TL;DR: AI agents are moving into critical workflows with decision-making and API chaining, but static provisioning, long-lived credentials, and human-era governance models do not scale to their velocity or delegation patterns, according to Strata Identity. The core issue is that identity systems assume stable, reviewable access, while agents appear, act, and retire faster than those controls can track.
Editorial analysis by NHI Mgmt Group, based on content published by Strata Identity: “Why Enterprises Need Just-in-Time Provisioning to Secure AI at Scale”.
Key questions
Q: What breaks when AI agents inherit human IAM controls?
A: Human IAM controls break because they assume a person makes a request, waits, and can later be reviewed or deprovisioned.
Q: Why do long-lived secrets create more risk for workloads and agentic AI systems?
A: Long-lived secrets increase blast radius because any exposed key can be reused until it is rotated or revoked.
Q: How should security teams handle delegated access when AI agents act on behalf of customers?
A: Security teams should treat delegated access as a separate governance layer, not as a normal login session.
Practitioner guidance
- Implement runtime identity issuance for agent tasks Issue identities only when a specific task begins, bind them to the task scope, and retire them as soon as the workflow ends so access does not outlive the work.
Bottom line: AI agents challenge identity governance because they act too quickly and too transiently for human-era provisioning and review cycles to govern effectively.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Access review assumes privilege lasts long enough to be reviewed, and that assumption fails for AI agents. Human-era governance expects identities to persist across a review window, but agentic systems may acquire, use, and discard access inside one task. That means the core control premise is broken before the review even starts. Practitioners need to recognise that this is not a faster version of human IAM; it is a different timing model altogether.
A few things that frame the scale:
- A May 2025 Gartner poll of 147 CIOs and IT leaders found that 24% had already deployed AI agents, 50% were experimenting and 17% planned to deploy by the end of 2026.
A question worth separating out:
Q: When should organisations replace static agent accounts with just-in-time provisioning?
A: They should do it when agents are task-scoped, short-lived, or capable of chaining multiple actions across systems. In those conditions, persistent accounts become a governance liability because the control model cannot reliably match privilege duration to actual execution time.
👉 Read our full editorial: Why just-in-time identity breaks human-era controls for AI agents