TL;DR: Teleport’s summary of the OWASP Top 10 for Agentic Applications 2026 shows that AI agents create identity and privilege risks across goal hijack, tool misuse, memory poisoning, insecure inter-agent communication, and rogue behaviour because they act with real permissions in production. Static IAM assumptions break when agents can decide, delegate, and execute within one session.
At a glance
What this is: Teleport’s overview of OWASP’s 2026 agentic applications Top 10 argues that AI agents introduce distinct identity, privilege, and trust failures that conventional IAM assumptions do not cover.
Why it matters: IAM, PAM, and security teams need to treat agent identities as governed actors because tool access, delegation, and session behaviour now shape security outcomes as much as authentication does.
👉 Read Teleport's analysis of OWASP Top 10 for agentic applications identity risks
Context
Agentic applications are software systems where an AI agent can choose actions, call tools, and continue work with live permissions. The governance problem is not just that agents are automated, but that they can behave like users while still operating outside human identity controls and conventional recertification assumptions.
Teleport’s article frames the 2026 OWASP Top 10 as a response to that shift in control plane thinking. The central issue for identity programmes is that agents can hold, inherit, misuse, and propagate privilege in ways that make static access models and human-paced approvals too slow to define risk accurately.
Key questions
Q: What breaks when agentic AI is governed like a normal application account?
A: Security controls break down because agentic systems do not behave like fixed-function applications. They can choose actions at runtime, combine tools in unexpected ways, and move faster than periodic review cycles. That means static roles, annual recertification, and one-time approvals do not fully describe the risk or contain the behaviour.
Q: Why do AI agents increase privilege risk even when logs exist?
A: Logs record what happened, but they do not stop a privileged agent from taking an irreversible action before review. If the agent can chain requests quickly, the governance problem is not visibility alone. The risk comes from granting access too early and leaving it available for whatever the agent decides to do next.
Q: What are the signs that agent memory or context is being poisoned?
A: Look for repeated bad recommendations, sudden shifts in tool selection, inconsistent task memory, or outputs that reference instructions the operator never approved. Those signals suggest that the agent is carrying forward untrusted context into later sessions, which can bias decisions long after the original injection.
Q: How should security teams compare agentic supply chain controls with identity controls?
A: Treat them as linked but distinct. Identity controls govern who or what gets to act, while supply chain controls govern what runtime components the agent is allowed to trust before it acts. If the agent can load external tools or descriptors dynamically, both controls are required to keep the trust boundary intact.
Technical breakdown
Why agent goals become an identity control problem
Agent Goal Hijack happens when an attacker changes what an agent is trying to accomplish by injecting instructions through documents, emails, APIs, or retrieved content. The security issue is not only prompt injection. Once the agent treats external text as part of its decision process, its goals become a governance surface that can steer tool use, data access, and execution paths. In practice, the identity model must assume that reasoning inputs can become authorization inputs unless they are isolated and constrained.
Practical implication: treat all goal-influencing inputs as untrusted and gate high-impact actions with explicit approval.
Tool misuse, privilege abuse, and scoped execution
Tool Misuse & Exploitation and Identity & Privilege Abuse show two related failures. In the first, the agent uses legitimate tools in unsafe ways, such as chaining a harmless action into a destructive API call. In the second, the agent inherits credentials, delegation, or implicit trust and then operates beyond the intended owner’s scope. Both risks show that access control for agents is not just about whether a tool is reachable, but whether the tool and the identity context are bounded tightly enough to prevent misuse across steps.
Practical implication: issue each agent a bounded identity with short-lived credentials, then constrain each tool by scope and action class.
Memory poisoning and inter-agent communication failures
Memory & Context Poisoning and Insecure Inter-Agent Communication move the risk from isolated actions to distributed decision corruption. If an attacker can alter long-term memory, RAG content, or shared context, the agent’s future decisions inherit that poison. If agents communicate over weakly authenticated channels, malicious messages can be replayed, spoofed, or modified. In both cases, trust is no longer local to one session. It becomes a propagation problem across stored context and machine-to-machine exchange.
Practical implication: validate memory writes, sign agent messages, and isolate context so poisoned data cannot spread across tasks.
Threat narrative
Attacker objective: The attacker aims to steer a live agent into carrying out unsafe actions with valid permissions while hiding the abuse inside normal agent behaviour.
- Entry occurs when malicious instructions arrive through external text, poisoned memory, a compromised plugin, or a spoofed agent message.
- Privilege or decision abuse follows when the agent accepts that input as part of its operating context and uses legitimate tools or delegated access accordingly.
- Impact lands as destructive actions, data exposure, replayed commands, or cascaded failures across connected agents and services.
Breaches seen in the wild
- reviewdog Action compromise 2025: A stolen maintainer token poisoned reviewdog/action-setup, leaking CI secrets including the tj-actions bot token used in the next attack.
- Shai Hulud npm malware campaign: Shai Hulud campaign: npm malware exposed secrets on GitHub.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Agentic identity is not a new wrapper around existing IAM. It is a different governance problem because the actor can decide, delegate, and act inside the same session. That means access intent is no longer stable at provisioning time, and a control model built for fixed human or workload behaviour loses precision as soon as the agent starts sequencing its own actions. Practitioners should treat agent identity as a runtime governance object, not a static account.
Least privilege becomes harder to define once the actor can choose its own path. The article’s ASI01, ASI02, and ASI03 categories show that goal selection, tool choice, and delegated privilege can all drift during execution. That is where traditional entitlement reviews become weak evidence, because the risk is not only over-assignment but also overreach created mid-task. The practitioner conclusion is that authorisation for agents has to be reasoned about at the moment of use, not only at provisioning.
