TL;DR: Only 10% of organisations have a well-developed strategy for managing non-human and agentic identities, according to Aembit and an Okta survey of 260 executives, while credential abuse remains the most common initial access vector in breaches, per the 2025 Verizon DBIR. Agentic systems break the assumption that identity only authenticates access, because they can plan, invoke tools and act across infrastructure in ways IAM was not built to certify in real time.
Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “6 Cybersecurity Risks of Agentic AI (and How to Address Them)”.
By the numbers:
- Only 10% of organisations have a well-developed strategy for managing non-human and agentic identities, according to Aembit and an Okta survey of 260 executives.
- Credential abuse remains the most common initial access vector in breaches, according to Aembit and the 2025 Verizon DBIR.
- The survey cited by Aembit drew on 260 executives.
Key questions
Q: What breaks when agentic AI is allowed to act with embedded credentials?
A: The control problem changes from isolated secret protection to governed runtime access.
Q: Why do agentic systems increase the risk of credential abuse?
A: They increase the risk because a stolen or shared credential can unlock a system that plans, calls tools and persists across steps rather than a single stateless request.
Q: How do security teams know whether managed identities are working for agents?
A: Managed identities are working when there are no embedded secrets in code or config, each agent has a distinct identity, and privileges map cleanly to a small number of functions.
Practitioner guidance
- Define agent identity as a first-class subject Assign each agent its own identity, policy boundary and audit trail so that access decisions are not inherited from the human it represents.
- Replace borrowed credentials with task-scoped access Use short-lived, cryptographically bound credentials for each task so that agent sessions do not retain reusable secrets across steps.
- Map every tool connection to a delegated trust path Inventory which databases, APIs, services and other agents each system can reach, then classify how far a single permitted action can compound.
Bottom line: Agentic AI shifts identity risk from authenticating users to governing actors that can plan, invoke tools and persist across steps.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity review cadences assume access persists long enough to be reviewed, but agentic systems can acquire, combine and release privileges within the same task. That is an assumption collapse, not just a control gap. The identity programme is being asked to certify a state that may no longer exist by the time the review cycle reaches it, which means the governance model itself needs rethinking.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- The 2026 Verizon DBIR found that exploitation of software vulnerabilities became the leading initial access vector in confirmed breaches, accounting for 31% of incidents.
A question worth separating out:
Q: When should organisations treat an AI agent as a privileged system?
A: Organisations should treat an AI agent as privileged whenever it can reach production data, administrative tools, or sensitive workflows without direct human approval for each step. At that point, the agent is no longer a passive automation helper. It becomes a governed identity whose permissions, logs, and exceptions need the same scrutiny as other high-risk access.
👉 Read our full editorial: Agentic AI identity risk is outpacing enterprise IAM controls