Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic AI security frameworks: what IAM teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Agentic AI agents can plan, call tools, remember context, and act across systems without human approval, which makes legacy application security and human-centric IAM assumptions inadequate, according to Akto. The governance problem is not just control coverage, but the collapse of the assumption that authorisation is stable long enough to be reviewed and certified.

NHIMG editorial — based on content published by Akto: Agentic AI Security Framework: A Stepwise, Technical Guide for 2026

By the numbers:

Questions worth separating out

Q: How should security teams implement zero trust for workloads and AI agents?

A: Start by giving each workload or agent a verifiable runtime identity, then enforce request-level policy and issue short-lived credentials only after the identity and context checks pass.

Q: Why do AI agents create more risk than traditional automation?

A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.

Q: What do security teams get wrong about agent inventory and ownership?

A: They often assume that once an agent is found, a single inventory record is enough.

Practitioner guidance

  • Inventory every agent and MCP-connected workflow Build a complete register of in-house agents, embedded assistants, and external connectors, then reconcile it against production data sources and APIs.
  • Replace standing agent permissions with task-scoped access Remove persistent API keys and broad shared accounts where an agent can reach tools or data directly.
  • Test multi-step behaviour, not single prompts Run red-team scenarios that simulate prompt injection, tool poisoning, and chained actions across several steps.

What's in the full article

Akto's full blog covers the operational detail this post intentionally leaves for the source:

  • The full step-by-step framework for discovery, posture management, red teaming, runtime protection, and incident response.
  • Specific examples of prompt injection, tool poisoning, shadow agents, and agent spoofing in multi-step workflows.
  • The article’s compliance crosswalks to NIST AI RMF, ISO 42001, SOC 2, and the EU AI Act.
  • Operational notes on using automated guardrails and runtime containment across 80+ connectors and 1,000+ probes.

👉 Read Akto's guide to agentic AI security frameworks and runtime controls →

Agentic AI security frameworks: what IAM teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 13137
 

Agentic AI exposes an assumption collapse, not just a control gap. Traditional IAM assumes a subject’s authorisation is stable long enough to be provisioned, reviewed, and certified. That assumption fails when an agent can alter its action sequence, select tools dynamically, and chain decisions at runtime. The implication is that governance must stop treating agent access as a static entitlement problem and start treating it as a time-bound behavioural problem.

A few things that frame the scale:

  • Non-human identities already outnumber humans by a factor of approximately 50:1 in the average enterprise, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows why discovery and inventory remain unfinished business.

A question worth separating out:

Q: How do security teams know runtime AI guardrails are actually working?

A: Look for blocked poisoned inputs, flagged anomalous outputs, and traceable enforcement before responses reach users or downstream systems. If controls only inspect prompts or only inspect outputs, they leave a gap that attackers can exploit through manipulated data sources or tool responses.

👉 Read our full editorial: Agentic AI security frameworks expose the limits of legacy IAM



   
ReplyQuote
Share: