Join our Newsletter — 33% off our NHI Course

Runtime identity for AI agents: what changes for governance?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Know Your Agent (KYA) shifts AI agent governance from registration-time checks to runtime authentication and authorization, tying consequential actions to a verified human owner and a cryptographic audit trail, according to 1Kosmos. The core issue is assumption collapse: traditional IAM assumes access can be validated once and remain stable, but autonomous agents decide and act at execution time.

Editorial analysis by NHI Mgmt Group, based on content published by 1Kosmos: “Know Your Agent: How KYA Secures Autonomous AI”.

By the numbers:

  • A single scan of one Fortune 100 environment found 700 agents in operation across 24 MCP servers.

Key questions

Q: What breaks when AI agents are not governed at runtime?

A: Without runtime governance, an agent can shift behaviour after provisioning and still execute actions that were never reviewed in context.

Q: Why do autonomous agents increase the risk of over-privileged access?

A: Autonomous agents increase risk because they can use permissions continuously, at scale, and without human hesitation.

Q: When should organisations require human approval for an AI agent action?

A: Require human approval when the action could change infrastructure, expose sensitive data, move laterally across systems, or trigger a business-critical workflow that is hard to reverse.

Practitioner guidance

  • Define execution-time approval thresholds Classify agent actions by consequence, not by tool type, and require runtime approval for data modification, money movement, infrastructure changes, and sensitive record access.
  • Replace static agent secrets with short-lived credentials Issue time-bound credentials bound to a specific agent instance, human owner, and permitted scope so a single credential cannot drift across tasks or sessions.
  • Attach human ownership to every agent Record who authorized the agent, who owns the work, and what action scope was granted so offboarding and revocation can follow the human, not just the software object.

Bottom line: AI agents need runtime identity controls because the meaningful security decision happens at execution time, not just at creation time.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 2 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21473
 

Runtime identity is now the control plane for autonomous action: registration-time identity does not answer the question that matters most, which is whether the agent is allowed to do this specific thing right now. Once an agent can choose tools and timing independently, governance has to move from static access approval to execution-time verification. That changes identity from a provisioning exercise into a live control surface, and practitioners should treat that as the new baseline for agent governance.

A few things that frame the scale:

  • 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: How should teams prove that an AI agent was authorised to act?

A: Teams should prove authorisation by tying each action to a distinct agent identity, a scoped permission decision, and an audit trail that shows who approved the access and under what conditions. That evidence has to cover both the agent's evaluation history and its runtime access history, otherwise the organisation can only prove performance, not authority.

👉 Read our full editorial: Know Your Agent makes runtime identity the control plane for AI


This post was modified 2 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.