TL;DR: Gartner’s Emerging Tech Impact Radar places agentic identities in the 1 to 3 year adoption ring with very high mass, according to Astrix Security, while Gartner also projects that 40% of enterprise apps will integrate task-specific AI agents by 2026 and 61% of organisations are already piloting or scaling them. Identity review cycles assume stable principals; autonomous agents break that assumption in-flight.
Editorial analysis by NHI Mgmt Group, based on content published by Astrix Security: “Astrix Named in Gartner’s Emerging Tech Impact Radar for Agentic Identity Security”.
By the numbers:
- Gartner projects that 40% of enterprise apps will integrate task-specific AI agents by 2026.
- 61% of organisations are already piloting or scaling AI agents.
- By 2028, at least 15% of day-to-day work decisions will be made autonomously through agentic AI.
Key questions
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do traditional access reviews struggle with agentic systems?
A: Traditional access reviews assume access persists long enough to be observed, certified, and removed on a schedule.
Q: When should organisations move from role-based control to task-based control for agents?
A: Shift when a role no longer predicts the agent’s real behaviour across tools, systems, or data.
Practitioner guidance
- Define agent identities as governed principals Inventory AI agents as distinct identities, not as unnamed automation, and record ownership, purpose, tool scope, and revocation authority for each one.
- Bind access to task scope and session duration Use JIT access, short-lived scopes, and explicit session boundaries so an agent cannot accumulate standing privilege across unrelated work.
- Log effective permissions and acting-on-behalf chains Capture what the agent actually touched, which delegated actions it took, and which upstream identity authorised the chain for audit and forensics.
Bottom line: Agentic identities force IAM teams to govern software principals that can decide and act at runtime, not just authenticated users and static service accounts.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic identities are not just another NHI category. They are a governance forcing function that exposes where identity programmes still assume predictable human or service-account behaviour. Once an identity can decide and act at runtime, the control plane has to shift from static assignment to continuous authorisation and observation. The implication is that agent governance becomes a core IAM design problem, not a side project for emerging technology teams.
A few things that frame the scale:
- Gartner predicts that AI systems will initiate 50% of all service requests by 2030, driven largely by agentic AI.
A question worth separating out:
Q: What is the difference between human IAM and machine identity governance?
A: Human IAM assumes a known person, a predictable lifecycle, and interactive authentication. Machine identity governance deals with software credentials that operate continuously, often lack clear ownership, and can be copied or reused across systems. The control model must therefore emphasize discovery, privilege scope, and behavior monitoring.
👉 Read our full editorial: Agentic identities are moving into the enterprise security control plane