Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic AI in finance: why legacy IAM is hitting a wall


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: 62% of financial firms say legacy IAM is not ready for agentic AI, according to Ory, while NHIs now outnumber humans 144:1 and 92.1% of enterprises have already seen negative operational impacts from rushed AI rollouts. The governance gap is structural: human-centric IAM models cannot safely absorb machine-speed identity sprawl and over-privileged automation.

NHIMG editorial — based on content published by Ory: Rushing Into Agentic AI: The Legacy IAM Bottleneck in Finance

By the numbers:

Questions worth separating out

Q: What breaks when AI identities are handled outside IAM?

A: When AI identities sit outside IAM, organisations lose a consistent record of who has access, why access exists, and who approved it.

Q: Why do NHIs complicate traditional IAM governance?

A: NHIs are created in many places, often outside central identity workflows, and they frequently outnumber human identities by a wide margin.

Q: How do security teams know if an AI agent has too much access?

A: Look for agents that can reach multiple systems without task-specific limits, use persistent tokens, or touch high-value services such as email, chat, cloud consoles, and file stores.

Practitioner guidance

  • Inventory all machine identities separately from human users Build a distinct register for service accounts, API keys, tokens, certificates, and AI agent credentials.
  • Measure identity blast radius before expanding AI access Test what a single automated identity can reach across data, infrastructure, and admin functions.
  • Replace static credentials with shorter-lived machine access Reduce reliance on long-lived secrets in AI and automation workflows, especially where those credentials can be reused across tools or environments.

What's in the full article

Ory's full article covers the operational detail this post intentionally leaves for the source:

  • EMA survey breakdowns by financial services segment, including readiness scores for resiliency, compliance, and security
  • The operational case for consolidating fragmented IAM systems rather than layering another platform on top
  • The article's practical five-question framework for securing machine automation execution threads
  • Survey context and commentary from Ory's team on why finance is feeling the pressure first

👉 Read Ory's analysis of legacy IAM readiness for agentic AI in finance →

Agentic AI in finance: why legacy IAM is hitting a wall?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Legacy IAM assumes access is stable long enough to be reviewed, and that assumption is breaking under agentic AI. Access review, certification, and recertification processes were designed for principals whose privileges persist across predictable governance cycles. When the actor is an autonomous or semi-autonomous machine identity, the access window can be shorter than the review window, which means the programme is measuring a state that no longer exists. The implication is that IAM teams must rethink the governance model itself, not just add more review tooling.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations treat agentic AI access differently from service account access?

A: Yes. Service accounts are usually persistent and can be managed through lifecycle controls, while agentic AI access is often ephemeral, runtime-selected, and initiated on demand. The right governance model is different because the identity behaviour is different. Treating both as the same class leads to control gaps and delayed policy decisions.

👉 Read our full editorial: Legacy IAM is not ready for agentic AI in financial services



   
ReplyQuote
Share: