TL;DR: The core issue is not whether AI can talk, but whether identity and access controls can safely govern autonomous execution, according to Palo Alto Networks, which says Prisma AIRS 3.0 adds discovery, risk assessment, and runtime protection across the agentic AI lifecycle, including agent inventory, architectural scanning, AI red teaming, and a control plane for authorization and observability.
At a glance
What this is: This is Palo Alto Networks' view of agentic AI security moving from observation to authorization, with runtime identity governance positioned as the control point that matters most.
Why it matters: IAM, PAM and NHI teams need to account for AI systems that choose actions at runtime, because governance designed for static access no longer captures agent behaviour, scope and execution risk.
Context
Agentic AI changes the security problem from monitoring outputs to governing independent action. Once an AI system can select tools, execute tasks and continue without human approval gates, identity becomes an operating control rather than a login event.
Palo Alto Networks frames Prisma AIRS 3.0 around discovery, risk assessment and protection across the agentic lifecycle. That matters because unmanaged AI agents can live in cloud services, SaaS applications and endpoints that conventional inventory and review processes often miss.
The governance gap is not simply that AI is complex. It is that existing access models assume access can be observed, reviewed and revoked on a predictable human schedule, while agentic execution can appear, act and disappear inside a single workflow.
Key questions
Q: What breaks when AI systems are governed like static applications?
A: Lifecycle drift breaks the model. AI systems change through training, fine-tuning, updates, and retirement, so static controls miss where risk enters and where access should end. That creates blind spots for data exposure, connector reuse, and post-deployment misuse.
Q: Why do autonomous MCP agents need NHI-style identity controls?
A: Autonomous MCP agents need NHI-style controls because they operate as their own principals once deployed. That removes the stable human owner assumption that underpins many IAM workflows. Ownership, access scope, review, and offboarding all have to be expressed against the agent itself, not against the person who launched it.
Q: How do security teams know if AI governance is working?
A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.
Q: How should security teams govern human, NHI, and agentic access in one programme?
A: Security teams should use one control plane for policy, logging, and lifecycle visibility, then apply actor-specific rules for authentication, credentials, and runtime behaviour. Humans, service accounts, and agentic systems should not share identical enforcement assumptions. The goal is consistent governance with differentiated controls, not separate identity programmes that drift apart.
How it works in practice
Agent inventory and shadow AI discovery
Agentic environments create an identity inventory problem before they create a policy problem. If teams cannot find where agents live, which models they use or what systems they connect to, they cannot govern authorization consistently. Shadow AI in this context means unmanaged agents operating outside formal inventory and approval paths. Discovery has to include cloud services, SaaS tenants and endpoints because the same agentic workload may span all three. The architectural implication is that discovery is part of identity control, not a separate asset-management exercise.
Practical implication: Treat agent discovery as a prerequisite control and inventory every agent, model connection and execution location before authorising access.
Agent architecture scanning and risk assessment
Agent Artifact Security is aimed at the design layer, where an agent's structure, dependencies and likely failure modes can be evaluated before runtime. In practice, that means looking for vulnerable components, unsafe tool chains and weak control boundaries inside the agent itself. AI red teaming extends that analysis by simulating context-aware attacks against agent behaviour, not just model outputs. The technical point is that agent risk is not limited to prompts or content safety. It includes the way the agent is wired to data, tools and execution paths, which is where authorization failures become exploitable.
Practical implication: Review agent architecture and tool chains before deployment so that unsafe dependencies are found before they become runtime access paths.
Runtime authorization and observability for autonomous execution
The AI Agent Gateway represents the runtime control layer Palo Alto Networks is describing, where identity, governance and observability meet. For agentic systems, runtime control has to answer three questions at once: who or what is the agent, what may it access, and what did it actually do. That is a different model from simple authentication because the security problem is ongoing delegation, not just entry. Observability also has to capture behaviour after deployment, because agentic risk shifts as the system chains tools, changes scope and completes tasks without a human in the loop.
Practical implication: Enforce task-scoped authorization and log post-deployment behaviour so that agent actions remain attributable and reviewable.
NHI Mgmt Group analysis
Agentic identity governance is now a runtime problem, not an inventory problem. Palo Alto Networks is describing a class of systems that can act independently across discovery, assessment and execution. That shifts the control question from whether an AI exists to whether its authority is bounded while it runs. Practitioners should read this as a governance pivot: identity controls must follow the agent into runtime, not stop at provisioning.
Access review processes assume access persists long enough to be reviewed. That assumption was designed for human and conventional NHI administration, where entitlements remain stable across a review cycle. It fails when an autonomous agent can obtain, use and discard access within a single session. The implication is that review cadences alone cannot govern agentic behaviour; control has to move to issuance time and execution time.
Shadow AI becomes an identity inventory failure when agents live outside the CMDB. The article's emphasis on discovering agents in cloud, SaaS and endpoints shows that unmanaged agentic identities can evade normal ownership models. That is not just a visibility gap, it is a lifecycle gap: if the estate is unknown, offboarding and recertification never start. Practitioners should treat undeclared agents as governance exceptions, not merely missing assets.
Agentic identity trust debt is the new lifecycle risk surface. The article points to design-time scanning, red teaming and runtime authorization because static trust decisions age poorly once agents can choose tools dynamically. A model that assumes the same access pattern from deployment to retirement will drift as the agent learns, re-plans or changes execution path. The field should now measure how quickly agent authority decays against its actual behaviour, not just whether the initial approval was clean.
Runtime observability is becoming a prerequisite for accountability. If a platform cannot explain what an agent accessed, when it did so and which controls approved the action, identity governance cannot support audit or containment. That problem spans NHI, IAM and agentic AI at once because the actor may not be human, but the accountability model still has to be enforceable. Practitioners should insist on traceable agent actions as a baseline control, not a reporting luxury.
From our research library:
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.
- Read next: Agentic AI Identity Guide
What this signals
Agentic identity governance will increasingly be measured at runtime. Programmes that still focus on cataloguing AI behaviour without enforcing live authorization will not be able to explain who acted, what they touched or why the action was allowed. The control boundary is shifting from model observation to action governance, which makes runtime traceability a board-level concern.
Access review cadence is too slow for autonomous execution. Access review processes assume access persists long enough to be certified, but autonomous agents can acquire and release privileges within a single task. That means the programme has to move critical control decisions closer to issuance time, not merely tighten periodic review.
For practitioners
- Define an agent inventory standard Catalog every agent, model connection, tool integration and execution location across cloud, SaaS and endpoint estates so unmanaged agentic identities do not sit outside governance scope.
- Separate design-time and runtime review Use architectural scanning and red teaming before deployment, then apply separate runtime authorization controls once the agent starts executing tasks independently.
- Bind agent authority to task scope Limit access to the minimum tool set and data paths needed for the current task, and revoke that authority as soon as the task completes or changes context.
- Instrument post-deployment behaviour logging Capture which systems the agent accessed, which tools it invoked and how its scope changed after deployment so audit, incident response and recertification have evidence to work from.
- Treat shadow AI as a governance exception Escalate any undiscovered or unmanaged agent into the same exception handling path used for unapproved privileged access until ownership and control are assigned.
Key takeaways
- Agentic AI changes the governance problem because systems that act independently need runtime authorization, not just monitoring and approval at setup.
- Discovery, architectural scanning and red teaming are only partial controls unless the organisation can also govern what the agent is allowed to do while it runs.
- Identity security teams should treat autonomous agents as a distinct lifecycle class with inventory, scope control and traceability built into the operating model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centers on autonomous agent authority and runtime governance. |
| Recommendation — Constrain agent privileges to the minimum runtime scope and revoke access as task context changes. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Agentic identities can accumulate excess authority across cloud, SaaS and endpoint environments. |
| NHI-10 — Human Use of NHI | The article warns that unmanaged agents can bypass normal ownership and governance paths. | |
| Recommendation — Audit agent permissions continuously and remove any access that exceeds task-scoped need. Require named ownership and explicit approval for every agentic identity before deployment. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The release is framed around governance and accountability for autonomous AI execution. |
| Recommendation — Establish accountability, approval and escalation paths for agentic systems before production use. | ||
| NIST Zero Trust (SP 800-207) | Principle of least privilege — Principle of least privilege | Runtime authorization for autonomous agents maps to least privilege and continuous verification. |
| Recommendation — Apply least privilege and continuous verification to every agent action path and tool connection. | ||
Key terms
- Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
- Agent Inventory: A governed record of every AI agent in use, including who created it, who can invoke it, what data it can reach, and what actions it can trigger. Without a current inventory, security teams cannot judge whether agent access still matches the business purpose.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org