Join our Newsletter — 33% off our NHI Course

OWASP agentic applications Top 10: what IAM teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Teleport’s summary of the OWASP Top 10 for Agentic Applications 2026 shows that AI agents create identity and privilege risks across goal hijack, tool misuse, memory poisoning, insecure inter-agent communication, and rogue behaviour because they act with real permissions in production. Static IAM assumptions break when agents can decide, delegate, and execute within one session.

Editorial analysis by NHI Mgmt Group, based on content published by Teleport: “OWASP Top 10 for Agentic Applications 2026: Key Takeaways & How to Take Action”.

Key questions

Q: What breaks when agentic AI is governed like a normal application account?

A: Security controls break down because agentic systems do not behave like fixed-function applications.

Q: Why do AI agents increase privilege risk even when logs exist?

A: Logs record what happened, but they do not stop a privileged agent from taking an irreversible action before review.

Q: What are the signs that agent memory or context is being poisoned?

A: Look for repeated bad recommendations, sudden shifts in tool selection, inconsistent task memory, or outputs that reference instructions the operator never approved.

Practitioner guidance

  • Define agent identities as bounded runtime principals Assign each agent a unique identity, short-lived credentials, and explicit tool scope so delegated authority cannot be reused across tasks.
  • Separate planning from execution Require approval or validation gates before an agent can move from reasoning to destructive actions, code execution, or privileged API calls.
  • Validate memory and context inputs Scan writes to long-term memory, RAG stores, and shared context before commit so poisoned data does not influence later decisions.

Bottom line: Agentic applications collapse the assumption that identity is a stable, human-paced construct, because the actor can decide and act during the same session.

What's in the full article

Teleport's full blog post covers the operational detail this post intentionally leaves for the source:

  • Teleport’s specific guardrail pattern for AI agents and MCP servers using ephemeral X.509 or SSH certificates
  • Examples of identity-based access requests and moderated sessions for human-in-the-loop oversight
  • The article’s own implementation framing for access guardrails, audit logs, and per-session authorisation
  • Related resource links on secretless engineering and securing MCP implementations

👉 Read Teleport's analysis of OWASP Top 10 for agentic applications identity risks →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21403
 

Agentic identity is not a new wrapper around existing IAM. It is a different governance problem because the actor can decide, delegate, and act inside the same session. That means access intent is no longer stable at provisioning time, and a control model built for fixed human or workload behaviour loses precision as soon as the agent starts sequencing its own actions. Practitioners should treat agent identity as a runtime governance object, not a static account.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: How should security teams compare agentic supply chain controls with identity controls?

A: Treat them as linked but distinct. Identity controls govern who or what gets to act, while supply chain controls govern what runtime components the agent is allowed to trust before it acts. If the agent can load external tools or descriptors dynamically, both controls are required to keep the trust boundary intact.

👉 Read our full editorial: OWASP Top 10 for agentic applications 2026: identity risks


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.