TL;DR: AI systems are often grouped into causal, predictive, generative, and agentic types, but the operational difference matters most when they start using tools and acting on behalf of systems, according to WorkOS. The real governance problem is that agentic behaviour changes identity assumptions, so IAM teams need to separate automation from autonomy before they overstate control coverage.
At a glance
What this is: This is a WorkOS overview of four AI types, with the key identity finding that agentic AI changes the governance problem because it can act autonomously rather than just assist or predict.
Why it matters: It matters because IAM, NHI, and PAM teams need to distinguish tool-using automation from autonomous action before they map access, accountability, and privilege controls.
Context
The core governance gap is not AI capability itself but the point at which a system stops waiting for a prompt and starts choosing actions. Once an AI system can select a sequence of actions and execute them, identity is no longer just about authenticating a caller. It becomes about governing an actor that can create its own access path.
This article is useful because it separates causal, predictive, generative, and agentic AI into distinct operating modes. That distinction matters for identity programmes because only the agentic model changes who or what is acting, not just what kind of output is produced.
For IAM and NHI practitioners, the practical question is where a model sits in the decision chain. Predictive and generative systems inform decisions, while agentic systems can initiate them, which changes how privilege, authorisation, and accountability need to be designed.
Key questions
Q: How should teams govern AI systems that can take actions as well as generate outputs?
A: Treat the agent as a governed actor, not just a model output stream. Require action-level logging, tool-call traceability, authorization boundaries, and approval gates before the system can write to records or invoke downstream tools. If an AI system can change state, its authority must be scoped, monitored, and revocable like any other privileged non-human identity.
Q: When do predictive or generative AI systems become an IAM concern?
A: They become an IAM concern when they can reach internal systems through credentials, service accounts, or delegated APIs. At that point the risk is no longer just model behaviour, but the access path attached to the application or workflow that uses the model. IAM teams should govern the calling system unless the model itself can act independently.
Q: What breaks when organisations treat agentic AI like ordinary automation?
A: They often miss that autonomous systems can decide timing, sequence, and tool choice at runtime. That makes static approvals and periodic reviews a poor fit, because the privilege may be used and discarded before anyone can inspect it. The failure is assuming that control can happen after execution instead of during issuance.
Q: How do IAM and NHI teams decide who owns autonomous AI access?
A: Ownership should sit with the team that controls the credential lifecycle, the approval model, and the offboarding path for the AI system. If the agent uses tokens, service accounts, or other machine credentials, the identity team should own the lifecycle controls even when the product team owns the model behaviour.
Technical breakdown
Why autonomous AI changes the identity problem
Agentic AI is different from predictive or generative AI because it does not stop at producing output. It perceives a situation, chooses a path, uses tools, and executes actions toward a goal. That means the identity question shifts from "who asked for this output?" to "what authority did the system use to decide and act?" In practice, the actor model becomes closer to a machine identity with runtime discretion than to a conventional application calling an API on behalf of a user. The important boundary is autonomy, not model type.
Practical implication: classify agentic systems by the authority they can exercise, not by whether they use an LLM.
Why predictive and generative AI do not need the same controls
Predictive AI forecasts likely outcomes from historical data, while generative AI creates new content from learned patterns. Neither model inherently chooses when to act, which tools to use, or how to sequence those actions. Their identity exposure is usually indirect, through the applications that call them or the data they consume. That makes them governance inputs, not autonomous subjects. IAM teams should avoid overextending agent-style controls to systems that remain bounded by application workflows, because doing so obscures where real authority actually lives.
Practical implication: apply access and data controls around the hosting application and its credentials unless the model can independently execute actions.
Where tool use turns AI into an access governance issue
Tool use is the inflection point. Once a system can call APIs, modify code, query internal systems, or trigger operational tasks, the security model has to account for delegated authority across multiple services. That is where agentic AI starts to overlap with NHI governance, because the system may rely on credentials, tokens, or service accounts to complete work. The risk is not that every tool-using model is autonomous. The risk is that organisations treat dynamic action as mere automation and fail to govern the identity and privilege path behind it.
Practical implication: inventory every credential and service path an AI system can use before permitting tool execution.
NHI Mgmt Group analysis
Agentic AI is the first AI category that turns identity from a login problem into an authority problem. Predictive and generative systems can be governed as outputs inside an application boundary. Agentic systems can initiate work, select tools, and complete tasks, which means the real control question is no longer authentication alone. Practitioners need to treat runtime authority as the primary security object.
The assumption that access is stable long enough to be reviewed breaks under autonomous behaviour. Access review models were designed for actors whose privileges persist across a human-paced lifecycle. That assumption fails when the actor can acquire, use, and relinquish authority inside a single task sequence. The implication is that governance has to move toward issuance-time control and task-scoped authority rather than retrospective certification.
Causal, predictive, generative, and agentic AI should not be grouped into one governance bucket. The article is right to separate them because their identity implications diverge sharply at the point of action. Predictive and generative AI remain control inputs, while agentic AI becomes an actor in its own right. That distinction is essential for clean ownership across IAM, NHI, and application security teams.
Identity blast radius becomes the more useful planning metric once AI can act. The practical risk is not only whether a system is accurate or useful, but how far it can move if its authority is mis-scoped. A model that can open pull requests, trigger workflows, or call internal tools creates a blast radius that must be bounded before deployment, not after an incident. Practitioners should map authority paths before they map features.
Autonomous AI governance will increasingly borrow from NHI discipline, not from model evaluation alone. The article focuses on AI types, but the security consequence is delegated machine authority through credentials, APIs, and service accounts. That means lifecycle management, privilege scoping, and offboarding patterns from NHI governance become more relevant than abstract AI capability labels. Teams should align control ownership to the identity path, not the model marketing category.
From our research library:
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
- Read next: Agentic AI Identity Guide
What this signals
Identity blast radius is the metric that matters once AI can act: a model's governance risk is defined less by output quality than by how far it can move through connected systems when it has credentials. That makes access boundaries and offboarding paths first-order design concerns, not afterthoughts.
Teams should expect the line between application control and identity governance to keep shifting as more systems gain tool use. The practical response is to govern autonomy at the point where a system can initiate work, not where it merely assists a human workflow.
For practitioners
- Classify AI systems by decision authority Separate systems that only predict or generate from systems that can choose actions and execute them without a human approval gate. Use that classification to decide whether the system belongs in an application control model or an identity governance model.
- Map every tool and credential path Document the APIs, service accounts, tokens, and internal systems an agentic workflow can reach, then confirm whether each path is scoped to the task and environment. Remove any credential path that is broader than the intended operational boundary.
- Bind autonomy to task-scoped privilege Treat any system that can execute its own action sequence as a non-human actor with explicit privilege boundaries. Limit each session or workflow to the minimum authority needed for that task and deny persistence by default.
- Assign ownership for autonomous action paths Make one team responsible for the identity path behind each agentic use case, including approval rules, credential lifecycle, and offboarding. Without a named owner, autonomous behaviour tends to outgrow the controls built around it.
Key takeaways
- Agentic AI changes the identity question because it can initiate actions, not just generate or predict outputs.
- Predictive and generative systems usually remain application governance problems unless they can independently use credentials or tools.
- Once AI can act on its own, teams need task-scoped privilege, explicit ownership, and credential lifecycle control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Agentic AI creates runtime authority risks when systems can act through delegated credentials. |
| Recommendation — Bind autonomous execution to explicit privilege limits and audit every delegated identity path. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Agentic workflows depend on machine credentials, tokens, and service accounts to act. |
| NHI-05 — Overprivileged NHI | Autonomous systems become risky when their delegated access exceeds the task boundary. | |
| Recommendation — Treat AI execution paths as NHI authentication flows and harden how credentials are issued and used. Scope machine credentials to the minimum access needed for each autonomous task. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | AI systems that act on behalf of services need governed entitlement boundaries. |
| Recommendation — Review and constrain entitlements for any AI workflow that can initiate actions or reach internal systems. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is fundamentally about how different AI modes change governance expectations. |
| Recommendation — Define governance ownership for each AI mode before permitting autonomous behaviour. | ||
Key terms
- Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
- Predictive AI: AI that forecasts likely outcomes from historical data patterns rather than choosing actions on its own. Its governance focus is usually the application and data pipeline around the model, unless it is connected to tools that let it act.
- Generative AI: AI designed to create text, code, images, or other content in response to a prompt. It is usually reactive rather than autonomous, which means the main security concern is output quality, leakage, and misuse of generated content rather than independent action.
- Autonomous Actor: An autonomous actor is an identity that can choose actions, select tools, and decide when to execute without a human approval gate. In governance terms, that changes the control problem from static access assignment to runtime authority management and accountability.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org