Join our Newsletter — 33% off our NHI Course

Beyond the Buzzwords: What Practitioners Know About AI Agent Risks

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Gartner’s Emerging Tech Impact Radar places agentic identities in the 1 to 3 year adoption ring with very high mass, according to Astrix Security, while Gartner also projects that 40% of enterprise apps will integrate task-specific AI agents by 2026 and 61% of organisations are already piloting or scaling them. Identity review cycles assume stable principals; autonomous agents break that assumption in-flight.

Editorial analysis by NHI Mgmt Group, based on content published by Astrix Security: “Astrix Named in Gartner’s Emerging Tech Impact Radar for Agentic Identity Security”.

By the numbers:

  • Gartner projects that 40% of enterprise apps will integrate task-specific AI agents by 2026.
  • 61% of organisations are already piloting or scaling AI agents.
  • By 2028, at least 15% of day-to-day work decisions will be made autonomously through agentic AI.

Key questions

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do traditional access reviews struggle with agentic systems?

A: Traditional access reviews assume access persists long enough to be observed, certified, and removed on a schedule.

Q: When should organisations move from role-based control to task-based control for agents?

A: Shift when a role no longer predicts the agent’s real behaviour across tools, systems, or data.

Practitioner guidance

  • Define agent identities as governed principals Inventory AI agents as distinct identities, not as unnamed automation, and record ownership, purpose, tool scope, and revocation authority for each one.
  • Bind access to task scope and session duration Use JIT access, short-lived scopes, and explicit session boundaries so an agent cannot accumulate standing privilege across unrelated work.
  • Log effective permissions and acting-on-behalf chains Capture what the agent actually touched, which delegated actions it took, and which upstream identity authorised the chain for audit and forensics.

Bottom line: Agentic identities force IAM teams to govern software principals that can decide and act at runtime, not just authenticated users and static service accounts.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 15 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20760
 

Agentic identities are not just another NHI category. They are a governance forcing function that exposes where identity programmes still assume predictable human or service-account behaviour. Once an identity can decide and act at runtime, the control plane has to shift from static assignment to continuous authorisation and observation. The implication is that agent governance becomes a core IAM design problem, not a side project for emerging technology teams.

A few things that frame the scale:

A question worth separating out:

Q: What is the difference between human IAM and machine identity governance?

A: Human IAM assumes a known person, a predictable lifecycle, and interactive authentication. Machine identity governance deals with software credentials that operate continuously, often lack clear ownership, and can be copied or reused across systems. The control model must therefore emphasize discovery, privilege scope, and behavior monitoring.

👉 Read our full editorial: Agentic identities are moving into the enterprise security control plane



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.