By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: C1.aiPublished May 13, 2025

TL;DR: 89% of security leaders plan to use AI agents within two years, even though 83% are concerned about the risks and 96% expect deployments to extend beyond non-critical tasks, according to C1.ai’s 2025 Future of Identity Security report. The signal is clear: identity programmes are moving into agentic workflows faster than traditional governance models can absorb.


At a glance

What this is: C1.ai’s survey shows security leaders are rapidly adopting AI agents while still flagging identity risk, complexity, and over-privilege as major concerns.

Why it matters: IAM teams now have to govern human, NHI, and AI-agent access together because the operational pressure to automate is arriving faster than control maturity.

By the numbers:

👉 Read C1.ai's survey findings on AI agents and identity security risk


Context

Identity security is now a control-plane problem, not just an access-management problem. As enterprises add AI agents into security operations, the programme has to govern an expanding mix of human users, non-human identities, and delegated machine actions under one policy model.

The survey points to a familiar pattern: organisations feel the operational pain of identity compromise, then try to solve it with more automation. That works only if the identity lifecycle, entitlement review, and privilege boundaries are already understood well enough to be automated safely. In practice, many teams are still struggling with visibility, over-privilege, and fragmented access controls.

For security leaders, the issue is not whether AI agents will enter the stack. It is whether identity governance can keep pace when boards, operators, and security teams all want the same thing: faster response, fewer manual tasks, and tighter control at the same time.


Key questions

Q: How should security teams govern AI-generated identity workflows in application code?

A: Treat them as controlled code changes, not convenience scaffolding. AI-generated identity workflows should go through the same review, testing, and release gates as any other access-related implementation because the generated output can alter role assignment, invitation handling, and SSO setup behaviour inside production code.

Q: Why do AI systems increase identity risk even when they improve security operations?

A: AI can help defenders, but it also helps attackers scale phishing, impersonation, and credential abuse. That means the same adoption that improves detection can also widen exposure unless authentication, monitoring, and access governance keep pace.

Q: What do security teams get wrong about AI agent and NHI monitoring?

A: They often treat monitoring as a logging problem instead of an identity governance problem. More telemetry does not help if the programme cannot tell which behaviour is expected, who owns the identity, or what an anomaly means in context. Monitoring must be tied to identity semantics, not raw event count.

Q: Should organisations prioritise AI agent settings or service account cleanup first?

A: Start with whichever set of artifacts currently grants broader or less visible access, but do not separate them into different programmes. AI settings files, pipeline tokens, and service accounts can all become enterprise access paths, so the right approach is to govern them under one identity risk model with consistent inventory, classification, and review.


Technical breakdown

Why agentic identity changes the IAM control model

AI agents are not just another workload. When they are used for access requests, provisioning, monitoring, or analysis, they become runtime actors that can trigger identity actions at machine speed. That changes the control model from one-time authorisation to continuous governance of who or what can act, when, and with which delegated permissions. The central technical issue is not automation alone, but the identity boundary around the agent’s tool use and execution scope.

Practical implication: treat agent-enabled workflows as governed identity pathways, not simple automation jobs.

Why over-privilege becomes more dangerous in agentic workflows

Over-privilege is already a common source of compromise in human and NHI environments, but AI agents amplify the blast radius because they can execute many actions quickly once access is granted. If agent permissions are broad, the same access that improves speed also increases the chance of cross-system impact. This is especially relevant when agents can touch provisioning, monitoring, and incident-response systems in the same session.

Practical implication: define agent permissions by task scope and system boundary, not by convenience.

How identity complexity blocks safe AI adoption

Complexity is not just an operational nuisance. In identity programmes, complexity usually means the organisation cannot reliably answer basic questions about account ownership, entitlement scope, or revocation timing. When that uncertainty exists, adding AI agents increases the number of moving parts without fixing the underlying governance gap. The result is more activity, not necessarily more control.

Practical implication: simplify visibility and ownership before expanding agentic access across sensitive identity workflows.


Threat narrative

Attacker objective: The objective is to exploit broad identity permissions and delegated access paths to expand impact faster than governance controls can react.

  1. Entry occurs when organisations grant AI agents access to security workflows such as monitoring, provisioning, or access requests without tightly defining task boundaries.
  2. Escalation follows when those agents inherit broad entitlements or operate across multiple systems, increasing the blast radius of any misuse or misconfiguration.
  3. Impact emerges when identity compromise, improper access, or over-privileged delegation turns speed and scale into faster operational harm.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic adoption is outrunning identity governance maturity. When 89% of leaders plan to use AI agents and 96% expect those agents to do more than non-critical work, the governance burden moves from future planning into immediate operating design. The field is no longer debating whether agents will arrive. It is deciding whether identity controls can define safe boundaries before adoption becomes embedded in daily security operations.

Identity complexity is the hidden constraint on AI agent governance. The survey’s finding that 50% of respondents still see system complexity as the biggest IAM challenge tells us the core problem is control fragmentation, not lack of intent. AI agents do not simplify that condition; they expose it faster. Practitioners should read this as evidence that control quality, not just control count, determines whether agentic access can be trusted.

Non-human identity urgency is becoming a board-level operating assumption. With 93% of leaders calling NHI risk urgent and 42% rating NHIs above human identities in priority, governance is shifting from an IAM subtopic to a central security planning issue. That matters because the same lifecycle, review, and privilege problems now affect service accounts, API keys, and AI agents together. The practical conclusion is that NHI governance is no longer a niche discipline.

Identity blast radius is the concept practitioners should track next. The combination of over-privilege, agentic acceleration, and cross-system automation means the important question is no longer only who has access, but how far a single identity can propagate impact. This is where human IAM, NHI governance, and AI-agent control converge. Security teams should measure where delegated actions can expand faster than review and rollback can contain them.

From our research:

What this signals

Identity programmes will be judged on delegation quality, not just access volume. When boards push AI adoption while IAM complexity remains the top challenge, teams need a cleaner way to distinguish safe delegation from uncontrolled expansion. That means tightening ownership, entitlement scope, and rollback paths before agentic access becomes operationally sticky.

With NHIs already outnumbering humans by 25x to 50x, the next wave of AI agents will not sit outside existing governance debt. The practical signal is that service accounts, tokens, and agent credentials should be treated as one control surface, not separate inventories. Teams that cannot explain the delegated-access chain will struggle to defend it.

Identity blast radius: the useful concept here is how far a single credentialed actor can move before human review catches up. As AI agents are pushed into provisioning and account workflows, blast-radius reduction becomes a better metric than raw automation count for judging programme readiness.


For practitioners

  • Define agent task boundaries before broad deployment Map each proposed AI agent to a single business function, the systems it may touch, and the actions it may never take. Do not let board pressure turn pilot scope into standing enterprise access.
  • Separate agent privileges from human administrator rights Create distinct entitlement sets for AI agents, service accounts, and human operators so that delegated automation never inherits privileged human access by default.
  • Inventory NHI and agent access together Review service accounts, API keys, tokens, and agent credentials in one programme so that entitlement reviews cover the full delegated-access chain, not just human users.
  • Measure identity complexity as a control risk Track ownership gaps, stale entitlements, and revocation latency as governance metrics, because complexity is the signal that access decisions are no longer reliably auditable.
  • Limit high-friction use cases first Start AI agents in narrow monitoring or triage workflows before granting them access requests, provisioning, or account changes that can alter identity state.

Key takeaways

  • The survey shows AI agent adoption is accelerating even while identity leaders remain worried about over-privilege, complexity, and NHI exposure.
  • The central constraint is not enthusiasm for automation but whether IAM and NHI controls can define safe delegation boundaries fast enough.
  • Security teams should prioritise access scope, ownership clarity, and revocation discipline before expanding agents into sensitive identity workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10The article centers on AI agents entering security workflows and the governance gaps that follow.
OWASP Non-Human Identity Top 10NHI-01The article focuses on non-human identities, delegated access, and privilege risk.
NIST AI RMFGOVERNAgentic adoption needs explicit accountability and oversight.
NIST CSF 2.0PR.AC-4The survey highlights access control and least-privilege weaknesses.
NIST Zero Trust (SP 800-207)Section 5.2Zero Trust principles align with continuous verification for delegated identities.

Review access entitlements for least privilege and validate that delegated access matches task scope.


Key terms

  • Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
  • Delegated Access Chain: A delegated access chain is the sequence of permissions that lets one identity act through another, such as an AI agent using a token to call a tool that reaches sensitive data. These chains are hard to see because the original grant and the final action may live in different control planes.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.

What's in the full report

C1.ai's full survey covers the operational detail this post intentionally leaves for the source:

  • Breakdowns of the survey methodology and respondent profile across 494 U.S.-based security leaders.
  • Additional use-case data on network monitoring, SOC automation, and access provisioning priorities.
  • The full set of trend comparisons between 2024 and 2025 for identity compromise, stress, and budget movement.
  • More detail on how respondents weighed AI agent risk against productivity gains in security operations.

👉 C1.ai's full report includes the survey breakdown, use-case priorities, and year-over-year identity risk trends.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building identity strategy or maturing governance across human and non-human access, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org