TL;DR: RSAC 2025 made one point hard to ignore: agentic AI has moved from prototype discussion to operational security concern, with autonomous systems now expected to act inside enterprise environments, according to Lasso Security. Access review, guardrails, and visibility models built for static workflows are already mismatched to runtime decision-making.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “RSAC 2025 Recap: Agentic AI, Global Recognition, and the Cowboys of GenAI Security”.
Key questions
Q: What breaks when AI systems are governed like static applications?
A: Lifecycle drift breaks the model.
Q: Why do agentic AI systems increase initial access and privilege abuse risk?
A: Because they can chain valid access into multiple tool calls without needing a human to approve each step.
Q: How can organisations tell whether AI governance is actually working?
A: Organisations can tell AI governance is working when they can inventory every agent, explain its purpose, show who owns it, and prove that permissions are tightly scoped.
Practitioner guidance
- Map autonomous actions to task-scoped authority Define exactly which actions an agent may take for a given task, then remove any standing privilege that is not required for that task boundary.
- Instrument runtime behaviour for auditability Capture tool calls, trigger events, data access, and decision points so the agent's session can be reviewed as an execution record.
- Separate discovery from delegated execution Inventory shadow AI and then classify whether each system merely uses AI or actually acts with autonomous authority before assigning governance.
Bottom line: Agentic AI changes the identity problem because systems can now act, select tools, and continue execution without waiting for human approval.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Autonomous identity review is a broken assumption, not just a missing control. Access review processes were designed for identities whose privileges remain stable long enough to be observed, certified, and remediated. That assumption fails when an autonomous actor can acquire, combine, and discard access inside a single operational session. The implication is that governance programmes must rethink what counts as an auditable entitlement state, because the old review cadence no longer matches the actor's behaviour.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: How do security teams decide whether an AI agent needs PAM-style controls?
A: Use PAM-style controls when the agent can reach sensitive systems, modify data, trigger administrative actions, or inherit privileges that exceed its task scope. The deciding factor is not whether the system is called an AI agent, but whether its actions can change operational state in ways that need tighter approval and session control.
👉 Read our full editorial: Agentic AI security at RSAC 2025 shows autonomy changed the threat model
Autonomous identity behaviour collapses the assumption that access is stable long enough to be reviewed: that assumption was designed for humans and static service accounts, not actors that decide and act within a single runtime session. Once action and review no longer share the same time horizon, entitlement governance loses its evidentiary basis. The implication is not merely faster review. It is that the review model itself no longer describes the actor accurately.
A few things that frame the scale:
- Only about one-third of approximately 500 organizations surveyed by McKinsey in 2026 report maturity level three or higher across agentic AI governance controls.
A question worth separating out:
Q: What is the difference between AI security controls and NHI controls?
A: NHI controls focus on identities such as service accounts, keys, tokens, and certificates. AI security controls extend that model to systems that can reason, select tools, and sometimes act autonomously. In practice, the strongest programmes use NHI discipline as the baseline and then add governance for runtime decision-making.
👉 Read our full editorial: Agentic AI security at RSAC 2025 shows autonomy changed the threat model