By NHI Mgmt Group Editorial TeamBased on Astrix Security: “NHI Governance for AI Agent Security in the Age of ChatGPT-5” (August 5, 2025)

TL;DR: GPT-5 lowers the barrier to creating custom AI agents that connect to corporate systems through service accounts, API keys, and tokens, increasing the risk of unmanaged access, misconfiguration, and privilege exposure, according to Astrix Security. The real issue is not agent creation speed itself but the governance assumption that non-human access can remain visible, bounded, and reviewable once employees can spin it up in minutes.


At a glance

What this is: This analysis argues that GPT-5 lowers the barrier to creating AI agents that rely on NHIs, making unmanaged access, misconfiguration and privilege sprawl more likely.

Why it matters: It matters because IAM and security teams now have to govern agent creation, ownership and access scope at the same speed that employees can create these agents.


Context

GPT-5 changes the economics of AI agent creation, but the underlying identity problem is older and harder: agents still need credentials, permissions and accountable ownership to touch corporate systems. When that access is created quickly and by non-specialists, the gap is not model capability, it is identity governance.

The result is familiar to anyone running NHI programmes. Service accounts, API keys, tokens and certificates become the control surface for agent behaviour, while discovery, owner mapping and review cadence struggle to keep pace. In practice, governance fails when access can be created faster than it can be catalogued and constrained.


Key questions

Q: What breaks when business users can build and deploy AI agents without strong guardrails?

A: Without guardrails, organisations can lose visibility into who built an agent, what it can access, and what it can do once triggered. That creates policy drift, overexposure of sensitive data, and automation that bypasses normal approval paths. The failure is not just technical. It is governance loss, because business intent can translate into uncontrolled machine action.

Q: Why do AI agents make excessive access more dangerous than human access?

A: AI agents can use inherited permissions continuously, across multiple systems, and at machine speed. That means a single overbroad entitlement can create rapid exposure to data, workflows, or administrative actions before humans notice. The risk is driven by both breadth of access and the pace at which the agent can exercise it.

Q: How do security teams know if agent governance is actually working?

A: It is working only if the team can answer three questions quickly for any agent: what it can reach, what it did recently, and whether that behaviour matches intent. If any of those answers require manual reconstruction, governance exists on paper but not in operations.

Q: How should teams govern AI assistants, workflows, and autonomous agents differently?

A: Teams should govern them by runtime behaviour, not by model family. Assistants need strong prompt and response controls, triggered workflows need untrusted-input screening and narrow tool scope, and autonomous agents need separate identities, scoped delegation, and traceability across each decision. A single AI policy rarely fits all three.


Technical breakdown

Why faster agent creation expands NHI sprawl

Custom AI agents are software actors that typically authenticate through NHIs such as service accounts, API keys, access tokens and certificates. GPT-5 reduces the friction required for non-technical users to create them, which means identity sprawl now starts at the point of creation rather than during platform integration. Once an agent can be spun up in minutes, the inventory problem shifts from tracking a few sanctioned integrations to tracking many unreviewed ones with distinct permissions, owners and usage patterns.

Practical implication: treat agent onboarding as an identity event, not a productivity feature.

How adaptive reasoning changes privilege risk

The article points to adaptive reasoning, larger context windows and integrated tool use as the features that make agents more capable and more difficult to govern. In identity terms, that means the agent can select tools, consume larger policy or data contexts, and invoke more services under one identity than a traditional workflow script would. The security issue is not intelligence on its own, but the combination of runtime choice and privileged connectivity, which makes over-granted access harder to detect from static configuration alone.

Practical implication: review agent permissions against actual tool paths, not the headline use case.

Why NHI governance assumptions break under agentic speed

Traditional NHI governance assumes there is enough time between creation, approval, review and offboarding to maintain control. GPT-5 accelerates the creation side so far that the review side becomes the bottleneck, especially when employees can create agents without security involvement. That creates a governance mismatch: access can become operational before the organisation has a reliable view of ownership, purpose and permission scope.

Practical implication: move control points earlier in the lifecycle, before credentials and connectors are issued.


Threat narrative

Attacker objective: The objective is to gain or abuse privileged access through an AI agent identity so sensitive systems, data or workflows can be reached without effective governance.

