Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agent discovery gaps: what IAM teams are missing in week one


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: The number of AI agents discovered in customer environments typically lands two to five times higher than what organisations believe is present, with one hospitality deployment showing a more than fivefold gap and twelve high-risk agents uncovered in the first scan, according to Onyx. Inventory accuracy, attribution, and continuous visibility are now governance prerequisites, not optional audit work.

NHIMG editorial — based on content published by Onyx: Thousands of Agents: What Onyx Discovers in 24 Hours

Questions worth separating out

Q: How should security teams handle AI agent discovery when approved inventories are incomplete?

A: Security teams should treat approved inventories as a starting point and query the environment directly.

Q: Why do AI agents create more governance risk than ordinary integrations?

A: AI agents can connect quickly, run continuously, and accumulate broad permissions across multiple services.

Q: What do organisations get wrong about agent identity attribution?

A: They often treat the human prompt as the identity, when the agent itself is the actor making tool selections and execution decisions.

Practitioner guidance

  • Establish a live AI agent inventory Query the environment directly, reconcile embedded and user-activated agents, and maintain ownership for every discovered agent in a central register.
  • Separate agent identity from human identity Tag agent actions with a distinct executor identity, preserve the human setup context separately, and ensure logs can show which credential was used, which system was reached, and who owns the agent lifecycle.
  • Review embedded AI features as new identities Treat product updates that add agentic capability as identity events, not feature toggles.

What's in the full article

Onyx's full article covers the operational detail this post intentionally leaves for the source:

  • The step-by-step week-one onboarding workflow used to surface hidden AI agents in customer environments
  • The specific patterns that caused approved inventories to diverge from the actual agent population
  • The 90-day operational model for keeping discovery, ownership, and remediation current
  • The practical examples of high-risk agents found during initial scans and how they were triaged

👉 Read Onyx's analysis of AI agent discovery gaps and onboarding findings →

AI agent discovery gaps: what IAM teams are missing in week one?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

AI agent inventory debt is now a governance failure mode, not a discovery nuisance. The article shows that the gap between believed and actual agent populations can reach five times, which means central inventories are structurally incomplete once agentic features are distributed through SaaS, engineering, and embedded product updates. This is not a tooling inconvenience. It is the point at which IAM, IGA, and security ownership stop describing the real environment. Practitioners should treat inventory debt as a standing control gap, not a project delay.

A few things that frame the scale:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • The same research found that lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, with inadequate monitoring and logging and over-privileged accounts each cited by 37%.

A question worth separating out:

Q: Who should own remediation when AI finds a multi-step exploit chain?

A: The owning team should be the one responsible for the full chain, not just the first broken component. In practice that usually means AppSec, IAM, infrastructure, and service owners must triage together so a bypass, a privilege gap, and a data exposure path are fixed as one control failure.

👉 Read our full editorial: AI agent inventory gaps are breaking enterprise governance models



   
ReplyQuote
Share: