TL;DR: AI agents are moving faster than workforce IAM can govern: long-lived credentials, session-only authorization and weak delegation tracking leave organisations exposed, according to Aembit’s analysis. The governing assumption is breaking, because many identity controls still assume access is stable long enough to be reviewed, certified or revoked after the fact.
Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “Why Traditional IAM Is No Match for Agentic AI”.
By the numbers:
- The non-human-to-human identity ratio can reach 144:1, and the article cites that figure as a 44% year-over-year increase.
Key questions
Q: What breaks when AI agents are treated like standard human users?
A: You lose visibility into effective permissions, expected behaviour, and real blast radius.
Q: Why do short-lived credentials matter more for agentic AI than for ordinary apps?
A: Agentic systems can request, use, and discard access inside a narrow runtime window, so long-lived credentials create unnecessary exposure between actions.
Q: How do you know if agent delegation is becoming ungoverned?
A: The warning signs are missing hop-by-hop attribution, shared service accounts across multiple agents and logs that show actions without the initiating user or top-level agent.
Practitioner guidance
- Map agent access paths first Inventory the production databases, APIs, CI/CD systems and SaaS tools that AI agents can already reach, then identify where standing credentials or shared service accounts are still in use.
- Issue short-lived credentials per interaction Replace reusable API keys and persistent tokens with short-lived, task-scoped credentials so each agent action has a narrow exposure window and a clear expiry boundary.
- Track delegation lineage in logs Record the initiating user, the top-level agent, any subagents, the resource touched and the permission scope at each handoff so incident response can reconstruct the chain of authority.
Bottom line: AI agents expose a structural mismatch in legacy IAM because human-centred controls do not govern machine-speed delegation and short-lived execution cleanly.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI agent identity governance is a separate discipline from workforce IAM. Workforce IAM assumes human-paced logins, stable role assignment and review after the fact. AI agents break that model because their access is task-scoped, transient and often delegated across multiple systems. The implication is that identity governance for agents cannot be treated as a variant of employee IAM.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.
A question worth separating out:
Q: Should organisations prioritise runtime authorization over traditional access reviews for agents?
A: Yes, when the actor can request, use and release access faster than a review cycle can observe it. Traditional access reviews still matter for governance, but they cannot be the primary control for autonomous execution that changes state within a single task.
👉 Read our full editorial: AI agent identity governance is outpacing legacy IAM controls