Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI agent runtime control gaps: what identity teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20538
Topic starter  

TL;DR: Identity standards can define how AI agents receive and carry credentials, but they still stop short of governing what those agents do after authentication, according to Cakewalk’s analysis of the Agent Control Standard. That gap leaves runtime decisions, last-mile enforcement, and fail-open behaviour as the real security boundary for agent governance.

NHIMG editorial — based on content published by Cakewalk: Identity Standards Stop at the Moment an AI Agent Acts Johannes Keienburg, CEO & Founder Published September 9, 2026

Questions worth separating out

Q: What breaks when AI agents inherit human IAM controls?

A: Human IAM controls break because they assume a person makes a request, waits, and can later be reviewed or deprovisioned.

Q: When does runtime authorization reduce risk more than stronger authentication?

A: Runtime authorization reduces risk most when the main exposure is what an identity can do after it has already logged in.

Q: What signals show that group governance is failing?

A: Look for large or frequently changing privileged groups, inconsistent ownership records, orphaned memberships, and review findings that repeat from cycle to cycle.

Practitioner guidance

  • Define runtime control as a separate governance requirement Map where your current IAM and NHI controls end at credential issuance and where agent runtime decisions begin.
  • Review every fail-open decision in agent workflows Identify timeouts, unreachable policy services, and default-allow logic in last-mile enforcement paths.
  • Strip persistent privilege from agent identities Replace inherited long-lived scopes with narrow task-scoped access and short-lived authorisation boundaries.

What's in the full article

Cakewalk's full article covers the operational detail this post intentionally leaves for the source:

  • The article breaks down the five identity gaps named by the Agent Control Standard, including chain integrity, over-privilege, token theft resistance, last-mile enforcement, and proof of intent.
  • It explains the fail-open design choice in the proposed runtime check and why that default matters when the control service is slow or unreachable.
  • It references the ACS identity working group documents and the specification section that describes how the enforcement step is meant to behave.
  • It shows how inherited human-oriented scopes create over-privilege when attached to agents rather than ordinary applications.

👉 Read Cakewalk's analysis of identity standards and AI agent runtime control →

AI agent runtime control gaps: what identity teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20129
 

Runtime identity governance is now a separate control plane from credential issuance. The article correctly identifies a structural gap: identity standards can explain how an agent gets a credential, but not what the agent may do once the credential is live. That is why runtime governance has to be treated as its own discipline alongside IAM and NHI. Practitioners should stop assuming that authentication completion equals control completion.

A few things that frame the scale:

  • 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to the AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to the same report.

A question worth separating out:

Q: How should organisations balance availability and enforcement for AI agents?

A: Organisations should decide whether the business can accept a failed control path before the agent is deployed. If enforcement must never be skipped, then the default should block the action rather than allow it. The trade-off is operational resilience versus security certainty, and it should be governed explicitly, not discovered during an incident.

👉 Read our full editorial: Identity standards stop when AI agents act at runtime



   
ReplyQuote
Share: