TL;DR: Agentic AI tools now plan, act, and adapt across enterprise systems without constant prompting, but that autonomy expands the identity problem beyond static automation, according to Lasso Security. Existing IAM, audit, and approval models were built for access that stays reviewable, not for actors that can change scope mid-session.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “Top 13 Agentic AI Tools in 2026 and Their Key Features”.
Key questions
Q: What breaks when access reviews are the main control for AI agents and NHIs?
A: Access reviews break when privilege changes faster than the review cycle can observe, certify and remediate it.
Q: Why does agentic AI increase access risk in enterprise identity programs?
A: Agentic AI increases risk because one agent may move across multiple services to complete a single task.
Q: What are the signs that AI access is outgrowing existing IAM controls?
A: Look for broad local permissions, connectors that are not registered, auto-approve modes used in production, and prompt-based tasks that touch sensitive repositories or cloud environments without task-scoped limits.
Practitioner guidance
- Define agent authority boundaries Document which actions an autonomous agent may initiate, which tools it may call, and which business systems remain out of scope for each task type.
- Replace broad delegated access with task-scoped access Issue the minimum tool, API, and workspace permissions needed for one execution path, then remove them as soon as the task closes.
- Inventory memory-enabled workflows Map where persistent memory changes future behaviour, because retained context can turn a narrow approval into broader downstream action.
Bottom line: Agentic AI tools change the identity problem because the actor can plan and act across systems without human prompts.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI tools create a runtime identity problem, not just a workflow problem. Once an actor can choose tools, sequence actions, and continue without approval, static provisioning no longer describes the real control boundary. The industry still talks as if these systems are extensions of automation, but their behaviour makes them non-human identities with decision authority. Practitioners should treat that as a different governance class, not a richer macro.
A few things that frame the scale:
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.
- Our research also found that 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
A question worth separating out:
Q: How do teams measure whether agent governance is actually working?
A: Look for evidence that every agent action can be traced to an approved purpose, a constrained tool path, and a named owner. If auditors cannot reconstruct the decision chain from logs and policy records, governance is incomplete. Effective control shows up as narrow reach, clear attribution, and fast containment when behaviour drifts.
👉 Read our full editorial: Agentic AI tools are outpacing enterprise identity controls
Access review was designed for access that remains stable long enough to be reviewed. That assumption fails when an autonomous actor can obtain, use, and drop privilege inside one session. The implication is not just tighter review, but a redesign of governance around runtime authorisation boundaries.
A few things that frame the scale:
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations treat agentic AI as an IAM or a model governance problem?
A: They should treat it as both, but IAM is the first-order constraint because an agent cannot be safely governed if its privileges are already excessive. Model governance matters, yet the most immediate risk comes from who or what can act, change, and persist in production systems.
👉 Read our full editorial: Agentic AI tools are outpacing enterprise identity controls