Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI agent identity risk is outpacing existing IAM controls


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: AI agents now operate with broad, long-lived access across code, data, and business systems, and Cakewalk argues that traditional IAM, NHI management, and observability do not provide action-time authorization. The core gap is that agent behaviour is emergent at runtime, so access decided at setup time leaves governance blind when it matters most.

NHIMG editorial — based on content published by Cakewalk: The New Frontier in Identity Security: AI Agent Access

By the numbers:

Questions worth separating out

Q: What breaks when AI agents are governed with human IAM, IGA, and PAM models?

A: Human identity models assume a known person, a start date, a manager, and predictable access review cycles.

Q: Why do NHIs complicate zero trust and least privilege efforts?

A: NHIs complicate zero trust because they are numerous, persistent, and often tightly integrated into applications and pipelines.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.

Practitioner guidance

  • Inventory every agent and delegated credential path Map which agents use human OAuth grants, service accounts, API keys, or token inheritance, then document the systems each one can reach and the approval chain behind it.
  • Move critical decisions to action time Require a policy check before each tool call, database query, or external request when an agent touches sensitive systems, rather than relying on setup-time approval.
  • Separate observability from enforcement Keep logs and traces for forensics, but place an independent control point between the agent’s decision and execution so monitoring does not become the only safeguard.

What's in the full article

Cakewalk's full article covers the operational detail this post intentionally leaves for the source:

  • A runtime walk-through of how agents discover tools, choose actions, and execute across systems without fixed workflows.
  • The article's full discussion of why borrowed human OAuth credentials create governance gaps for delegated agent access.
  • Specific examples of where setup-time permissions fail when an agent encounters a database, API, or deployment pipeline at runtime.
  • Cakewalk's closing recommendations on where security, compliance, and engineering teams should begin reworking access decisions.

👉 Read Cakewalk's analysis of AI agent access and identity security →

AI agent identity risk is outpacing existing IAM controls?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

AI agent access is an IAM problem only if organisations treat agents as humans with faster hands. That assumption is already failing. Agents do not just authenticate and execute a fixed role; they discover tools, decide paths, and expand their own operational surface at runtime. The implication is that identity programmes must stop modelling agent access as a static entitlement problem and start treating it as runtime authorisation.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials, according to AI Agents: The New Attack Surface report.
  • 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who is accountable when an AI agent uses delegated access incorrectly?

A: Accountability should follow the delegated authority chain, not stop at the agent label. The relevant owners are the teams responsible for the human identity, the service identity, the workflow, and the policy that allowed the action path. If those responsibilities are not explicit, incident review will be incomplete and remediation will focus on the wrong layer.

👉 Read our full editorial: AI agent access is breaking traditional identity security models



   
ReplyQuote
Share: