TL;DR: The first 2026 MITRE ATLAS update expands coverage of AI service APIs, agent tool credential harvesting, data poisoning, data destruction, and clickbait attacks against agentic browsers, according to Zenity. The shift matters because autonomous agents can invoke tools, credentials, and workflows at runtime, which means identity and runtime governance now sit at the center of AI security.
At a glance
What this is: Zenity analyses the first 2026 MITRE ATLAS update and argues that agentic AI security now needs threat coverage for execution-layer abuse, not just model inputs and outputs.
Why it matters: IAM, PAM, and AI governance teams need to treat autonomous tool use, delegated access, and runtime monitoring as core control points for agentic systems.
Context
MITRE ATLAS for agentic AI security is the right lens here because the article is about how attack techniques change once software can act, not just predict. The underlying governance gap is simple: traditional threat models assume human-paced workflows and static applications, while autonomous agents can select tools, access data, and keep operating across systems.
That matters for identity programmes because the subject is not model quality alone. Once an agent can authenticate to services, invoke APIs, and operate with implicit permissions, the security problem becomes how to govern runtime authority, delegated access, and tool-mediated action across the full control stack.
Zenity's contribution to the 2026 ATLAS update is the signal, but the subject is broader than one vendor. The article frames agentic AI security as an operational discipline that now sits at the intersection of AI security, identity governance, API security, and incident response.
Key questions
Q: What breaks when AI agents are reviewed like human users?
A: Human review assumes access is stable long enough to be observed, approved, and recertified. Agentic workflows often complete within one session and can change scope mid-execution, so the review cycle arrives too late to matter. The result is a governance gap where the action has already happened before anyone can certify it.
Q: Why do autonomous agents increase authorisation risk even when authentication works?
A: Because authentication only proves the agent holds a valid credential, not that the action is appropriate in context. Once the agent can be steered by new instructions or delegated tasks, a legitimate session can be used to reach data or systems that were never intended for the original purpose.
Q: What are the signs that an agentic browser is being manipulated?
A: Warning signs include unexpected downloads, unplanned navigation, unusual code copy actions, and task completion that does not match the user's intent. Suspicious page metadata, hidden instructions, and repeated tool triggers are especially important because they indicate the browser is acting on machine-readable bait rather than normal user behavior.
Q: How should security teams respond when agent tooling can expose secrets across apps?
A: They should treat every tool connection as a possible secret exposure path and remove unnecessary privilege sharing between systems. The practical test is whether one connected service can reveal or reuse credentials from another without a separate approval boundary. If it can, the agent ecosystem is over-trusted.
Technical breakdown
Why AI service APIs become attack surfaces in agentic systems
AI service APIs are not just transport mechanisms for prompts and responses. In agentic systems they sit inside orchestration paths that can call tools, move data, and trigger downstream actions without a human in the loop. That creates a new attack surface where adversaries target the control plane around the agent rather than the model itself. The article's SesameOp example shows how a backdoor can blend into ordinary assistant logic and use the service API as covert command and control. The security issue is not simply API misuse. It is that the API becomes part of the agent's execution environment, which means compromise can look like normal task completion.
Practical implication: monitor agent API traffic as execution telemetry, not just application traffic.
How tool credential harvesting works through agent integrations
Agentic systems frequently connect to storage, collaboration, and business apps that already hold credentials, tokens, or secrets needed for automation. When an attacker can influence the agent or access its toolchain, those integrations become a route to harvest API keys, session material, and other secrets from connected services. This is different from classic secret theft because the exposed asset is often embedded in the agent's operating context, not a vault alone. The article shows why this matters for SharePoint, OneDrive, and similar services: the agent can be the path by which credentials become visible to an attacker. Once those secrets are accessible, downstream service abuse follows quickly.
Practical implication: inventory every tool connection that can reveal secrets to an agent or through an agent.
Why clickbait against agentic browsers is a new execution-layer risk
Agentic browsers read pages, follow links, click buttons, download files, and sometimes copy code on behalf of users. That means malicious web content can target machine interpretation rather than human judgment, using hidden instructions, deceptive UI, or prompt-like page content to drive unintended action. The article's example of an internal procurement agent downloading and processing a file after reading embedded instructions shows the core failure mode. Traditional web controls often assume a human would notice deception, but agents may execute the page content as task-relevant. The issue is not curiosity bait. It is instruction capture at the point where the agent converts content into action.
Practical implication: treat browser-facing agents as privileged executors that need content and action guardrails.
Threat narrative
Attacker objective: The objective is to turn trusted agent infrastructure into a covert execution layer for data theft, persistence, manipulation, or destructive action.
- Entry begins when an attacker targets the AI service API, browser surface, or connected tool channel that the agent already uses as part of normal work.
- Credential access follows when the attacker uses those integrations to retrieve secrets, keys, or delegated access material from the agent's tool environment.
- Escalation occurs when the attacker uses the agent's own orchestration or browsing behaviour to invoke additional tools, blend into legitimate workflows, or issue covert commands.
- Impact is achieved when the agent performs unintended data access, unauthorized workflow execution, destructive actions, or covert command and control under its legitimate identity.
Breaches seen in the wild
- SalesBleed Salesforce Agentforce 2026: Three fixed Agentforce flaws let poisoned web leads make AI agents leak CRM data with zero clicks and send phishing under the agent's identity.
- 12,000 secrets in LLM training data: Truffle Security found 11,908 live API keys and passwords hard-coded in web pages captured by Common Crawl, a dataset used to train LLMs.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Agentic AI security is no longer a model-only problem. The article shows that the decisive risk now sits at the orchestration and execution layer, where agents invoke tools, access APIs, and keep working across systems. That shifts governance away from static input-output analysis and toward runtime authority, tool use, and delegated action. For practitioners, the control question is no longer just what the model outputs, but what the agent can do while producing it.
Identity does not remain stable long enough for legacy review assumptions to hold. Access review processes were designed for privileges that persist until certification cycles catch them. That assumption fails when an agent can acquire, use, and chain access as part of a single task flow across multiple services. The implication is that governance has to account for runtime behaviour, not only assigned entitlements.
AI service API abuse is emerging as the agentic equivalent of living off the land. When attackers can hide inside orchestration layers, the boundary between legitimate automation and malicious control becomes much harder to see. That makes telemetry, identity binding, and execution tracing more important than static allow lists. Practitioners should treat agent APIs as part of the attack surface, not just plumbing.
Agentic browsers collapse the human skepticism assumption. Web controls built for people assume a user can spot deception, ignore bait, or stop before a risky click. Autonomous browsing agents do not share that boundary, so clickbait, hidden instructions, and misleading UI can steer machine action directly. The result is a new class of compromise where the browser is not the endpoint of trust but the execution path of abuse.
MITRE ATLAS is becoming the common language for AI security operations. The update matters because it translates agentic threats into techniques security teams can map, monitor, and test. For NHI and IAM leaders, that means the future control set will increasingly blend identity governance, API oversight, and AI risk language into one operating model. The practical conclusion is straightforward: agent security must be governed as production security.
From our research library:
- Only 23% of IT leaders were very confident in their organisation's ability to manage security and governance for GenAI deployments, according to a 2025 Gartner survey of 360 IT leaders.
What this signals
Agent runtime governance is now the control plane. The article points to a shift in how enterprise AI should be managed: the question is no longer only what the model knows, but what the agent can do with tools, credentials, and context. For IAM and PAM teams, that means authorisation design must account for runtime behaviour, not just static role assignment.
Identity governance programmes will need to absorb AI security telemetry as agent adoption grows. If tool invocation, browser actions, and delegated API calls are not visible to security operations, then the organisation cannot distinguish legitimate automation from malicious orchestration.
Agentic AI identity and MITRE ATLAS are converging around the same operational problem: autonomous systems introduce attack paths that legacy control models were never built to observe. The next maturity step is to make agent visibility, task scope, and delegated access part of the standard governance stack.
For practitioners
- Map agent runtime authority Inventory where AI agents can authenticate, which tools they can invoke, and which actions happen without a human approval gate. Treat that inventory as a privileged access register for autonomous systems.
- Trace tool-to-secrets pathways Identify every connected application, data source, and assistant that can expose secrets, tokens, or API keys through normal agent operation. Remove implicit access paths that let one tool reveal credentials from another.
- Add runtime telemetry for agent decisions Log tool selection, API invocation, context changes, and browser actions so unexpected agent behaviour can be investigated as an execution event. Build detections around scope drift rather than only failed authentication or malware signatures.
- Segment browser-facing agents from sensitive workflows Keep agentic browsers away from high-impact actions such as code execution, procurement approval, and administrative portals unless the workflow has explicit guardrails and containment. Hidden instructions should not be able to reach privileged operations.
Key takeaways
- MITRE ATLAS's 2026 update reflects a broader shift from model-centric AI risk to execution-layer abuse, where agent tool use and runtime decisions become the main control challenge.
- Agentic systems expand the attack surface through service APIs, connected tools, and browser automation, which makes delegated access and secret exposure central governance issues.
- Security teams should treat agent visibility, runtime telemetry, and approval boundaries as core controls, because the main failure mode is not just bad output but unintended action.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATLAS | TA0006;TA0008;TA0040 — Credential Access; Lateral Movement; Impact | The article centers on AI-specific attack techniques, including credential harvesting, covert control, and destructive actions. |
| Recommendation — Map agentic attack paths to ATLAS techniques and hunt for credential access, orchestration abuse, and destructive actions. | ||
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | Tool abuse is central to the article's discussion of autonomous agents invoking APIs and browser actions. |
| ASI03 — Identity & Privilege Abuse | The article repeatedly focuses on delegated authority, credentials, and runtime privilege in agents. | |
| ASI09 — Human-Agent Trust Exploitation | Clickbait and hidden instructions exploit how agents interpret content as task-relevant input. | |
| Recommendation — Constrain agent tool access and review every high-risk tool path for misuse potential. Bind agent identities to least-privilege authorization and monitor privilege drift at runtime. Validate agent inputs from untrusted content sources before allowing task execution to continue. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is fundamentally about governance of autonomous AI behaviour in enterprise settings. |
| Recommendation — Assign clear accountability for agent governance, monitoring, and approved use cases. | ||
Key terms
- Agentic AI Security: Agentic AI security is the discipline of securing autonomous AI systems that can take actions, use tools, and chain decisions without direct human approval at each step. It covers identity and access management for AI agents, prompt injection defence, tool call governance, credential scoping, and runtime monitoring. As agentic systems acquire real-world authority, API access, file writes, workflow triggers, the security model must treat them as non-human identities with explicit lifecycle controls, not trusted processes.
- AI Service API: An API that lets an AI system or agent interact with services, tools, or orchestration layers. In agentic environments, it becomes part of the attack path because adversaries can hide in normal-looking service calls, reuse legitimate access, and steer execution through the integration layer.
- Tool Credential Harvesting: The abuse pattern where an attacker uses an agent’s connected tools to retrieve secrets, tokens, or API keys. It matters because the tools created to make the agent useful can also become the easiest route to adjacent privileges and broader enterprise access.
- Agentic Browser: An agentic browser is a web browser with an embedded AI assistant that can interpret page content and take actions on the user’s behalf. It combines browsing, reasoning, and execution in one interface, which creates new governance requirements for identity, data handling, and approval boundaries.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org