TL;DR: Identity remediation, ServiceNow automation, and AI agent security are converging across Bedrock AgentCore and ServiceNow AI Agents, signalling a broader shift from visibility to governed action, according to Veza. For IAM teams, the real question is whether remediation workflows can keep pace with autonomous and semi-autonomous identities before access drift becomes operational risk.
At a glance
What this is: This is a May 2026 Veza product update roundup focused on AI agent security, identity remediation automation, and integrations with ServiceNow and Amazon Bedrock AgentCore.
Why it matters: It matters because IAM teams now have to govern AI agents, shadow AI, and remediation workflows in the same identity operating model that already covers service accounts and human access.
By the numbers:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
👉 Read Veza’s May 2026 product updates on AI agent security and identity remediation
Context
Veza’s May 2026 roundup sits at the intersection of identity security, workflow automation, and AI agent governance. The primary issue is not the release cadence itself, but the growing need to decide which identities can trigger remediation, which can only be observed, and which must remain tightly constrained inside existing IAM and PAM controls.
For security teams, the important question is how AI agent security fits into the same lifecycle model used for service accounts, API keys, and other non-human identities. Once identity remediation becomes automated, the control problem shifts from simple detection to deciding whether the actor is allowed to act, when it can act, and how its access is revoked or bounded.
Key questions
Q: How should IAM teams govern AI-assisted identity workflows?
A: Treat AI-assisted identity workflows as governed control paths, not simple productivity tools. Define which tasks the assistant may recommend, draft, or execute, then keep approval rights and exception handling with named humans. The essential control is traceability, so every machine-generated action can be reviewed, challenged, and linked back to a responsible operator.
Q: Why do AI agents complicate identity remediation more than traditional automation?
A: AI agents can influence remediation decisions in context rather than simply following a fixed script. That means the risk shifts from job execution to governance of decision boundaries, approval gates, and downstream identity state changes that may happen faster than teams can manually inspect them.
Q: What breaks when shadow AI is not mapped in the access graph?
A: Teams lose visibility into which service accounts, tokens, or delegated credentials give hidden AI systems access to tools and data. Without that mapping, least privilege cannot be measured properly, and offboarding may miss the real execution path that keeps the agent alive.
Q: Who should own revocation for AI agent and service account access?
A: Ownership should sit with the team that can revoke access in time and understand the operational purpose of the identity. If no one can act before the chain completes, accountability is only theoretical and the control model is already too slow.
Technical breakdown
AI agent security inside identity remediation workflows
AI agent security changes the control plane because the actor can influence identity workflows rather than just consume them. In practice, that means agents may assist with discovery, triage, or remediation recommendations, while still relying on explicit authorization boundaries and monitored execution paths. The architectural risk is not only access misuse, but overtrust in a system that can accelerate decisions across multiple identity stores and remediation queues. When AI agent actions are coupled to ticketing or response systems, the identity boundary must be clear enough for audit, rollback, and human override.
Practical implication: treat AI-assisted remediation as a governed workflow, not as an autonomous trust decision.
Identity remediation automation and ServiceNow integration
Automating identity remediation with ServiceNow shifts the issue from manual ticket handling to policy-driven execution. That architecture is useful only if the remediation trigger, approval path, and final revocation step are all visible to the identity programme. The weakness in many environments is not detection, but delayed or inconsistent closure once a risky account, token, or entitlement is identified. Remediation automation also needs strong exception handling, because orphaned cases and partial fixes can leave privilege exposure intact even after the workflow appears complete.
Practical implication: map every automated remediation path to a clear ownership, approval, and revocation checkpoint.
Shadow AI discovery and access graph context
Shadow AI becomes an identity problem when unmanaged agents and tool connections appear outside approved governance. Discovery alone is insufficient if the access graph cannot show which identities can reach which tools, datasets, or downstream systems. The real value of an access graph is that it turns hidden dependencies into governable relationships, especially when AI systems are connecting to sensitive sources through service accounts or delegated tokens. Without that mapping, teams may see the AI workload but still miss the effective privilege chain behind it.
Practical implication: inventory AI-connected identities and map their effective access paths before expanding automation.
NHI Mgmt Group analysis
Identity remediation is becoming an execution problem, not just a visibility problem. The moment an identity platform can trigger workflows into ServiceNow or AI agent environments, it stops being a passive control and starts influencing operational outcomes. That raises the bar for approval, logging, and rollback because remediation itself can create new access states. Practitioners should judge these systems by the safety of their execution boundaries, not by the completeness of their dashboards.
AI agent security and NHI governance are converging around the same control question: who is allowed to act on identity state. Service accounts, API keys, and AI agents may differ in runtime behaviour, but each can change access conditions without a human typing credentials at the moment of use. That means lifecycle governance, not point-product detection, becomes the durable organising model. The practical conclusion is that identity teams need one governance plane for all non-human actors.
Shadow AI expands the identity blast radius because hidden agents can inherit access through delegated tooling. The risk is not limited to the agent itself. It also includes the service account, token, or workflow account that lets the agent operate across systems. When those dependencies are invisible, least privilege is no longer measurable in practice. Security teams should treat access graph visibility as a prerequisite for any AI-enabled identity programme.
Automated remediation only works when access state can be reversed cleanly. If a workflow can create a revocation, but cannot confirm completion across all connected systems, then the organisation has automation without governance. That is especially important for environments with multiple identity stores, third-party integrations, and fast-moving AI workloads. Practitioners should assume incomplete remediation is still exposure until closure is verified end to end.
From our research:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- For a deeper baseline, 52 NHI Breaches Analysis shows how missing lifecycle controls repeatedly turn delegated access into incident paths.
What this signals
Shadow AI governance now depends on identity discovery, not just model governance. As AI systems are connected to internal tools through delegated credentials, teams need to identify the service accounts and tokens that make those connections possible before they can govern the agent itself. That is why access graph visibility is becoming a core requirement for modern identity programmes. Access graph visibility is the control concept that turns hidden AI connections into auditable identity relationships. Practitioners should use it to prioritise offboarding and approval boundaries before expanding automation.
The next maturity step is to decide which remediation actions can be safely machine-mediated and which must remain human-approved. That decision belongs in IAM, PAM, and IGA governance, because workflow speed alone does not prove control quality. When remediation is automated without clean state verification, organisations can create the appearance of closure while leaving access paths active.
NHI governance and AI agent security are converging on the same operational question: can the organisation prove that every non-human actor has a current owner, a bounded purpose, and a revocation path? If the answer is no, then the programme is still running with unmanaged identity debt, regardless of how advanced the tooling looks.
For practitioners
- Define approval boundaries for AI-assisted remediation Classify which identity actions an AI workflow may recommend, which it may execute, and which always require human approval before state change. Tie those boundaries to the same entitlement model used for service accounts and operational accounts, then test for rollback and audit completeness.
- Map remediation workflows to identity lifecycle checkpoints Document where a ticket, alert, or agent action becomes a real access change and who owns each transition. Include create, modify, revoke, and exception states so that automated handling does not leave partial privilege behind.
- Inventory AI-connected identities and delegated tokens List every service account, API token, or credential path that allows AI systems to reach internal tools or sensitive data. Prioritise the paths that cross business units or third-party systems, because those are the routes most likely to hide unreviewed access.
- Treat shadow AI as a discovery and offboarding problem Use the access graph to find AI agents or tool connections that are not in the approved inventory, then determine how they are authenticated and how they are removed. Discovery without offboarding leaves dormant access in place even after the system is no longer trusted.
Key takeaways
- Veza’s May 2026 update reflects a wider shift from identity visibility to governed execution across AI agents and remediation workflows.
- The central risk is not only unmanaged AI activity, but incomplete control over the identities and delegated paths that allow AI systems to act.
- IAM teams should treat remediation automation, shadow AI discovery, and access graph mapping as one identity governance problem.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | The article centers on AI agent security and delegated tool use in identity workflows. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity remediation and shadow AI discovery both depend on governed non-human identities. |
| NIST CSF 2.0 | PR.AC-4 | Least privilege and access governance are central to remediation and agent control. |
| NIST Zero Trust (SP 800-207) | 4.5 | Zero Trust access decisions matter when AI systems act through delegated credentials. |
| NIST AI RMF | GOVERN | AI agent security requires clear accountability and governance for machine-driven decisions. |
Review agent tool access, approval boundaries, and execution logging before allowing identity-state changes.
Key terms
- Identity Remediation Automation: Identity remediation automation is the use of workflows or software to detect and correct risky access states with limited manual handling. In identity programmes, it only works when every state change is auditable, reversible, and tied to a clear owner for approval and exception handling.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.
- Delegated Credential: A token, key, or other secret that allows one system to act on behalf of another identity. For agentic environments, delegated credentials matter because they extend trust into runtime, where the agent can use them to reach tools, data, or services without a fresh human approval.
What's in the full article
Veza's full article covers the operational detail this post intentionally leaves for the source:
- Implementation context for identity remediation automation with ServiceNow.
- Product-specific details on AI agent security for Amazon Bedrock AgentCore and ServiceNow AI Agents.
- Workflow and platform changes tied to Veza AI agent security and shadow AI discovery.
- Release-by-release product update detail that helps teams assess deployment impact.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org