Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic AI and IAM: where do current identity controls fail?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15509
Topic starter  

TL;DR: Agentic AI combines human-like decision-making with machine speed, exposing a gap in IAM models built for people or deterministic systems, according to Orchid Security. The real issue is not just access volume but the collapse of assumptions about stable privilege, reviewable activity, and delegated authority.

NHIMG editorial — based on content published by Orchid Security: LLMjacking: How Attackers Hijack AI Using Compromised NHIs

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that browse and transact on behalf of users?

A: Security teams should govern AI agents as delegated actors with narrow, task-scoped permissions, not as enhanced browsers.

Q: Why do existing IAM controls struggle with autonomous AI agents?

A: Existing IAM controls were designed around human users and predictable workload behaviour.

Q: What do IAM teams get wrong when they treat AI agents like service accounts?

A: They assume an agent is just another fixed non-human identity, when its behaviour may be runtime-driven and tool-selecting.

Practitioner guidance

  • Define agent identities explicitly Create a distinct identity category for AI agents in your governance model so they are not hidden inside human or service-account inventories.
  • Map delegation chains end to end Track which human, service, or system authorised the agent, what scope was intended, and where the agent can branch at runtime.
  • Replace standing access with runtime boundaries Limit agent access to the shortest viable scope and tie it to the task context, data domain, and execution window.

What's in the full article

Orchid Security's full article covers the operational detail this post intentionally leaves for the source:

  • The vendor’s comparison table showing how human, NHI, and agent identity requirements differ in authentication, behaviour, privilege, and risk.
  • The application-level discovery findings on cleartext credentials, IdP bypasses, and missing baseline controls across enterprise estates.
  • The autonomous analysis workflow used to surface hidden identity flows inside applications without manual onboarding or prior context.
  • The source article’s positioning on continuous observability as the missing layer for agentic identity governance.

👉 Read Orchid Security’s analysis of why agentic AI breaks legacy IAM assumptions →

Agentic AI and IAM: where do current identity controls fail?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15094
 

Agentic AI is an identity class problem before it is a tooling problem. The article is right to frame the issue around the mismatch between human IAM and deterministic NHI controls. A system that can decide, act, and adapt at runtime does not fit neatly into either model, which means the governance layer must start with actor classification, not product selection. Practitioners should stop forcing agents into existing buckets and instead define what behavioural evidence is required before access is granted.

A few things that frame the scale:

  • From our research: 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to the AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who is accountable when an AI agent exceeds its intended scope?

A: Accountability should follow the delegation chain, not stop at the agent label. The human requester, the policy owner, and the team that granted underlying access all matter, because the agent acts within a permission model someone designed. If the chain is unclear, the governance model is already too weak.

👉 Read our full editorial: Agentic AI breaks legacy IAM assumptions across human and machine identities



   
ReplyQuote
Share: