TL;DR: Teleport says AI agents are moving into production infrastructure with autonomous access to data, code, deployments, and databases, while a survey of over 200 decision-makers found 69% believe identity management must change significantly for AI adoption. Static credentials and long-lived secrets no longer match agent behaviour, and identity now determines whether AI scales safely or expands blast radius.
Editorial analysis by NHI Mgmt Group, based on content published by Teleport: “AI Infrastructure Needs an Agentic Identity Framework — We’re Building It”.
By the numbers:
- 69% said widespread AI adoption will need significant changes to how identity is managed.
- Only 2% disagreed with the view that AI adoption will require major identity changes.
- Teleport surveyed over 200 infrastructure and security decision-makers.
Key questions
Q: What breaks when AI agents rely on static secrets?
A: Static secrets break the trust model because they are reusable, portable, and often broader than the task requires.
Q: Why do autonomous agents create more risk than traditional application accounts?
A: Autonomous agents create more risk because they can change scope while they are running.
Q: How do security teams know whether AI agent ownership verification is working?
A: It is working when every active agent has a current, auditable owner response and ownership gaps are shrinking rather than being deferred.
Practitioner guidance
- Adopt short-lived agent credentials Replace reusable API keys and long-lived secrets with ephemeral credentials tied to a specific task or session.
- Classify every agent as a first-class digital actor Inventory agents alongside human users, service accounts, and workloads so discovery, ownership, and offboarding are governed in one place.
- Bind authorisation to cryptographic identity Require proof of identity that can be verified at runtime and traced back to a governed issuance event.
Bottom line: AI agents are already colliding with identity models that were built for humans and stable service accounts, not autonomous production actors.
What's in the full article
Teleport's full article covers the operational detail this post intentionally leaves for the source:
- The agentic identity framework’s reference architecture for humans, machines, workloads, and AI agents
- The vendor’s standards-driven design goals for discovery, audit logging, and centralised control of MCP endpoints
- The practical framing for reducing shared secrets, impersonation, and standing privilege in production deployments
- The article’s explanation of how the framework is intended to evolve as agentic systems mature
👉 Read Teleport's analysis of AI agent identity frameworks and cryptographic trust →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Static credential governance was designed for stable actors, not autonomous ones: passwords, API keys, and long-lived secrets assume the identity holder is predictable enough for periodic review and manual containment. That assumption fails when the actor is an AI agent because the access path can change during execution and the credential can outlive the task. The implication is that identity governance must move from reviewing holdings to governing issuance.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What should organisations do when agent identity is not yet fully governed?
A: They should limit agent access to the smallest set of systems needed for a defined task and remove shared or reusable credentials from the design. They should also make ownership and offboarding explicit so no agent remains active without a current business purpose or accountable operator.
👉 Read our full editorial: AI agent identity frameworks need cryptographic trust, not static secrets