TL;DR: AI agents are already operating beyond human-speed access patterns, and 73% of CISOs say they are critically concerned while only 30% report mature safeguards, according to Aembit. Legacy IAM assumptions around static sessions, long-lived secrets, and predictable users do not hold once agents authenticate to APIs, databases, and MCP servers at runtime.
Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “What Is IAM for Agentic AI? The New Perimeter of Trust in 2026”.
By the numbers:
- 73% of CISOs are critically concerned about AI agent security risks.
- only 30% have mature safeguards in place
Key questions
Q: What breaks when AI agents are treated like standard human users?
A: You lose visibility into effective permissions, expected behaviour, and real blast radius.
Q: Why do static credentials create more risk for AI agents than for traditional workloads?
A: AI agents execute quickly, can chain actions across systems and may terminate before manual review ever happens.
Q: How do security teams know if agent authorization is actually working?
A: Authorization is working only if the agent can complete the intended task without gaining unnecessary reach.
Practitioner guidance
- Define agents as managed workloads Assign each agent, orchestrator and tool connector a distinct identity and ownership record so access can be tied to a specific runtime subject rather than a broad application bucket.
- Replace static secrets with runtime proof Use cryptographic attestation and short-lived credentials for agent access, and remove reusable API keys from agent configuration wherever possible.
- Policy-gate every agent request Evaluate identity, environment posture and request context at access time so approvals reflect the task being attempted rather than a pre-set role.
Bottom line: AI agent identity security exposes a structural mismatch between legacy IAM and autonomous software that can request, combine and use access at runtime.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Legacy IAM is built on a human-session assumption that does not survive autonomous execution. The model assumes identity is established once, then trusted for the duration of a session. AI agents continuously acquire new access paths while they work, so the original trust decision becomes stale almost immediately. The implication is not simply more automation, but a different identity premise: runtime identity proof must replace login-time trust.
A few things that frame the scale:
- Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.
A question worth separating out:
Q: What should teams do when autonomous agents need access to multiple systems?
A: Design for runtime authorisation rather than broad pre-provisioning. Each system should evaluate the agent’s identity and context before granting access, and the resulting permission should be narrow enough to fit one task, not an entire workflow. If teams widen scopes to avoid failure, they are trading usability for uncontrolled blast radius.
👉 Read our full editorial: AI agent identity security breaks legacy IAM assumptions