Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic AI risks: are legacy IAM controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Agentic AI systems that plan, choose tools, and act with broad permissions create security, compliance, and operational risks that legacy controls were not designed to govern, according to Akto. The governance problem is no longer automation speed alone but the mismatch between autonomous execution and human approval models.

NHIMG editorial — based on content published by Akto: Agentic AI Challenges & Risks: A Complete Security Overview

Questions worth separating out

Q: How should security teams govern agentic AI as it moves into production?

A: Security teams should govern agentic AI as a class of non-human identity, not as a generic application feature.

Q: Why do AI agents create more risk than traditional automation?

A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.

Q: What breaks when AI agents are given broad inherited permissions?

A: Broad inherited permissions break the assumption that access is tied to a narrow business need.

Practitioner guidance

What's in the full article

Akto's full blog covers the operational detail this post intentionally leaves for the source:

  • Practical examples of how the vendor frames AI agent identity security across APIs, tools, and runtime access paths.
  • The article's discussion of control patterns for limiting agent permissions and reducing blast radius in production workflows.
  • Examples of how visibility and logging are positioned for AI agent investigation and governance.
  • The vendor's own framing of how its platform fits into agentic security programmes.

👉 Read Akto's overview of agentic AI risks and security controls →

Agentic AI risks: are legacy IAM controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Agentic AI governance is becoming an identity problem, not just an AI safety problem. The article correctly centres autonomy, but the more important shift for security teams is that agentic systems behave like non-human identities with delegated authority. That means IAM and PAM controls must move from static account management to runtime governance of scope, sequence, and revocation. The discipline that matters is not just model oversight. It is identity-bound control over what an agent can do, when, and under which policy conditions.

A question worth separating out:

Q: How do organisations know if agent governance is actually working?

A: Agent governance is working when every agent is discoverable, owned, least privileged, and auditable at the action level. Look for reduced shadow AI, fewer embedded secrets, clean revocation on retirement, and logs that show which tools and data paths were used. If those signals are missing, governance is still partial.

👉 Read our full editorial: Agentic AI risks expose the limits of legacy IAM controls



   
ReplyQuote
Share: