Join our Newsletter — 33% off our NHI Course

Agentic AI security best practices for 2026: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Agentic AI systems plan, decide, and act inside enterprise environments, and a global survey cited by Lasso Security found 97% of security leaders expect a material incident this year while only 6% of budgets are allocated to the risk. Existing IAM and monitoring models struggle because agent behaviour changes at runtime and can chain across tools and data sources.

Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “How to Secure Agentic AI in the Enterprise: Best Practices for 2026”.

By the numbers:

  • 97% of security leaders expect a material AI-agent-driven security incident this year, according to Lasso Security.
  • Only 6% of security budgets are currently allocated to this risk, according to Lasso Security.

Key questions

Q: What breaks when agentic AI is governed like a normal application account?

A: Security controls break down because agentic systems do not behave like fixed-function applications.

Q: Why do overprivileged agent identities create such a large security risk?

A: Because agents can turn ordinary tool access into destructive action at machine speed.

Q: How do security teams know if agentic AI controls are failing?

A: The main signs are session drift, repeated retry loops, unauthorized tool calls, and behaviour that diverges from the documented task sequence.

Practitioner guidance

  • Define task boundaries in policy Specify which tools, data sources, write paths, and escalation conditions each agent is allowed to use, and enforce them outside the prompt layer.
  • Issue dedicated identities per agent role Remove shared credentials across workflows and bind each agent role to a unique service identity with narrow, task-specific access.
  • Convert broad tokens to time-bounded access Replace persistent credentials with short-lived tokens for sensitive operations so access expires with the task instead of persisting across sessions.

Bottom line: Agentic AI introduces a non-human identity problem because agents can plan, choose tools, and execute actions at runtime inside enterprise systems.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 2 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Agentic AI is not just another NHI class. It collapses the assumption that access can be provisioned once and safely reviewed later. Identity controls for service accounts were designed for stable behaviour and predictable request patterns. That assumption fails when the actor can choose tools, reorder actions, and change behaviour mid-session. The implication is that governance has to be rethought around runtime intent, not just entitlement state.

A few things that frame the scale:

  • 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
  • Only 33% of organisations report their AI agents have accessed inappropriate or sensitive data beyond their intended scope, which means scope creep is already operational rather than theoretical.

A question worth separating out:

Q: Who is accountable when an AI agent causes an unauthorised action?

A: Accountability should sit with the system owner and the governance process that granted the agent its access, not with the agent itself. If the workflow has no owner, no approval path, and no recorded scope, responsibility becomes diffuse very quickly. Organisations need named ownership for agent identities before production use.

👉 Read our full editorial: Agentic AI security in 2026: why current controls fall short



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Agentic AI creates an identity problem before it creates an application problem: these systems are non-human identities that can plan, choose tools, and execute actions inside live enterprise environments. That means their risk cannot be reduced to prompt safety or model quality alone. The real governance issue is that they operate as active identities with delegated authority, so IAM, PAM, and workflow governance all become runtime control problems.

A few things that frame the scale:

  • Organisations that describe themselves as confident in their AI deployment actually experience a 72% security incident rate, compared to 33% for those who remain cautious, according to the 2026 Infrastructure Identity Survey.
  • 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: Should organisations prioritise runtime controls or prompt rules for agentic AI governance?

A: Runtime controls should take priority because prompt rules are advisory, not enforced policy. Prompt text can be manipulated, but infrastructure and authorisation layers can bound tools, data, and execution conditions. Organisations should treat prompts as guidance and runtime policy as the governing control.

👉 Read our full editorial: Agentic AI security in 2026: why current controls fall short


This post was modified 2 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.