TL;DR: RSA 2026 Day 1 sessions, as covered by AppSOC, argue that agentic AI is compressing detection and attack timelines beyond human-scale response, while enterprises still rely on visibility, review, and governance models built for slower systems. The core implication is that identity and security programmes must shift from static oversight to context-aware, continuously enforced control.
NHIMG editorial — based on content published by AppSOC: RSAC 2026 Day 1, Security Must Evolve at Agentic Speed
By the numbers:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems.
Questions worth separating out
Q: How should security teams govern AI agents that can change actions at runtime?
A: Security teams should govern runtime AI by correlating identity, data, and intent before trusting an action path.
Q: Why do traditional security controls fail for agentic AI workflows?
A: Traditional controls fail because they are usually applied before or after execution, while agentic AI can retrieve data, invoke tools, and act during the session.
Q: What breaks when non-human identities are authorized without oversight?
A: When non-human identities are left on standing privileges, access outlives the task, the owner, and sometimes the vendor relationship.
Practitioner guidance
- Shorten the decision window for machine identities Rebuild detection and response expectations around minutes, not hours or days, for credentials and agents that can act at machine speed.
- Inventory where AI systems inherit real access Map every agent, API key, and service account to the data sources, tools, and downstream systems it can touch.
- Replace review-only governance with runtime guardrails Use just-in-time access, scoped delegation, and continuous policy enforcement where AI systems or NHIs can execute sensitive actions.
What's in the full article
AppSOC's full post covers the operational detail this post intentionally leaves for the source:
- How the RSA 2026 sessions were framed and which speakers made each point.
- The specific context-aware security and MCP Security Gateway claims made by the vendor.
- The article's broader commentary on AI-native defense, monitoring, and policy enforcement.
- Examples of the AI system interactions and risk relationships the vendor says its platform correlates.
👉 Read AppSOC's RSA 2026 analysis of agentic AI security and context-aware defence →
Agentic AI risk at RSA 2026: are security controls keeping up?
Explore further
Agentic AI exposes a governance gap that static IAM cannot close. Human-paced access review, approval, and recertification cycles assume access remains visible long enough to govern. That assumption fails when an actor can choose actions and execute them at runtime without waiting for human approval. The implication is that identity governance must be redesigned around runtime observability and control boundaries, not periodic review alone.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How can organisations tell whether AI governance is actually working?
A: Organisations can tell AI governance is working when they can inventory every agent, explain its purpose, show who owns it, and prove that permissions are tightly scoped. If those four things are missing, the programme has policy language but not operational control. Auditors will notice the gap quickly.
👉 Read our full editorial: AI-driven threats expose the limits of human-speed security