals category maturation, not category completion. The market is moving from proving that AI agents can run to proving that they can be governed. That shift will favour organisations that can connect platform security with lifecycle governance across the full NHI estate. The practitioner takeaway is to evaluate agentic AI through an identity governance lens, not just an infrastructure lens.

From our research library:

What this signals

Agentic AI creates an identity volume problem before it creates an intelligence problem. Enterprises that let agents proliferate without lifecycle controls will be forced to govern a faster-growing NHI estate than their current IAM and PAM processes were built to handle. The practical question is not whether agents are secure in isolation, but whether the programme can still see, own, and revoke the credentials they depend on.

Access review must move closer to issuance time for autonomous systems. Traditional certification cycles assume a subject stays stable long enough to be reviewed. Agentic behaviour breaks that assumption because credentials may be created, used, and discarded inside the same operational window, leaving very little value in after-the-fact attestation.

Zero Trust for AI agents only works when identity lifecycle is treated as the control plane. Session isolation and verification matter, but they do not replace inventory, ownership, and revocation discipline across the agent stack. For practitioners, that means the security programme has to connect platform controls to continuous governance across the full NHI estate.


For practitioners

  • Map every agent credential path Inventory the tokens, API keys, certificates, and service accounts each AI agent can create, inherit, or consume across its lifecycle.
  • Separate platform security from runtime governance Treat secure hosting, session isolation, and Zero Trust verification as the baseline, then define who monitors tool use, scope drift, and anomalous behaviour after launch.
  • Define ownership for agent-issued secrets Assign explicit owners for credential issuance, rotation, and revocation when agent workflows span multiple systems and teams.
  • Rebuild access review around agent behaviour Move beyond periodic certification by capturing which credentials were used, for which tool calls, and whether the agent stayed within its intended scope.

Key takeaways

  • Agentic AI changes identity governance because the actor can select tools and use credentials dynamically rather than following a fixed workflow.
  • AWS AgentCore shows the platform side of the problem is becoming more mature, but runtime governance still determines whether agents stay within scope.
  • The control that matters most is lifecycle oversight of the credentials agents create, inherit, and consume, because that is where visibility and revocation break down.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI agents using credentials and privilege dynamically at runtime.
Recommendation — Map agent identity controls to ASI03 and constrain privilege use during execution, not only at provisioning.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article warns that agent credentials and write permissions scale faster than governance can track.
NHI-07 — Long-Lived SecretsThe article highlights how secrets multiply across agent workflows and persist beyond the intended window.
Recommendation — Review agent entitlements against NHI-05 and remove write access that exceeds the task scope. Shorten secret lifetime and revoke credentials that survive beyond the agent task.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe core issue is whether agent permissions stay aligned to the intended access model.
Recommendation — Align agent permissions to PR.AA-05 and continuously validate entitlements against approved use cases.
MITRE ATT&CKTA0006;TA0040 — Credential Access; ImpactThe article describes credential use leading to cascading system impact.
Recommendation — Track agent misuse patterns under TA0006 and TA0040 to prioritise detection of harmful credential-driven actions.

Key terms

  • Agentic AI Identity: The complete set of credentials, permissions, and governance controls applied to an autonomous AI agent, covering authentication, authorisation, action logging, and access revocation. Distinct from traditional NHI because agent identities are often ephemeral, delegated, and multi-hop.
  • Runtime Governance: Runtime governance is the set of controls that verify what a system or agent is actually doing after deployment. It combines monitoring, authorization checks, and access validation so teams can detect drift, misuse, or excessive privilege in motion rather than assuming build-time policy still holds.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Credential Lifecycle: Credential lifecycle is the process of issuing, rotating, expiring, and revoking secrets, certificates, and tokens across their usable life. For non-human identities, lifecycle discipline is the core control that separates temporary access from persistent exposure.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org