Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI agents in identity security: what the latest survey means for teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: 89% of security leaders plan to use AI agents within two years, even though 83% are concerned about the risks and 96% expect deployments to extend beyond non-critical tasks, according to C1.ai’s 2025 Future of Identity Security report. The signal is clear: identity programmes are moving into agentic workflows faster than traditional governance models can absorb.

NHIMG editorial — based on content published by C1.ai: 2025 Future of Identity Security report

By the numbers:

Questions worth separating out

Q: How should security teams govern AI-generated identity workflows in application code?

A: Treat them as controlled code changes, not convenience scaffolding.

Q: Why do AI systems increase identity risk even when they improve security operations?

A: AI can help defenders, but it also helps attackers scale phishing, impersonation, and credential abuse.

Q: What do security teams get wrong about AI agent and NHI monitoring?

A: They often treat monitoring as a logging problem instead of an identity governance problem.

Practitioner guidance

  • Define agent task boundaries before broad deployment Map each proposed AI agent to a single business function, the systems it may touch, and the actions it may never take.
  • Separate agent privileges from human administrator rights Create distinct entitlement sets for AI agents, service accounts, and human operators so that delegated automation never inherits privileged human access by default.
  • Inventory NHI and agent access together Review service accounts, API keys, tokens, and agent credentials in one programme so that entitlement reviews cover the full delegated-access chain, not just human users.

What's in the full report

C1.ai's full survey covers the operational detail this post intentionally leaves for the source:

  • Breakdowns of the survey methodology and respondent profile across 494 U.S.-based security leaders.
  • Additional use-case data on network monitoring, SOC automation, and access provisioning priorities.
  • The full set of trend comparisons between 2024 and 2025 for identity compromise, stress, and budget movement.
  • More detail on how respondents weighed AI agent risk against productivity gains in security operations.

👉 Read C1.ai's survey findings on AI agents and identity security risk →

AI agents in identity security: what the latest survey means for teams?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Agentic adoption is outrunning identity governance maturity. When 89% of leaders plan to use AI agents and 96% expect those agents to do more than non-critical work, the governance burden moves from future planning into immediate operating design. The field is no longer debating whether agents will arrive. It is deciding whether identity controls can define safe boundaries before adoption becomes embedded in daily security operations.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations prioritise AI agent settings or service account cleanup first?

A: Start with whichever set of artifacts currently grants broader or less visible access, but do not separate them into different programmes. AI settings files, pipeline tokens, and service accounts can all become enterprise access paths, so the right approach is to govern them under one identity risk model with consistent inventory, classification, and review.

👉 Read our full editorial: Security leaders are fast-tracking AI agents despite rising identity risk



   
ReplyQuote
Share: