TL;DR: AI agents are inheriting broad, long-lived access faster than legacy IAM can govern, creating orphaned identities, privilege creep, static credentials, and weak traceability, according to Akto. The core issue is that human-era access review and lifecycle models break when machine identities operate at machine speed and scale.
NHIMG editorial — based on content published by Akto: Securing Agent Identities, 8 Risks Every CISO Must Address
Questions worth separating out
Q: How should security teams govern AI agents that inherit authority from other identities?
A: Security teams should govern AI agents by tracking identity lineage, not just credentials.
Q: Why do AI agents increase non-human identity risk?
A: AI agents increase non-human identity risk because they can execute many actions quickly once they inherit a credential or tool permission.
Q: What breaks when AI agents are given broad inherited permissions?
A: Broad inherited permissions break the assumption that access is tied to a narrow business need.
Practitioner guidance
- Assign accountable owners to every agent identity Create a named owner for each agent at creation, with responsibility for approvals, review, and retirement.
- Replace standing agent credentials with short-lived trust Move agents off long-lived API keys and hardcoded secrets where possible, and use short-lived tokens or certificates with tight scope.
- Right-size permissions to the task, not the platform Review every agent entitlement against the specific workflow it supports.
What's in the full article
Akto's full blog covers the operational detail this post intentionally leaves for the source:
- The article's full eight-risk breakdown for agent identities and the specific examples behind each control gap.
- The maturity-model framing for moving from basic discovery to stronger governance across agent identities and secrets.
- The operational sequencing Akto recommends for inventory, ownership, privilege reduction, and logging.
- The product-context detail on how the vendor positions agent identity security in its own platform.
👉 Read Akto's analysis of eight AI agent identity risks and governance gaps →
Agent identity risks: what IAM teams need to fix first?
Explore further
Agent identity governance is now a lifecycle problem, not a tooling problem. The article shows that AI agents fail when they inherit access faster than teams can assign ownership, review entitlements, and retire unused identities. That is the same lifecycle discipline IAM has used for humans, but the execution interval is shorter and the inventory is less visible. Practitioners should treat agent identity as a governed population, not a feature flag.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: When should organisations re-evaluate identity controls for AI agents and non-human identities?
A: They should re-evaluate them as soon as delegated access, autonomous decision-making, or machine-to-machine trust enters production. At that point, human-centred review cycles are no longer enough, because access can be used in ways that are not tied to a predictable person or session.
👉 Read our full editorial: Agent identity risks are outpacing legacy IAM controls