  1. Entry occurs when an employee quickly creates a custom AI agent and connects it to corporate systems through service accounts, API keys or other tokens.
  2. Credential access emerges as the agent inherits or is granted permissions that exceed the intended task scope, especially when access is configured with weak oversight.
  3. Escalation follows when overly broad tool access, dormant credentials or misconfigured sharing paths expose sensitive systems or allow privilege expansion.
  4. Impact is unmanaged access to corporate environments, including policy violations, exposed sensitive systems and broader NHI sprawl that is difficult to unwind.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

GPT-5 does not create a new identity category, it compresses the lifecycle of an old one. The important change is that employees can now generate AI agents that immediately need accounts, tokens and permissions, often before security teams know they exist. That is a governance acceleration problem, not merely an AI adoption story. Practitioners should read it as a signal that agent inventory and ownership need to move to the front of the lifecycle.

Access review was designed for access that lasts long enough to be reviewed. That assumption fails when a user can create a custom agent in minutes, attach it to business systems and leave behind a live NHI footprint before the next review cycle begins. The implication is not simply more review activity, but a different governance model that treats issuance and approval as the control point rather than periodic certification.

Agent privilege now behaves like an identity blast radius problem. When one agent can reach email, code, databases and SaaS platforms through a small number of credentials, the security question becomes how far one identity can reach before it is noticed. That pushes IAM, PAM and NHI governance into the same conversation because the blast radius is defined by both privilege scope and machine-to-machine connectivity.

Shadow AI is increasingly a shadow identity problem. The article shows that unmanaged agents are not just unapproved software, they are unowned identities with credentials, logins and downstream authority. That means governance teams need a named owner, a clear business purpose and a revocation path for every agent, or they will inherit an unbounded access estate they cannot certify.

From our research library:

What this signals

Agent identity sprawl is now a governance speed problem. When employees can stand up AI agents in minutes, the control failure is no longer discovery alone. It is the delay between creation, ownership assignment and permission review, which means the programme has to govern issuance before the next review cycle begins.

Identity blast radius is the right metric for agentic risk. The more systems one agent can reach through service accounts, API keys and tokens, the more quickly a small misconfiguration can become broad exposure. That makes connector scope, credential lifecycle and owner accountability the operational levers that matter most.

AI agent governance is still immature across the market. Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security. That gap means practitioners should expect shadow agents, orphaned credentials and overexposed integrations to outpace policy maturity.


For practitioners

  • Map every agent to an accountable owner Require a human owner for each custom or third-party agent, including who approved it, what it can reach and what business purpose it serves.
  • Inventory agent identities and connected systems Create a live inventory of agents, their NHIs, the platforms they touch and the permissions each connector carries so shadow agents do not remain hidden.
  • Constrain permissions to the minimum needed Remove broad connector scopes, review service account entitlements and block agents from inheriting human-level access by default.
  • Require approval before agents go live Insert governance sign-off before credentials are issued or external connections are enabled, especially for agents that can reach sensitive systems.
  • Monitor agent activity continuously Watch for unusual tool use, dormant credentials, orphaned agents and unexpected sharing paths that indicate the identity estate is drifting.

Key takeaways

  • GPT-5 lowers the friction of agent creation, but the security consequence is faster NHI sprawl rather than safer automation.
  • The article’s core risk is unmanaged access through service accounts, API keys and tokens, especially where ownership and approval lag behind adoption.
  • The control response is to govern agent issuance, ownership and permission scope before credentials are issued or connectors are exposed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on agents inheriting or being granted excessive identity scope through fast deployment.
ASI02 — Tool MisuseThe article warns that agents can reach and misuse connected tools once permissions are too broad.
Recommendation — Apply ASI03 to bound agent credentials, privileges and identity scope before production use. Map each agent to approved tools and block access paths that exceed the intended workflow.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIService accounts and tokens used by agents are at risk of carrying more privilege than they need.
NHI-10 — Human Use of NHIThe article describes employees creating and operating NHIs through AI agents without specialist oversight.
Recommendation — Review NHI entitlements for agent connectors and remove any privilege not required for the task. Prevent unsanctioned human-created NHIs by routing agent issuance through governed workflows.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about managing permissions and authorisations for non-human identities connected to business systems.
Recommendation — Enforce PR.AA-05 by continuously reviewing and constraining agent entitlements to business need.

Key terms

  • AI Agent Identity: The digital identity used by an autonomous AI agent to authenticate to external systems, APIs, and services. Managing AI agent identities is an emerging and rapidly evolving area of NHI security.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Agent Sprawl: Agent sprawl is the uncontrolled growth of AI agents, scripts, and automation identities across teams and environments. It creates governance strain because each agent can introduce its own permissions, secrets, and ownership gaps, making revocation, review, and accountability harder to sustain.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org