Identity blast radius is the right named concept for this category. A single agent can touch APIs, code, memory, and other agents, so one compromise can spread across systems much faster than a human session. OWASP’s focus on cascading failures and rogue agents reflects a governance reality: the unit of control is no longer just the identity, but the reach of its live permissions across connected runtime paths. Teams should assess how far one agent can propagate error before containment triggers.
Agentic supply chain risk extends the trust boundary into runtime composition. The article shows that models, plugins, descriptors, and tool sources can be loaded dynamically, which means the identity problem includes what the agent trusts before it acts. That makes manifests, inventories, and signed attestation part of the identity story, not just software hygiene. The implication is that security teams need to govern the sources feeding agent behaviour as tightly as the credentials the agent uses.
Auditability must shift from who accessed what to why the agent did it. Human review alone cannot explain decisions that emerge from memory, delegated tools, and chained actions. The article’s controls point toward logs, session records, and explicit approvals, but the deeper lesson is that traceability has to capture both the permission and the reasoning context at the moment action occurs. Without that, investigation will reconstruct outputs while missing the governing decision path.
From our research library:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- Read next: AI Agent Identity Security Buyer's Guide
What this signals
Identity blast radius: agent programmes should be designed around the maximum harm one session, one tool chain, or one delegated task can produce before containment. That is the governance shift this category forces, because agent behaviour can propagate faster than human review cycles can react.
Agentic systems also push lifecycle governance into the foreground: short-lived credentials, explicit offboarding, and traceable delegation become more important than periodic entitlement snapshots. When runtime composition changes every task, the control point moves toward issuance, approval, and revocation rather than retrospective certification.
For practitioners
- Define agent identities as bounded runtime principals Assign each agent a unique identity, short-lived credentials, and explicit tool scope so delegated authority cannot be reused across tasks.
- Separate planning from execution Require approval or validation gates before an agent can move from reasoning to destructive actions, code execution, or privileged API calls.
- Validate memory and context inputs Scan writes to long-term memory, RAG stores, and shared context before commit so poisoned data does not influence later decisions.
- Sign and authenticate inter-agent messages Use authenticated channels, message signing, and replay protection so spoofed or modified agent-to-agent traffic cannot alter commands.
- Instrument agent activity for containment Keep tamper-evident logs, tool invocation traces, and blast-radius limits so a compromised agent can be isolated quickly.
Key takeaways
- Agentic applications collapse the assumption that identity is a stable, human-paced construct, because the actor can decide and act during the same session.
- The risk is not confined to prompt injection. Tool misuse, privilege abuse, poisoned memory, and unsafe inter-agent messaging can all turn legitimate access into harmful action.
- Teams need session-level governance for agents, with bounded identities, traceable actions, and containment controls that limit how far one compromise can spread.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI01 — Agent Goal Hijack | Goal hijack is one of the article’s core agentic risks and maps directly to runtime manipulation of agent intent. |
| ASI02 — Tool Misuse | Tool misuse is central to the article’s explanation of how legitimate capabilities become dangerous in agentic systems. | |
| ASI03 — Identity & Privilege Abuse | Identity and privilege abuse is the article’s clearest identity governance issue for agents. | |
| Recommendation — Treat externally influenced agent goals as untrusted and require approval for goal-changing actions. Constrain each agent tool by scope, data access, and allowed action class. Issue each agent a bounded identity with short-lived credentials and re-authorization for escalation. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Short-lived agent credentials and revocation are authenticator-management concerns. |
| Recommendation — Use IA-5 to enforce short-lived agent credentials and rapid revocation of stale authenticator state. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about how agent permissions and entitlements must be governed differently. |
| Recommendation — Apply PR.AA-05 to review and constrain agent entitlements at the point of issuance. | ||
| NIST Zero Trust (SP 800-207) | Least privilege — Least privilege | The article repeatedly relies on zero-trust style privilege scoping for agents and their tools. |
| Recommendation — Design agent access around least privilege and continuous verification of each request. | ||
Key terms
- Agent Goal Hijack (ASI01): An attack where an adversary redirects an AI agent's objectives by manipulating its instructions, tool outputs, or external content, causing it to act outside its intended scope while appearing normal. The number one risk in the OWASP Top 10 for Agentic Applications 2026.
- Tool Misuse: Tool misuse occurs when an agent uses an allowed integration in a way that exceeds its intended task, scope, or risk tolerance. The problem is often not access alone but the combination of valid credentials, broad permissions, and unbounded action sequencing.
- Context And Memory Poisoning: Context and memory poisoning are techniques that manipulate what an agent reads in the moment or stores for later use. The first shapes immediate responses and tool calls within a session, while the second persists across sessions. Both can steer behaviour gradually, making compromise look like normal reasoning drift.
- Rogue Agent (ASI10): An AI agent that has been compromised, manipulated, or misaligned and now operates outside its intended purpose, potentially exfiltrating data, escalating privileges, or sabotaging systems, while appearing superficially legitimate.
What's in the full article
Teleport's full blog post covers the operational detail this post intentionally leaves for the source:
- Teleport’s specific guardrail pattern for AI agents and MCP servers using ephemeral X.509 or SSH certificates
- Examples of identity-based access requests and moderated sessions for human-in-the-loop oversight
- The article’s own implementation framing for access guardrails, audit logs, and per-session authorisation
- Related resource links on secretless engineering and securing MCP implementations
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org