By NHI Mgmt Group Editorial TeamBased on Keyfactor: “Keyfactor Validates PKI-Based Identity for Securing Agentic AI” (November 11, 2025)

TL;DR: AI systems need strong machine identity controls before they can safely interact with tools, services, and data, as Keyfactor’s validation of PKI-based identity for securing agentic AI points to a broader governance problem. The issue is not whether AI can authenticate, but whether identity, privilege, and lifecycle controls can keep pace with runtime autonomy.


At a glance

What this is: This is a Keyfactor analysis of PKI identity for agentic AI, arguing that the real problem is a governance trust gap between authentication and control over runtime access.

Why it matters: It matters because identity teams now have to govern AI actors that can obtain and use access dynamically, which stresses existing lifecycle, privilege, and trust assumptions.


Context

Agentic AI uses software systems that can decide, act, and call tools at runtime, which means identity controls have to govern behaviour, not just login events. In this article, the primary gap is not whether an AI system can present credentials, but whether those credentials remain governed once the system starts acting independently.

Keyfactor frames PKI-based identity as part of the answer, but the governance problem is broader than certificate issuance. Identity, privilege scope, and offboarding all need to keep pace with agent execution, or the organisation ends up authenticating an actor it cannot reliably constrain.

For identity teams, this is a maturity question as much as a technical one. The article’s starting position is typical of the current market: authentication is advancing faster than the controls that define who or what an agent is allowed to do after authentication.


Key questions

Q: How should security teams govern PKI-based identity for AI agents?

A: They should treat certificates as the start of governance, not the finish. The important controls are scoped issuance, short-lived trust, revocation tied to workflow changes, and logging that links each certificate to downstream actions. Without those controls, PKI authenticates the agent but does not contain its authority or explain what it did.

Q: Why is authentication alone not enough for agentic AI access control?

A: Authentication answers whether the agent can prove its identity, but agentic AI can still take actions that exceed the original intent of that identity. The risk appears after login, when tool use, delegation, and chained actions expand the effective permission boundary. That is why authorisation must operate continuously, not only at issuance.

Q: What fails when AI agents keep valid certificates after their task changes?

A: The failure is governance, not cryptography. A valid certificate can continue to grant trust after the original business purpose has ended, which means the agent may still act under an entitlement that no longer matches the intended scope. That creates dormant authority and weakens offboarding.

Q: What is the difference between PKI identity and agent authorisation?

A: PKI identity establishes cryptographic trust in the actor, while authorisation defines what that actor is allowed to do. For agentic AI, those are separate decisions because the agent may be trusted to authenticate but still need tight limits on tool use, data access, and delegated execution. Conflating the two leaves runtime behaviour under-governed.


Technical breakdown

PKI identity for agentic AI: what actually changes

PKI gives an agent a cryptographically verifiable identity, usually through certificates and related trust chains. That solves one layer of the problem: proving the actor is the same entity it claimed to be. It does not, by itself, define task scope, approval boundaries, or when credentials should stop being usable. For agentic AI, the hard part is that identity must travel with runtime behaviour, not sit only at issuance time. A certificate can confirm trust in the entity, but it cannot on its own prevent the agent from using that trust in an unsafe sequence of actions.

Practical implication: treat PKI as the identity substrate, not the complete control model for agentic AI.

Why runtime autonomy breaks traditional access assumptions

Traditional identity controls assume access is granted to support a relatively stable subject, then reviewed later. Agentic AI can compress that timeline by requesting, using, and chaining access inside a single task flow. That creates a governance mismatch: the actor can change scope mid-session while the control plane still behaves as though access remains stable long enough for periodic review. This is why agentic AI is not just another workload. It introduces decision-making at runtime, which means privilege can no longer be treated as a fixed artifact of provisioning.

Practical implication: move from static entitlement thinking to task-scoped, runtime-aware authorisation for agents.

Certificate lifecycle becomes part of AI governance

Once certificates are used to represent agent identity, certificate lifecycle management becomes an AI governance control, not just a PKI hygiene issue. Issuance, rotation, revocation, and ownership now determine whether the organisation can still trust the agent after its purpose changes or its runtime context drifts. The governance risk is especially sharp when an agent persists beyond the task, the project, or the environment it was created for. In that state, a valid certificate can outlive the business justification for the identity itself.

Practical implication: bind certificate ownership and revocation to the agent lifecycle, not to infrastructure convenience.


Threat narrative

Attacker objective: The objective is to operate through a trusted AI identity in a way that bypasses human-paced governance and expands access beyond intended scope.

  1. Entry occurs when an agent is issued a valid cryptographic identity and can authenticate to connected tools or data sources.
  2. Escalation occurs when the agent uses that identity to obtain additional access or move from one permitted action to a broader task sequence.
  3. Impact occurs when the authenticated agent can act beyond the intended governance boundary without timely revocation or review.
  • Nx s1ngularity attack 2025: Attackers stole Nx's npm token via a GitHub Actions flaw and shipped malware that stole 2,349 secrets and abused developers' AI CLIs.
  • SpotBugs token leak 2025: A SpotBugs maintainer's PAT, stolen via a pull_request_target workflow in 2024, started the reviewdog and tj-actions supply chain attack.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

PKI-based identity for agentic AI is necessary but not sufficient: cryptographic proof of identity solves authentication, not governance. The article highlights a familiar failure mode in a new form: organisations can verify an agent without meaningfully constraining what it does after verification. The practitioner takeaway is that authentication for agents must be paired with runtime authorisation and lifecycle control, or trust becomes a thin wrapper over autonomy.

Runtime privilege, not certificate possession, is the real control plane: agentic AI changes the timing of identity risk because the actor can act, chain tools, and change scope inside one execution flow. That means least privilege cannot be defined only at provisioning time. The field should treat agentic AI as a case where privilege is continuously negotiated at runtime rather than granted once and later reviewed.

Certificate lifecycle has become an AI governance issue: when a certificate represents an autonomous or semi-autonomous actor, revocation and ownership become policy decisions about whether the agent is still entitled to exist. That is a stronger condition than simple credential validity. The article points toward a governance model where certificate state, task scope, and agent purpose must remain synchronised.

Identity trust for agents exposes an assumption collapse in existing IAM: least privilege was designed for actors whose access could be reasoned about at provision time. That assumption fails when the actor can choose actions and tools at runtime, because intended scope is no longer fully knowable in advance. The implication is that agentic AI governance cannot rely on static entitlement logic to describe active behaviour.

Named concept: identity trust gap for agentic AI: this is the gap between being able to authenticate an agent and being able to govern its runtime authority. It is not solved by stronger credentials alone. Practitioners should treat this as a distinct control problem spanning PKI, privilege governance, and lifecycle offboarding.

From our research library:

What this signals

Agentic AI forces identity teams to separate proof of identity from proof of safe authority. A certificate can tell you who the agent is, but it cannot tell you whether the agent should still be trusted to act in the same context ten minutes later.

Identity trust gap for agentic AI: this is the control gap between successful authentication and governed execution. As agent use expands, teams will need policy, ownership, and revocation models that operate at runtime instead of only at enrolment.

67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey. That dependency is incompatible with agents that can acquire and use privileges dynamically.


For practitioners

  • Map agent identities to explicit owners Require every agent certificate or credential to have a named business owner, a technical custodian, and a revocation path tied to that ownership.
  • Bind privilege to task scope Issue access only for a defined task boundary and prohibit reusable standing permissions that remain valid after the task completes.
  • Review certificate lifecycle for agents Align issuance, rotation, expiry, and revocation for agent certificates with the agent lifecycle rather than with infrastructure deployment cycles.
  • Separate authentication from authorisation checks Treat successful agent authentication as a prerequisite only, then enforce explicit policy checks before tool use, data access, or delegated actions.

Key takeaways

  • Agentic AI makes authentication necessary but not sufficient, because a trusted identity can still exercise unsafe runtime authority.
  • The central governance issue is the gap between PKI-based proof and the controls that bound what an agent may do after trust is established.
  • Identity teams should tie agent ownership, task scope, and certificate lifecycle together so that valid credentials do not outlive the authority they represent.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centres on authenticating agent identities with PKI and the limits of that trust.
NHI-05 — Overprivileged NHIThe governance gap is agent privilege that outlives or exceeds its intended task boundary.
NHI-01 — Improper OffboardingAgent certificates and ownership must end when the agent's purpose ends.
Recommendation — Use NHI-04 to separate cryptographic identity proof from runtime authorisation for agent identities. Apply NHI-05 to constrain agent permissions to the smallest task-scoped access set. Use NHI-01 to revoke agent credentials when the business need or runtime context changes.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about governing what authenticated agents may access and do.
Recommendation — Apply PR.AA-05 to enforce continuous authorisation checks for agent actions and tool use.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementAgent credentials can be abused to expand access across tools and services.
Recommendation — Map agent misuse to TA0006 and TA0008 to hunt for credential-driven scope expansion.

Key terms

  • Agentic AI Identity: The complete set of credentials, permissions, and governance controls applied to an autonomous AI agent, covering authentication, authorisation, action logging, and access revocation. Distinct from traditional NHI because agent identities are often ephemeral, delegated, and multi-hop.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
  • Certificate Lifecycle Management: The governance of digital certificates from issuance through renewal and revocation, ensuring certificates are valid, monitored, and rotated before expiry. Expired certificates are a leading cause of outages and unplanned security gaps.
  • Task-Scoped Access: Task-scoped access is permission granted for one defined purpose and removed once the task is complete or the session expires. For non-human identities, it reduces standing privilege and limits how long an attacker can exploit a stolen credential.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org