Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic AI approvals: are your controls keeping up with machine speed?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: AI agents are moving from advisory tools to digital workers that can execute workflows, but traditional identity models still assume a human-authenticated request path and cannot prove who authorized high-risk actions, according to Yubico. The real control gap is not automation itself, but the lack of cryptographically verified human approval for consequential agent activity.

NHIMG editorial — based on content published by Yubico: human-in-the-loop authorization for AI agents and high-risk actions

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can change actions at runtime?

A: Security teams should govern runtime AI by correlating identity, data, and intent before trusting an action path.

Q: Why do AI agents create a governance problem for IAM teams?

A: AI agents create a governance problem because they authenticate and act as autonomous software entities with tool access.

Q: What breaks when AI actions are not bound to a human approver?

A: Without a verifiable human approval step, high-consequence AI actions become difficult to attribute, contest, or reconstruct after the fact.

Practitioner guidance

  • Define approval thresholds for agent actions Classify which actions can remain autonomous and which must stop for cryptographically verified human approval, starting with transfers, production changes, and sensitive document access.
  • Separate proposal and approval identities Ensure the AI agent that proposes an action is not the same identity path that authorizes it, and keep the approval channel out-of-band from the original workflow.
  • Bind approvals to specific action payloads Record the exact transfer, deployment, or disclosure request that was approved so the decision can be tied to a specific verified identity and later audited for non-repudiation.

What's in the full article

Yubico's full article covers the operational detail this post intentionally leaves for the source:

  • The policy-driven consent flow used to decide when an AI agent can proceed automatically versus when it must escalate.
  • How CIBA-based backchannel approval works in practice for high-risk decisions that need out-of-band verification.
  • The hardware-backed tap process that creates proof of presence and supports non-repudiation for the approving human.
  • The partner workflow details linking AI orchestration, identity orchestration, and human approval across the full chain.

👉 Read Yubico's analysis of human-in-the-loop authorization for AI agents →

Agentic AI approvals: are your controls keeping up with machine speed?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Human-in-the-loop authorization is becoming a structural control, not a workflow preference. When AI agents can initiate real actions, the question is no longer whether a human should be informed, but which actions must be stopped until a verified person approves them. That changes IAM and PAM design because the control boundary moves from post-event review to pre-action consent. Practitioners should treat this as a governance layer for consequential actions, not a convenience feature.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, according to AI Agents: The New Attack Surface report.
  • Another finding from the same research shows that only 52% of companies can track and audit the data their AI agents access, leaving 48% with a compliance and investigation blind spot.

A question worth separating out:

Q: Who is accountable when an AI agent makes a risky decision?

A: Accountability should rest with the organisation that authorised the agent, the human owner of the workflow, and the control process that allowed the behaviour. If an agent can act independently, the programme must preserve attribution, action logs, and policy decisions so audit and remediation are possible after the event.

👉 Read our full editorial: Human-in-the-loop authorization is the control gap in agentic AI



   
ReplyQuote
Share: