TL;DR: AI systems are often grouped into causal, predictive, generative, and agentic types, but the operational difference matters most when they start using tools and acting on behalf of systems, according to WorkOS. The real governance problem is that agentic behaviour changes identity assumptions, so IAM teams need to separate automation from autonomy before they overstate control coverage.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “What is the difference between causal, predictive, generative, and agentic AI?”.
Key questions
Q: How should teams govern AI systems that can take actions as well as generate outputs?
A: Treat the agent as a governed actor, not just a model output stream.
Q: When do predictive or generative AI systems become an IAM concern?
A: They become an IAM concern when they can reach internal systems through credentials, service accounts, or delegated APIs.
Q: What breaks when organisations treat agentic AI like ordinary automation?
A: They often miss that autonomous systems can decide timing, sequence, and tool choice at runtime.
Practitioner guidance
- Classify AI systems by decision authority Separate systems that only predict or generate from systems that can choose actions and execute them without a human approval gate.
- Map every tool and credential path Document the APIs, service accounts, tokens, and internal systems an agentic workflow can reach, then confirm whether each path is scoped to the task and environment.
- Bind autonomy to task-scoped privilege Treat any system that can execute its own action sequence as a non-human actor with explicit privilege boundaries.
Bottom line: Agentic AI changes the identity question because it can initiate actions, not just generate or predict outputs.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI is the first AI category that turns identity from a login problem into an authority problem. Predictive and generative systems can be governed as outputs inside an application boundary. Agentic systems can initiate work, select tools, and complete tasks, which means the real control question is no longer authentication alone. Practitioners need to treat runtime authority as the primary security object.
A few things that frame the scale:
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How do IAM and NHI teams decide who owns autonomous AI access?
A: Ownership should sit with the team that controls the credential lifecycle, the approval model, and the offboarding path for the AI system. If the agent uses tokens, service accounts, or other machine credentials, the identity team should own the lifecycle controls even when the product team owns the model behaviour.
👉 Read our full editorial: Causal, predictive, generative and agentic AI: identity implications