Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

BOLA in agentic AI: are your API controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI agents amplify broken object level authorization because one agent can issue thousands of object requests across APIs and MCP servers at machine speed, turning valid calls into data exposure, according to Salt. The real failure is assumption collapse: access review and static authorization models assume human-paced, record-by-record behaviour that autonomous agents do not follow.

NHIMG editorial — based on content published by Salt: LLMjacking and the case for BOLA-driven agentic risk

Questions worth separating out

Q: How should security teams manage permissions for AI agents?

A: Security teams should regularly assess and update the permissions granted to AI agents to ensure they align with their intended scope.

Q: Why do AI agents make BOLA more dangerous than in traditional applications?

A: Because an autonomous agent can issue many valid requests in rapid succession, turning a single authorization gap into large-scale exposure.

Q: What do security teams get wrong about agentic AI security tools?

A: The most common mistake is treating agentic AI security as an extension of an existing category such as NHI, endpoint, or DSPM.

Practitioner guidance

What's in the full article

Salt's full analysis covers the operational detail this post intentionally leaves for the source:

  • Concrete examples of how BOLA appears in agent-facing APIs and MCP-connected workflows.
  • The article's description of the 1-to-many risk pattern across object requests and backend systems.
  • The operational framing Salt uses for continuous API inventory and runtime governance.
  • The full explanation of how intent analysis is positioned against abnormal agent behaviour.

👉 Read Salt's analysis of BOLA risk in autonomous AI agent systems →

BOLA in agentic AI: are your API controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

BOLA has become the most important authorization problem in agentic AI because it scales abuse through legitimate access. The article's central point is not that AI agents create a new vulnerability class, but that they industrialise an old one. When one authenticated system can traverse thousands of objects across multiple APIs, the control failure is no longer accidental overreach on one record. Practitioners should treat object-level authorization as the primary governance boundary for agentic runtime behaviour.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.

A question worth separating out:

Q: Who should own governance when humans and AI agents share access paths?

A: Ownership should sit with the identity, security, and platform teams jointly, because the control problem spans human delegation, machine credentials, and runtime auditability. If each team manages only its own layer, no one can reconstruct the full action chain or revoke access cleanly when the workflow changes.

👉 Read our full editorial: BOLA is the core identity risk in autonomous AI agent systems



   
ReplyQuote
Share: