By NHI Mgmt Group Editorial TeamBased on Oasis Security: “RSA 2025: 5 Takeaways on AI, Third‑Party Risk & the Future of Identity” (May 1, 2026)

TL;DR: RSA 2025 made one pattern clear: AI is moving into security workflows while third-party risk and non-human identity sprawl are moving to the centre of identity governance, according to Oasis Security’s conference takeaways. The practical shift is that IAM, NHI, and AI security controls now have to be designed together, not as separate programmes.


At a glance

What this is: This conference roundup argues that RSA 2025 made identity the control plane for both AI-enabled security and NHI governance, with third-party risk, service accounts, and access ownership becoming the dominant operational themes.

Why it matters: It matters because IAM, NHI, PAM, and emerging AI security workflows now intersect in the same control surface, so practitioners need one governance model for identities that can act, automate, or be delegated.


Context

RSA 2025 framed identity as the control plane behind both AI-assisted security operations and the growing NHI estate. In practical terms, that means the old separation between human IAM, NHI governance, and security automation is breaking down.

The article points to third-party risk, model supply chain concerns, and NHI sprawl as the same governance problem expressed through different assets. As gen-AI tools and SaaS dependencies expand, ownership, lifecycle, and entitlement scope become the control points that matter most.

For IAM and security teams, the issue is not whether AI belongs in operations, but how identity controls are extended to the systems, service accounts, and delegated access paths that AI and third parties depend on.


Key questions

Q: What breaks when AI-assisted security workflows rely on unmanaged machine identities?

A: The control plane becomes opaque. If service accounts, API keys, and tokens used by AI workflows are not owned, scoped, and reviewed, then automation can reach sensitive systems without a clear accountability trail or a reliable offboarding path.

Q: Why do third-party integrations increase identity risk so quickly?

A: Third-party integrations increase identity risk because they extend trust through credentials, tokens, and delegated access rather than through direct human oversight. Once the supplier has standing access, your programme inherits the supplier’s governance quality. That is why inventory, expiry, and revocation discipline matter as much as vendor due diligence.

Q: How should security teams govern AI-assisted actions in the SOC?

A: Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation. Define which tools the system may access, which actions require approval, and what must be logged for later review. The goal is to keep investigation speed while preserving human accountability and least privilege across prompts, queries, and remediation steps.

Q: How can organisations tell whether their NHI controls are keeping up with AI agents?

A: Look for controls that can prove who requested access, which tool was used, what scope was granted, and whether the identity could be revoked cleanly. If those answers require manual reconstruction across logs, the programme is behind the behaviour it is trying to govern.


Technical breakdown

Identity as the security control plane

Identity becomes the control plane when access decisions, ownership, and accountability sit above individual tools and workflows. In this article’s framing, security outcomes increasingly depend on whether the organisation can discover who or what is acting, map that actor to an owner, and govern its entitlement scope across cloud and SaaS environments. That is the core IAM and NHI convergence point: the control is no longer the app or the network boundary, but the identity attached to the action. Practicality matters because teams cannot secure AI-enabled operations if they still treat identities as static accounts rather than operational control objects.

Practical implication: unify ownership and entitlement governance across human users, service accounts, and delegated machine identities.

Third-party risk in identity-connected supply chains

Third-party risk now extends beyond vendor contracts into the identities vendors and tools use to interact with customer environments. API keys, service accounts, tokens, and privileged integrations create trust paths that can outlive the original business justification if they are not continuously governed. The article’s emphasis on supply chain control reflects a common pattern: the more operational value a third party provides, the more identity surface it receives. That surface has to be inventoried, scoped, and monitored like any other privileged access path, because compromise often enters through the relationship rather than the application itself.

Practical implication: inventory third-party identities and align them to lifecycle and access review controls, not just procurement reviews.

AI for security changes the identity problem, not just the workflow

When AI assists triage, investigation summaries, or playbook generation, it starts to participate in security decisions rather than merely support them. That shifts the identity question from who can use the tool to what the tool can touch, infer, and trigger on behalf of the operator. In governance terms, the security team has to classify AI-adjacent credentials, define approved data boundaries, and decide where human approval remains mandatory. The article suggests this move is already happening in SOC workflows, which means identity controls must be designed for runtime delegation, not only for static human access.

Practical implication: define approval boundaries for AI-assisted workflows before they are wired into live SOC processes.


Threat narrative

Attacker objective: The attacker seeks to leverage trusted third-party or machine identities to move through the control plane with less scrutiny than a direct user compromise would face.

  1. Entry begins through a trusted third-party identity such as an API key, service account, or vendor integration that already has access into the environment.
  2. Credential access or misuse follows when that identity is over-scoped, poorly owned, or not tied to a clear lifecycle and review process.
  3. Escalation occurs when the same delegated access reaches sensitive workflows, cloud assets, or security operations data without tighter authorization boundaries.
  4. Impact is control-plane compromise, where identity trust is abused to influence security operations, cloud posture, or downstream supply chain access.
  • Salesloft OAuth token breach: hackers stole OAuth tokens to access Salesforce data via Salesloft.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity governance is becoming the operating layer for AI-enabled security. RSA 2025’s signal is not that AI is replacing security operations, but that identity is now the mechanism that decides what AI can see, touch, and trigger. When copilots move into production, entitlement scope and ownership become more important than model novelty. Practitioners should treat security AI as an access problem first and an automation problem second.

Third-party access without lifecycle discipline is now a supply chain risk, not a vendor-management detail. The article’s emphasis on SaaS chains and NHI sprawl shows that trust is being extended through integrations faster than governance is being attached to them. That creates a control gap across onboarding, recertification, and offboarding. The practitioner conclusion is straightforward: the identity plane must extend into third-party operational relationships, not stop at contract review.

Ephemeral access does not remove accountability when the identity estate expands dynamically. As gen-AI tools create micro-services on demand and service identities multiply, the relevant governance question becomes who owns each identity and when its authority ends. This is where NHI governance and IAM converge most sharply. Teams need an identity lifecycle model that can follow machine-created access as closely as it follows human-created access.

Runtime delegation is the named concept that best captures the RSA 2025 shift. Identity is no longer just about authentication and authorization at login, because AI-assisted workflows and third-party integrations make decisions during execution. That means governance has to move closer to issuance time, classification time, and trust propagation time. Practitioners should assume the control plane is now dynamic and distributed across humans, NHIs, and AI-enabled systems.

OWASP-NHI and broader access governance are converging on the same failure mode: unmanaged delegated trust. The conference themes map cleanly to NHI lifecycle gaps, overprivileged integrations, and hidden machine access paths that are hard to see once production starts. The implication for the field is that identity programmes can no longer treat machine access as a niche inventory problem. They need to govern it as core architecture.

From our research library:

What this signals

Runtime delegation: AI-assisted security will keep expanding the set of identities that can act on behalf of humans, but the governance model still has to answer who owns the delegated authority and when it ends. That makes lifecycle control a prerequisite for safe automation, not a follow-on cleanup step.

Third-party access paths are now identity assets in their own right. If procurement, security review, and access governance stay separated, organisations will keep discovering that their riskiest trust relationships are also their least visible ones.


For practitioners

  • Map AI-adjacent access paths Inventory the service accounts, API keys, tokens, and delegated permissions used by AI-assisted security workflows, then assign clear ownership and expiration rules.
  • Reclassify third-party trust relationships Treat vendor integrations as governed identity relationships, not just contractual dependencies, and subject them to the same review and revocation discipline as internal access.
  • Set approval boundaries for security copilots Define which investigations, summaries, or response steps AI can perform independently and which must remain human-approved before execution.
  • Right-size NHI entitlements continuously Use periodic entitlement reviews to remove excess privileges from service accounts and machine identities before they become part of the security control plane.

Key takeaways

  • RSA 2025 reinforced that identity, not tooling, is the control layer that now connects AI-assisted security, third-party risk, and NHI governance.
  • The article points to machine identities, delegated access, and integration trust as the practical pressure points for modern security programmes.
  • Teams that cannot assign ownership and lifecycle controls to non-human access will struggle to govern AI-enabled workflows safely.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIThe article focuses on third-party identities and supply chain trust paths.
NHI-05 — Overprivileged NHIIt highlights right-sizing entitlements for service accounts and machine access.
NHI-07 — Long-Lived SecretsThe article’s NHI and integration themes depend on secrets that can outlive their intended use.
Recommendation — Inventory third-party NHIs and bind them to ownership, scope, and revocation rules. Reduce NHI privilege scope and remove unused entitlements from delegated access paths. Shorten credential lifetimes and review long-lived secrets used by integrations.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsIdentity governance and entitlement scope are the central control themes.
Recommendation — Apply entitlement governance to all human, machine, and third-party access paths.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article’s threat pattern centers on trusted credentials and downstream access expansion.
Recommendation — Map delegated identity paths to credential access and lateral movement detections.

Key terms

  • Runtime Delegation: The process by which an identity is allowed to choose actions, tools, or next steps while a task is in progress. In AI agent environments, runtime delegation is risky when it is broad, opaque, or disconnected from explicit policy, because the resulting behaviour may exceed the original intent.
  • Third-Party Identity: An identity issued to a partner, vendor, contractor, or external service that can access internal systems. These identities often sit outside normal employee governance and can become persistent trust paths if they are not reviewed, expired, and revoked on schedule.
  • Identity Control Plane: An identity control plane is the governance layer that decides who or what can access systems and under what conditions. In practice, it coordinates authentication, authorization, privilege review, and lifecycle management across human and machine identities so access policy is enforced consistently across environments.
  • Delegated access path: A delegated access path is the chain of identities, tokens, connectors, and approvals that lets one system act through another. It becomes a governance concern when the path outlives the original approval or can be reused for actions beyond the intended business purpose.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org