TL;DR: AI agent security conversations at Identiverse 2026 showed a widening gap between discovery and runtime enforcement, with attendees focused on visibility while access decisions, tool use, and approval logic remained unresolved, according to Aembit. The real risk is that teams keep accumulating agents, credentials, and exceptions before they have a governance model that can enforce access at runtime.
Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “Identiverse 2026 Confirmed the AI Agent Identity Gap: Visibility Is Not Enforcement”.
Key questions
Q: What breaks when agentless visibility is missing in AI infrastructure?
A: Without agentless visibility, ephemeral training jobs, GPU clusters, and short-lived inference services can disappear before traditional tools observe them.
Q: Why do AI agents create risk even when they stay within approved permissions?
A: AI agents can be authorised correctly and still produce harmful outcomes because permission is not the same as intent or behavioural appropriateness.
Q: How can security teams tell whether agent access is actually under control?
A: Look for evidence that the team can trace every tool call, secret use, and cross-system action back to a named owner and a valid approval path.
Practitioner guidance
- Define runtime authorization for agents Set policy to decide each agent request at the moment of access, using agent identity, user context, requested action, and target resource as separate inputs.
- Separate agent rights from user rights Do not let an agent inherit the full access scope of the human session it supports.
- Inventory where visibility stops short Review current agent-discovery tools to see whether they only describe connections and logs, or whether they can actually block disallowed access paths.
Bottom line: AI agent security becomes an authorization problem once agents can choose tools and actions at runtime, not just an inventory problem.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Visibility without enforcement is not an identity control. The market can discover AI agents, map connections, and still leave the real decision point untouched. That creates a governance illusion: teams believe they understand the environment while access remains governed only after the fact. For identity programmes, the lesson is that runtime authorization is now the control plane, not a reporting layer.
A few things that frame the scale:
- Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.
A question worth separating out:
Q: Should organisations treat AI agents like human users in IAM?
A: No. Human IAM assumes a person logs in, works within a session, and can be reviewed later as a stable identity holder. Agents can act at machine speed, across multiple systems, and with changing runtime context, so they need identity governance built around execution and delegation rather than human authentication patterns.
👉 Read our full editorial: AI agent security needs enforcement, not just visibility